Protected data is not the same as a business that recovers

September 24, 2026
Triangle & Business Post - Cyber Recovery

Triangle Director of Technology Padhraic Maguire recently spoke with the Business Post about a gap most recovery plans do not close: protecting data and recovering a business are not the same thing.

An organisation can hold protected copies of every data set it owns and still struggle to restore the services it depends on after an attack. Businesses do not run on data in isolation. They run on services, and those services depend on infrastructure, applications, cloud platforms, software providers and third parties that have to be restored, in the right order, before the business is operating again. Cyber recovery has to account for how those pieces fit back together.

Cyber resilience starts with an uncomfortable assumption

Cyber security remains essential. Prevention, detection, patching, monitoring and access controls all reduce risk. But no organisation can build its recovery strategy on the assumption that those controls will always hold.

In the Business Post article, Padhraic explains why:

"With the best will in the world, keeping attackers out is nearly impossible, and you have to have a plan in place on how to recover should that day ever come."

That shift in thinking is what has moved the conversation over the last five or six years from cyber security towards cyber resilience. The practical question is no longer only how well an organisation can defend its environment. It is what happens when an attacker gets through, and whether the business has a proven route back to operation.

The business does not run on isolated systems

That question gets harder as enterprise IT becomes more distributed.

"We're talking about IT services across multiple service providers, across different cloud platforms. You have SaaS providers, you're going to have on-prem infrastructure, and all of those services are needed to deliver an organisation's products or whatever the business needs are." - Padhraic Maguire

A critical business service may depend on several of those environments at once, so restoring one server, application or data set says very little about whether the service itself has recovered. The dependencies have to be understood, along with the sequence in which systems need to return and the point at which the complete service can be trusted again. This is where recovery moves beyond backup. Protecting data is necessary, but recoverability depends on understanding how that data, the infrastructure around it and the applications that use it come together to support the business.

Recoverability is the success measure

As Padhraic puts it: "Protecting the data is only one step in the process. You still have to put it all back together. I can protect every piece of data my organisation has. If I don't understand how to put that puzzle back together, then it's really pointless."

That is what cyber recovery has to be designed for. The objective is not simply to preserve copies of critical information. An effective recovery position also needs isolated recovery infrastructure, a way to validate that recovered data can be trusted, defined recovery processes and regular testing of how critical services will actually be restored.

Triangle's approach to cyber recovery is built around those disciplines, including isolated data protection, cyber vaulting, clean room recovery, data forensics and recovery testing. Padhraic sets out the design principles behind them in our cyber recovery video series. Each addresses a different part of the same question: if production systems are compromised, can the organisation recover cleanly and with confidence?

AI increases the speed of the challenge

Artificial intelligence is changing both sides of the cyber security equation. Attackers can use AI to find vulnerabilities and operate more quickly. Security and recovery teams can use it to analyse large volumes of information and support detection, forensic and recovery processes. But faster tools do not remove the underlying recovery challenge. If the organisation does not understand the dependencies behind a critical business service, technology alone cannot reconstruct that service after an attack. The recovery architecture, processes and responsibilities still have to be designed in advance and kept current as the environment changes.

Regulation is increasing the focus on evidence

Expectations around operational resilience have changed too. European frameworks including DORA and NIS 2 have increased scrutiny of resilience, governance and third-party technology risk for the organisations they cover. For managed service providers supporting regulated organisations, that is changing the nature of the relationship. Padhraic describes the change directly:

"We're no longer just asked to deliver a service. We're asked to help an organisation maintain compliance. We're also being asked to be involved in the governance of all these things, and to make sure that we're achieving the desired outcomes that are needed to say from an audit point of view that we're compliant."

The precise obligations depend on the organisation and the framework that applies. The operational implication is the same in every case: resilience needs evidence. A recovery plan describes what should happen. Testing provides evidence of what actually happens. Triangle's cyber recovery services are built to produce that evidence, including the auditable proof of prior recovery that regulators now expect.

Testing is where recovery becomes real

That makes testing central to cyber recovery. Cyber recovery has one measure of success. Either the business services can be restored after an attack, or they cannot. It is not enough to prove that an individual system can be brought back. The organisation needs to know whether the complete service can return to a usable state.

"It's not just that I can recover this system; it's that I can recover the service to the point that I can prove it is a usable service." - Padhraic Maguire

Regular recovery testing turns assumptions into evidence. It exposes missing dependencies and sequences that no longer reflect the production environment, and it shows where runbooks have fallen behind changes in the estate. It also gives teams experience of the processes they would have to run under pressure.

That matters because recoverability does not stay still. As we explored in Recoverability is built before recovery starts, enterprise environments keep changing. New applications and integrations arrive, infrastructure is replaced, and suppliers and access paths change. Over time, the environment being operated can move away from the environment the recovery plan describes. Regular, evidenced testing is how an organisation finds that gap before an incident does.

The better recovery question

Protected data remains fundamental to cyber recovery. Protection on its own does not tell an organisation whether it can recover. The more useful question is whether critical business services can be reconstructed from trusted data, across their real dependencies, using processes that have been recently exercised and proven.

That is the difference between having protected data and having a recovery capability the business can rely on.

-----------------

Read Padhraic Maguire's full interview in the Business Post >>

Triangle SBP Sept 26 - article header image - min

-----------------

Explore related:

back to all resources

Other resources you might like