| Cyber resilience is the ability to keep operating through a cyber attack and get back to normal afterwards, measured in hours and days instead of in controls installed. It assumes something will get through and asks what happens next. |
Most cyber resilience advice is built on a picture of the attacker as a patient intruder, creeping around your network for weeks while you hunt for them. That picture still fits some intrusions and not others, and planning around it alone sends your money to the wrong place.
Sophos, reporting on 661 incident response and managed detection cases across 70 countries in the year to October 2025, put median dwell time at three days. Mandiant, looking at its own 2025 caseload, found the median gap between an attacker getting in and handing the network on to a second attacker group had collapsed to 22 seconds. In 2022 that same gap ran to more than eight hours, and that collapse is a real change in how quickly access moves between criminal groups.
Speed like that changes what detection has to do.
Your monitoring has not failed, and none of this argues for buying more of it. Mandiant’s own advice is to treat routine malware alerts as high-priority indicators and to remediate before hands-on-keyboard activity begins, which is an argument for acting on early alerts rather than giving up on them. What the numbers add is a second question alongside the first: not just how quickly you would notice, but how quickly you would be back. Cyber resilience is the name for that second question, and unlike the first it has an answer you can put a number against.
This page is about that measurement. What cyber resilience means alongside prevention and detection, what really decides your recovery time, and the four questions a New Zealand business should be able to answer with a number.
What Is Cyber Resilience and How Is It Different From Cyber Security?
Cyber security is the work of stopping attacks. Cyber resilience is the work of surviving the ones that get through. The two overlap heavily in practice, and the distinction only starts to matter when you are deciding where the next dollar goes.
A business with strong cyber security and weak cyber resilience looks fine on an audit and then loses a fortnight when something lands. A business with the reverse looks unimpressive on paper and is trading again by Wednesday. Most of the New Zealand businesses we assess sit closer to the first than the second, and the reason is not carelessness.
Prevention is easier to buy. It arrives as a product, with a licence count and a renewal date and a line in the budget. Recovery capability arrives as a set of procedures somebody has to rehearse, and nobody can point at a rehearsal in a board pack, so cyber resilience work gets deferred year after year until the year it is needed.
Worth saying what this page is not. It is not a list of the controls to put in place, which we cover separately in our cyber readiness blueprint. This page is about the one thing a list of controls cannot tell you: how long you would be down.
How Long Do Attackers Spend Inside a Network Before They Act?
It depends which number you read, and the two most quoted ones point in opposite directions. Treat them as descriptions of different caseloads rather than as a countdown for your business.

Sophos reports a median dwell time of three days across its 2026 Active Adversary Report, drawn from 661 incident response and managed detection engagements. Mandiant’s M-Trends 2026, covering its 2025 investigations, puts the global median at 14 days across every intrusion type it handled, up from 11 days the year before, a higher figure lifted by long-running espionage cases and not by criminal ones. Sophos also splits its own median by service, five days across incident response cases and two across managed detection.
The two are not the same measurement and should never be averaged. Sophos is describing its own response caseload. Mandiant is describing consulting engagements that include state-sponsored intrusions sitting undetected for months. One median fell and the other rose, so there is no single direction of travel to read off them. Sophos is explicit that its decrease reflects defenders detecting faster as well as attackers moving faster. What both rule out is any assumption that warning arrives in weeks as a matter of course.
Mandiant’s sharpest number is the one that should change how you plan. Across its 2025 cases, the median time from initial access to hand-off to a second threat group was 22 seconds. That is the speed at which access changes hands, not the time to encryption or to a business being stopped.
Read that alongside whatever monitoring arrangement you have. Round-the-clock detection is worth paying for and we sell it, but the honest case for it has changed. It no longer buys you weeks to investigate at your own pace. What it does is shorten the blast radius of something already moving faster than any person can respond to.
The planning consequence follows on its own. When access can change hands in seconds, prevention and prompt detection still reduce how often and how far an attacker gets, and recovery decides what it costs when one does. Cyber resilience occupies that second territory, and it is why it deserves a budget line of its own rather than a paragraph inside the security one.
How Long Would It Take Your Business to Get Back Up?
The estimate usually goes wrong in the same direction. It is built on how long a restore takes when everything works, when the answer is set by whichever dependency nobody wrote down.
The table below is the version of this conversation we have with clients. The middle column is what people say when asked cold. The right-hand column is what actually determines the answer, and in every case it is a question of fact somebody could go and check this week without spending anything. Cyber resilience gets built out of those answers.
| What stops | The usual assumption | What actually decides it |
|---|---|---|
| Back within the hour | Whether the tenant itself is compromised, and whether you have an out-of-band way to reach staff | |
| Files and shared drives | Restore from backup today | When a restore was last actually attempted, and how long a full one takes at your data volume |
| Line-of-business system | The vendor will handle it | The recovery commitment written into your contract, and whether anybody has read it |
| Phones | Unaffected | Whether the phone system depends on the same network and the same identity provider as everything else |
| Knowing what was taken | The logs will show us | How long your logs are actually retained, which is often 30 days or less |
That last row surprises people most. Logs help establish what an attacker reached, and that feeds the Privacy Act decision, but they will not always give you a complete record. The test is not what the logs show. If you believe on reasonable grounds that a breach has caused, or is likely to cause, serious harm to people, you must notify the Privacy Commissioner and the affected people as soon as practicable, subject to the exceptions in the Act. Assess on what you have and revise as the investigation develops, rather than waiting for certainty or defaulting to the worst case.
Nothing in the right-hand column needs an assessment. It needs somebody to go and look, and the looking keeps getting postponed because it never feels urgent until it is.
What Does the NZ Cyber Security Strategy Expect of Businesses?
Preparation, not compliance, at least for now. The Government published New Zealand’s Cyber Security Strategy 2026-2030 in February 2026. It is built around four objectives, and they read as expectations of organisations generally, not only of government agencies.
The four objectives, in the strategy’s own words:
- Understand: we are well aware of cyber risks and know how to protect ourselves.
- Prevent and prepare: we manage cyber risks to prevent harm and are well-prepared when incidents occur.
- Respond: we react effectively and decisively to adverse cyber incidents.
- Partner: our resilience to cyber threats is bolstered by strategic and targeted cooperation.
Two of the four are about what happens after prevention fails, which is this page’s argument put in official language.
On regulation the strategy commits to developing a regulatory regime to improve the cyber security of critical infrastructure, with public consultation as the first step. That consultation ran from 27 February to 19 April 2026 and has closed, with DPMC saying feedback will inform further advice to Cabinet. As at 15 September 2026 no bill had been introduced. The regime as proposed would reach roughly 200 entities across seven essential services, so most New Zealand businesses would sit outside it. Size alone would not settle the question, because the Minister would be able to designate entities into the regime and to exempt others, and supplying a covered entity is a separate matter from being one.
A second measure gets quoted more loosely than it deserves, and it is worth pinning down because you will see it stated as settled. Civil penalties under the Privacy Act do not appear in the strategy. They appear in the accompanying Cyber Security Action Plan 2026-2027, where the commitment is to provide advice on options to incentivise the protection of personal information, giving a civil pecuniary penalty regime as an example of such an option. Advice on options is several steps short of a penalty regime.
The strategy also names quantum computing, warning that the technology has the potential to render current encryption methods obsolete. It does not put a date on that. For most small businesses that is a watching brief and not a 2026 project. It is still a fair reason to ask what your longest-lived systems encrypt with, because those will still be running when it matters.
Why Do Recovery Plans Fail When They Are Needed?
Because having a plan and having tested one are different things, and the gap between them stays invisible until the day it matters. The strategy makes the same point about New Zealand businesses in general, observing that many overestimate their resilience and their ability to handle cyber threats.

In our own incident work the failures cluster in four places, none of them exotic. The backup ran every night but nobody ever restored from it, so the first attempt is also the first test. The plan names somebody who left in March. The contact list lives on the file server that is currently encrypted. Or the plan was written for a systems outage and the incident turns out to be a data breach, which asks a completely different set of questions.
Every one of those is cheap to fix beforehand and expensive to discover at the time. That asymmetry is the practical case for cyber resilience work, and it is more persuasive than any threat statistic because it does not depend on believing anything about attackers at all.
What a plan should actually contain sits in our guide to the incident response plan. The backup architecture behind a credible restore is covered in our data backup strategy. Both will be more use to you than a second summary of them here.
What Should a Small Business Do First?
Test one restore.
Not a plan, not an assessment, not a policy document. Pick the system you would miss first, restore it somewhere it cannot do any damage, and write down how long it took and what went wrong on the way. Cyber resilience starts there and not with a document. A first attempt usually turns up something uncomfortable, and finding it deliberately costs far less than finding it during an incident. How long the exercise takes depends on the systems, the licences and whether a supplier has to be involved, so agree that before you start.
After that, the list below is roughly the order we would work in for a business with no dedicated security team, and it is deliberately short because none of it requires a purchase.
A proportionate order of work:
- Restore one critical system from backup and time it, including the part where you hunt for the credentials.
- Write down who decides to declare an incident, and who decides when that person is on holiday.
- Keep the contact list somewhere that survives the systems being down, including on paper.
- Check how long your logs are kept, because that sets what you can prove after a breach.
- Read the recovery commitment in your line-of-business software contract.
- Confirm one backup copy is actually offline or immutable, and not simply in a different folder.
- Agree what an acceptable outage looks like for each critical system, in hours, which is the method our business impact analysis guide sets out in full.
Boards find that last one hardest, and it is the item that makes everything above it decidable. Until somebody says out loud how long the business can survive without its main system, every argument about security spending is an argument between opinions.
How Do You Know If Your Cyber Resilience Is Real?
You can answer four questions with numbers. That is the whole test. It is unforgiving in a useful way, because a number can be shown to be wrong and a reassurance cannot.
Ask how long a full restore of the main system takes, and accept only an answer in hours from somebody who has done it, along with what that test did not cover. Ask when it was last done, and how old the recovered data was. Ask how long the business can trade without that system, which is the outer limit rather than the target. Ask what your logs would let you prove about a breach discovered three months later, and who decides whether to notify.
If those come back as adjectives, the cyber resilience being described is aspirational. That is not a criticism of whoever is answering. It usually means nobody has ever been asked to find out, and that is a governance gap and not a technical one. We have written separately about what boards are responsible for, because cyber resilience that nobody owns at board level stays theoretical no matter how much is spent underneath it.
None of this makes an attack less likely on its own. It changes what an attack costs you. Prevention and detection reduce how often you are in that position, recovery decides what it costs when you are, and cyber resilience is the name for managing the second one deliberately rather than discovering it.
Frequently Asked Questions
What is cyber resilience?
Cyber resilience is the ability to prepare for cyber disruption, keep essential work going through it, recover safely and improve afterwards. Recovery time is one measure of it. People, access, suppliers, data integrity and the decisions made during an incident all shape the outcome as well.
Is cyber resilience just a new name for disaster recovery?
No. Disaster recovery is one component of it, covering how you restore systems and data. Cyber resilience also covers the decisions, communications and legal obligations that run alongside the restore, and it assumes your environment may be actively hostile while you work.
What is dwell time and what do the published figures mean?
Dwell time is the interval between compromise and detection. It is not the time to data theft, to ransomware being deployed or to recovery. Sophos put the median at three days in the year to October 2025, while Mandiant put its own global median at 14 days, up from 11 the year before. The figures differ because the caseloads differ, so a published median is not a deadline for your business.
What is a recovery time objective?
A recovery time objective is the target time for restoring an agreed level of service after disruption. It sits inside the maximum tolerable downtime, which is the outer limit beyond which the damage becomes unacceptable. Both are commercial judgements, and both are separate from what a recovery test actually achieved.
How long should a full restore take?
There is no universal figure. It depends on data volume, where the backup lives, what identity and infrastructure has to be rebuilt, and the application checks before anyone can work. What matters is your own number from an actual attempt, together with what that attempt did not cover. A backup restore time is not the same as the time to resume trading.
How often should we test a restore?
Set the schedule by how critical the service is, how fast it changes and any commitments you have made, with at least quarterly for anything the business cannot trade without. Retest after a significant change or a failed exercise. Record what each test covered, because restoring a sample file and recovering a whole service answer different questions.
Does cyber insurance cover downtime?
Business interruption cover is available on many cyber policies. What it actually pays depends on the wording of your own policy, including the waiting period, the limits, the exclusions and the conditions you agreed to. Read those with your broker rather than assuming that one declared control decides the outcome.
Does the NZ Cyber Security Strategy require businesses to be cyber resilient?
Not as a legal requirement for most businesses. The strategy sets expectations across four objectives and commits to developing a regulatory regime for critical infrastructure. That regime remains at the proposal stage after consultation closed in April 2026.
Will the Privacy Act get civil penalties for cyber failures?
It is under consideration and nothing has been decided. The Cyber Security Action Plan 2026-2027 commits to providing advice on options to incentivise the protection of personal information, and gives a civil pecuniary penalty regime as one example. No bill has been introduced.
Can a small business realistically be cyber resilient?
Yes. Start with the services the business cannot operate without, work out what they depend on and agree who makes the decisions during disruption. Then test recovery in a controlled way. How much work that takes depends on the systems and the support available rather than on employee numbers.
What is the difference between cyber resilience and business continuity?
Business continuity plans for disruption from any cause, including floods, power cuts and the loss of a key supplier. Cyber resilience covers keeping and recovering dependable operations under cyber disruption, where your own systems may be working against you and your backups may be a deliberate target. The two should share the same priorities, decision roles and fallback arrangements.
How do you measure cyber resilience?
Use several measures rather than one. Tested service recovery against the target, how old the recovered data was, whether essential work can continue, how ready the response is, and what remains unresolved. Record the scenario each result came from and what it did not cover. A single restore duration does not measure the whole capability, and without numbers the measurement has not been done.
NEXT STEP
Find out where you actually stand
If you cannot say what would delay recovery, start with the service the business depends on most. We run recovery testing and cyber resilience assessments for New Zealand businesses from Christchurch and Dunedin. You get the tested result for the scenario we ran, the assumptions behind it and what the exercise could not cover, which is a position the business can act on rather than a guaranteed incident duration.
Or read more about our cyber security services.

