Start With the Question That Matters Most: Did the Data Survive?
Adversaries target backups because backups determine whether an organization can recover after an attack. In fact, research has shown that attackers were at least partially successful in compromising backup environments in about 74% of ransomware cases.
Every data protection vendor claims immutability. But organizations should pressure-test whether it holds against a skilled adversary with domain admin credentials already inside the network.
Know Where To Recover Before the Crisis
Cyberattacks often don’t create physical damage. Instead, attacks destroy trust in the security context. Because production and disaster recovery sites are tightly integrated, a compromise at one site often means the DR site can’t be trusted either. For this reason, cyber recoveries can require a new construct: an isolated recovery environment. An IRE gives organizations a clean, separate place to restore critical systems, test recovery and avoid reinfecting the environment they are trying to rebuild.
Thankfully, an IRE does not require another physical site, nor does it need to host the entire hospital application fleet. What’s important is that it can support the applications supporting urgent clinical and operational functions.
READ MORE: Build clinical care resilience when your EHR goes down.
Recover What Matters First
Health system IT teams already have a clear picture of their most critical applications.
A practical recovery sequence starts with identity, Domain Name System, Dynamic Host Configuration Protocol and other critical services without which applications will not function. Then come internal communications, which help coordinate the organization’s response. Next come clinical applications in priority order, based on how care is delivered.
The “minimum viable hospital” concept can help frame that work. By repeatedly drilling these recoveries into an IRE, the organization develops cyber resilience, assuring the ability to quickly restore care for patients.
Test the Plan Before Patients Depend on It
Orchestrated application recovery, as a tactic, lets teams run automated drills on a schedule. Weekly testing can reveal what breaks, what takes too long and what must be fixed before an attack.
That matters financially too. A five-day reduction in recovery time can save a health system tens or even hundreds of millions of dollars.
The message for organizations is clear: Start building, automating and testing now with the resources you have.
Build Clinical Continuity, Not Just IT Recovery
When a hospital goes dark, the mission must continue. Stroke patients still arrive. Labs still need results. Surgeries must go on. Clinical recovery should be planned alongside IT recovery.
Legal, regulatory, financial, operational and clinical decisions converge in the first hours of a cyberattack. Cross-functional simulations help organizations see what a coordinated response looks like. They also expose gaps in staffing, communications, manual workflows and decision-making before those gaps affect patient care.
Click the banner below to sign up for HealthTech’s weekly newsletter.
