Cyber Resilience: How Fast Could Your Business Actually Recover?

Cyber resilience is the ability to keep operating through a cyber attack and get back to normal afterwards, measured in hours and days instead of in controls installed. It assumes something will get through and asks what happens next.

Most cyber resilience advice is built on a picture of the attacker as a patient intruder, creeping around your network for weeks while you hunt for them. That picture is out of date. Acting on it sends your money to the wrong place, and it has been sending it there for a while.

Sophos, reporting on 661 incident response and managed detection cases across 70 countries in the year to October 2025, put median dwell time at three days. Mandiant, looking at its own 2025 caseload, found the gap between an attacker getting in and handing the network to a ransomware crew had collapsed to 22 seconds. In 2022 that same gap ran to more than eight hours, and the distance between those two figures is the most important change in this field in a decade.

You are not going to spot them in time.

Your monitoring has not failed, and none of this argues for buying more of it. The numbers simply look like that now. What changes is the useful question, which moves from how quickly you would notice to how quickly you would be back. Cyber resilience is the name for that second question, and unlike the first it has an answer you can put a number against. It is also the answer almost nobody has measured.

This page is about that measurement. What cyber resilience means once detection time is counted in days, what really decides your recovery time, and the four questions a New Zealand business should be able to answer with a number.

What Is Cyber Resilience and How Is It Different From Cyber Security?

Cyber security is the work of stopping attacks. Cyber resilience is the work of surviving the ones that get through. The two overlap heavily in practice, and the distinction only starts to matter when you are deciding where the next dollar goes.

A business with strong cyber security and weak cyber resilience looks fine on an audit and then loses a fortnight when something lands. A business with the reverse looks unimpressive on paper and is trading again by Wednesday. Most of the New Zealand businesses we assess sit closer to the first than the second, and the reason is not carelessness.

Prevention is easier to buy. It arrives as a product, with a licence count and a renewal date and a line in the budget. Recovery capability arrives as a set of procedures somebody has to rehearse, and nobody can point at a rehearsal in a board pack, so cyber resilience work gets deferred year after year until the year it is needed.

Worth saying what this page is not. It is not a list of the controls to put in place, which we cover separately in our cyber readiness blueprint. This page is about the one thing a list of controls cannot tell you: how long you would be down.

How Long Do Attackers Spend Inside a Network Before They Act?

Days, not weeks, and for ransomware often far less. Dwell time has moved further over the past three years than any other number in this field, and most cyber resilience writing has not caught up with it.

Dwell time compared: the weeks-long assumption against a 14 day and a 3 day median, and a 22 second ransomware handover too small to draw

Sophos reports a median dwell time of three days across its 2026 Active Adversary Report, drawn from 661 incident response and managed detection engagements. Mandiant’s M-Trends 2026, covering its 2025 investigations, puts the global median at 14 days across every intrusion type it handled, a higher figure lifted by long-running espionage cases and not by criminal ones.

The two are not the same measurement and should never be averaged. Sophos is describing its own response caseload. Mandiant is describing consulting engagements that include state-sponsored intrusions sitting undetected for months. What they agree on is the direction of travel, and neither leaves room for the idea that you get weeks of warning before anything happens.

Mandiant’s sharpest number is the one that should change how you plan. Across its 2025 cases, the median time from initial access to hand-off to a ransomware operator was 22 seconds.

Read that alongside whatever monitoring arrangement you have. Round-the-clock detection is worth paying for and we sell it, but the honest case for it has changed. It no longer buys you weeks to investigate at your own pace. What it does is shorten the blast radius of something already moving faster than any person can respond to.

The planning consequence follows on its own. Once the window for stopping an attack has narrowed to the point where automation decides the outcome, the one variable still under your control is what happens afterwards. Cyber resilience occupies exactly that territory, and it is why cyber resilience deserves a budget line of its own rather than a paragraph inside the security one.

How Long Would It Take Your Business to Get Back Up?

Almost every business gets this wrong in the same direction. The estimate is built on how long a restore takes when everything works, and the answer is actually set by whichever dependency nobody wrote down.

The table below is the version of this conversation we have with clients. The middle column is what people say when asked cold. The right-hand column is what actually determines the answer, and in every case it is a question of fact somebody could go and check this week without spending anything. Cyber resilience gets built out of those answers.

What stops The usual assumption What actually decides it
Email Back within the hour Whether the tenant itself is compromised, and whether you have an out-of-band way to reach staff
Files and shared drives Restore from backup today When a restore was last actually attempted, and how long a full one takes at your data volume
Line-of-business system The vendor will handle it The recovery commitment written into your contract, and whether anybody has read it
Phones Unaffected Whether the phone system depends on the same network and the same identity provider as everything else
Knowing what was taken The logs will show us How long your logs are actually retained, which is often 30 days or less

That last row surprises people most. Establishing what an attacker reached is what determines your Privacy Act notification obligations. If the logs have already rolled over, you end up notifying on a worst-case assumption, and that is a far more expensive letter to send than an accurate one.

Nothing in the right-hand column needs an assessment. It needs somebody to go and look, and the looking keeps getting postponed because it never feels urgent until it is.

What Does the NZ Cyber Security Strategy Expect of Businesses?

Preparation, not compliance, at least for now. The Government published New Zealand’s Cyber Security Strategy 2026-2030 in February 2026. It is built around four objectives, and they read as expectations of organisations generally, not only of government agencies.

The four objectives, in the strategy’s own words:

  • Understand: we are well aware of cyber risks and know how to protect ourselves.
  • Prevent and prepare: we manage cyber risks to prevent harm and are well-prepared when incidents occur.
  • Respond: we react effectively and decisively to adverse cyber incidents.
  • Partner: our resilience to cyber threats is bolstered by strategic and targeted cooperation.

Two of the four are about what happens after prevention fails, which is this page’s argument put in official language.

On regulation the strategy commits to developing a regulatory regime to improve the cyber security of critical infrastructure, with public consultation as the first step. That consultation ran from 27 February to 19 April 2026 and has closed. No bill has followed. The regime as proposed would reach roughly 200 entities across seven essential services, so it will not touch most New Zealand businesses at all.

A second measure gets quoted more loosely than it deserves, and it is worth pinning down because you will see it stated as settled. Civil penalties under the Privacy Act do not appear in the strategy. They appear in the accompanying Cyber Security Action Plan 2026-2027, where the commitment is to provide advice on options to incentivise the protection of personal information, giving a civil pecuniary penalty regime as an example of such an option. Advice on options is several steps short of a penalty regime.

The strategy also names quantum computing, warning that within its timeframe the technology has the potential to render current encryption methods obsolete. For most small businesses that is a watching brief and not a 2026 project. It is still a fair reason to ask what your longest-lived systems encrypt with, because those will still be running when it matters.

Why Do Recovery Plans Fail When They Are Needed?

Because having a plan and having tested one are different things, and the gap between them stays invisible until the day it matters. The strategy makes the same point about New Zealand businesses in general, observing that many overestimate their resilience and their ability to handle cyber threats.

Two documents contrasting having a recovery plan with having tested it, the gap marked as where recovery fails

In our own incident work the failures cluster in four places, none of them exotic. The backup ran every night but nobody ever restored from it, so the first attempt is also the first test. The plan names somebody who left in March. The contact list lives on the file server that is currently encrypted. Or the plan was written for a systems outage and the incident turns out to be a data breach, which asks a completely different set of questions.

Every one of those is cheap to fix beforehand and expensive to discover at the time. That asymmetry is the practical case for cyber resilience work, and it is more persuasive than any threat statistic because it does not depend on believing anything about attackers at all.

What a plan should actually contain sits in our guide to the incident response plan. The backup architecture behind a credible restore is covered in our data backup strategy. Both will be more use to you than a second summary of them here.

What Should a Small Business Do First?

Test one restore.

Not a plan, not an assessment, not a policy document. Pick the system you would miss first, restore it somewhere it cannot do any damage, and write down how long it took and what went wrong on the way. Cyber resilience starts there and not with a document. Nearly every business that tries this learns something uncomfortable on the first attempt, and the discovery costs a morning instead of a fortnight.

After that, the list below is roughly the order we would work in for a business with no dedicated security team, and it is deliberately short because none of it requires a purchase.

A proportionate order of work:

  • Restore one critical system from backup and time it, including the part where you hunt for the credentials.
  • Write down who decides to declare an incident, and who decides when that person is on holiday.
  • Keep the contact list somewhere that survives the systems being down, including on paper.
  • Check how long your logs are kept, because that sets what you can prove after a breach.
  • Read the recovery commitment in your line-of-business software contract.
  • Confirm one backup copy is actually offline or immutable, and not simply in a different folder.
  • Agree what an acceptable outage looks like for each critical system, in hours.

Boards find that last one hardest, and it is the item that makes everything above it decidable. Until somebody says out loud how long the business can survive without its main system, every argument about security spending is an argument between opinions.

How Do You Know If Your Cyber Resilience Is Real?

You can answer four questions with numbers. That is the whole test. It is unforgiving in a useful way, because a number can be shown to be wrong and a reassurance cannot.

Ask how long a full restore of the main system takes, and accept only an answer in hours from somebody who has done it. Ask when it was last done. Ask how long the business can trade without that system. Ask what your logs would let you prove about a breach discovered three months later.

If those come back as adjectives, the cyber resilience being described is aspirational. That is not a criticism of whoever is answering. It usually means nobody has ever been asked to find out, and that is a governance gap and not a technical one. We have written separately about what boards are responsible for, because cyber resilience that nobody owns at board level stays theoretical no matter how much is spent underneath it.

None of this makes an attack less likely. It changes what an attack costs you. Once the window for stopping one has narrowed to seconds, cost is the only variable still under your control, and cyber resilience is the name for managing it deliberately.

Frequently Asked Questions

What is cyber resilience?

Cyber resilience is the ability to keep operating through a cyber attack and return to normal afterwards. It assumes prevention will sometimes fail and concentrates on what happens next, which makes cyber resilience a question about recovery time and not about how many controls you own.

Is cyber resilience just a new name for disaster recovery?

No. Disaster recovery is one component of it, covering how you restore systems and data. Cyber resilience also covers the decisions, communications and legal obligations that run alongside the restore, and it assumes your environment may be actively hostile while you work.

What is dwell time and why has it fallen so far?

Dwell time is how long an attacker is inside a network before being detected. It has fallen because attack tooling is now largely automated, so intruders no longer need days of manual work to find what they came for. Sophos put the median at three days in the year to October 2025.

What is a recovery time objective?

A recovery time objective is the longest a system can be unavailable before the damage to the business becomes unacceptable. It is a commercial judgement and not a technical one. It has to be set before an incident, because during one everybody’s answer is immediately.

How long should a full restore take?

There is no universal figure. It depends on your data volume, where the backup lives and how much has to be rebuilt around the data once it lands. What matters is knowing your own number from an actual attempt, not from a specification sheet.

How often should we test a restore?

At least quarterly for any system the business cannot trade without, and again after a significant change to the environment. A restore that has not been attempted in a year only tells you about last year’s configuration.

Does cyber insurance cover downtime?

Business interruption cover is available on many cyber policies, though it usually starts after a waiting period and pays against demonstrated loss. It also depends on the controls you declared being in place on the day. That is worth checking before you need to rely on it.

Does the NZ Cyber Security Strategy require businesses to be cyber resilient?

Not as a legal requirement for most businesses. The strategy sets expectations across four objectives and commits to developing a regulatory regime for critical infrastructure. That regime remains at the proposal stage after consultation closed in April 2026.

Will the Privacy Act get civil penalties for cyber failures?

It is under consideration and nothing has been decided. The Cyber Security Action Plan 2026-2027 commits to providing advice on options to incentivise the protection of personal information, and gives a civil pecuniary penalty regime as one example. No bill has been introduced.

Can a small business realistically be cyber resilient?

Yes, and often more easily than a large one, because there are fewer systems and fewer people to coordinate in a hurry. The constraint is usually attention, not budget. The two highest-value actions are a tested restore and a written decision path, and neither costs much.

What is the difference between cyber resilience and business continuity?

Business continuity covers any disruption at all, including floods, power cuts and the loss of a key supplier. Cyber resilience is the subset dealing with attacks, where the complication is that your own systems may be working against you and your backups may be a deliberate target.

How do you measure cyber resilience?

Cyber resilience is measured in time. How long to restore the main system, when that was last proven, how long the business can trade without it, and how far back the logs would let you investigate. Four answers, all of them numbers, or the measurement has not been done.

NEXT STEP

Find out where you actually stand

If you cannot put a number on how long you would be down, that is the gap worth closing first. We run recovery testing and cyber resilience assessments for New Zealand businesses from Christchurch and Dunedin. The output is a time, in hours, per system, with the evidence behind it.

Or read more about our cyber security services.

Start typing and press Enter to search

Cyber security leadership banner showing a compass with a settled needle pointing one wayProactive IT monitoring banner showing a fault intercepted on a monitoring line before it reaches staff systems Call Us Now