.jpg)
Most businesses can answer the question "do we have backups?" Fewer can answer "how fast could we actually get back up and running, and in what order?"
That gap is where real damage happens.
The UK government's Cyber Security Breaches Survey puts the number of UK businesses hit by a breach or attack in the last year at 43%, an estimated 612,000 organisations. Separately, UK organisations report being 11% less likely than their international counterparts to have tested a recovery plan in the last month. Having a backup and having a tested recovery process are not the same commitment, and treating them as interchangeable is where a lot of "we thought we were covered" conversations start.
Recovery Time Objective (RTO) and Recovery Point Objective (RPO) aren't jargon, they're decisions
RTO is how long you can survive without a system before it costs you real money or real trust. RPO is how much data you can afford to lose, measured in time, an hour, a day, a week. Neither of these should be set by your IT provider in isolation. They're business decisions dressed up in technical language, and if nobody in the leadership team has actually agreed them, your recovery plan is guessing on your behalf.
Workload dependencies matter more than most recovery plans admit
Restoring your file server doesn't help much if the application that depends on it, and the database that application depends on, aren't back yet too. Recovery plans that list systems individually, rather than in the order they depend on each other, tend to fall apart exactly when they're needed.
Restoration order is a plan, not an afterthought
When everything's down, what comes back first? Email? Your core line-of-business system? Customer-facing services? If the honest answer is "whatever the IT team gets to first," that's not a plan, that's a hope.
The governance gap is real
Only 27% of UK businesses currently have a board member responsible for cyber security, down from 38% in 2021, and just 25% have a formal incident response plan. That means most businesses that experience a breach are improvising their response in real time. Recovery planning fixes that, but only if it's tested, not just written down.
What good actually looks like
A recovery strategy that's separate from, and more detailed than, your backup strategy. Agreed RTOs and RPOs signed off by the business, not just IT. A documented restoration order based on real dependencies. And a test, run at least annually, that proves it all works when nobody's expecting it.
Backups are the raw material. Recovery is the plan for using them. Only one of those gets you back to business.
If your recovery plan hasn't been tested this year, it's not a plan — it's a theory.
Synapse, Manx Telecom Enterprise and our partners at Dell Technologies are coming together to help Isle of Man businesses build real cyber resilience, protecting critical data and preparing properly for when (not if) a cyber event happens.
When? 10th September | 12–3pm
Where? Manx Museum, Douglas
If you're behind the scenes on cyber, compliance or risk for your business, come along.
Sign up here: mt.im/cyberrecovery
.png)

