Minimum viable company: Recover faster when systems go dark
LIM HSIN YIN
Vice President & General Manager, ASEAN
Cohesity
Most organisations across the Asia-Pacific region don’t fail to recover from cyber incidents due to lack of backups. A common but often overlooked failure point is trying to restore everything at once.
Today, cyber attacks are often destructive, with common attack vectors such as wiper malware, compromised identity systems and persistent backdoors attacks.
This means organisations are not just recovering from failure. They are recovering from a compromise. The issue isn’t just technical capabilities.
In that context, the central question has changed. It’s no longer: How do we restore everything?
It’s: What do we actually need to operate?
The instinct to restore everything might backfire
In the aftermath of a major cyber incident, the instinct is to bring every system back online as quickly as possible. Get the business running again. It feels like the fastest path to normal. In reality, it often does the opposite – slowing recovery, reintroducing risk, and undermining trust at the exact moment organisations need it most. At its worst, it could shift quickly from a crisis to a siege scenario.
In fact, organisations that recover fastest start from a different premise. They might not necessarily have the most sophisticated security stacks or large IT budgets. However, they are the ones to assume large parts of their organisation will be unavailable or untrusted, and they plan accordingly. This mindset leads to a much clearer goal – restore what matters most, quickly, and in a state you can trust.
A different way of thinking about recovery
This is the idea behind the Minimum Viable Company (MVC) – sometimes referred to as the Minimum Viable Organisation: a definition of what must exist for the organisation to survive.
The term borrows from the startup culture, where a minimum viable product is the smallest version of something that still works. The MVC goes beyond technology. It is a business definition of survival grounded in how organisation creates value. At Cohesity, we define MVC as the minimum combination of people, processes, technology, documentation, facilities and third-party dependencies required to keep the business functioning under extreme conditions.
Cyber resilience goes beyond bringing systems back. It restores the ability to operate safely and credibly, in a trusted state. In other words, MVC is not simply about restoring the minimum number of systems. It is about restoring the minimum amount of trust required for the organisation to operate safely and credibly, and in accordance with regulatory and business obligations.
From strategy to execution
Defining the MVC is only the first step. The real challenge is operationalising it.
There are five key capabilities when it comes to operationalising an MVC.
- Identity critical services: A precise understanding of the systems and dependencies that directly support revenue and mission-critical operations is needed here. If organisations can’t map systems to business value, they can’t define their MVC, and without that, recovery becomes guesswork.
First, start with mapping what is critical by conducting a structured assessment, aligning across business and technology stakeholders, and going through a realistic simulation of how recovery will unfold under pressure. This will uncover the key areas needed to provide just enough capability to keep the organisation functioning safely during a crisis and guide recovery. In practice, this means defining what must function in the first 24 hours, the first 72 hours, and the first week after a disruption.
- Establish a trusted foundation (Tier 0): This is what the practitioners call Tier 0 – the control plane for recovery. It is the foundational layer that allows organisations to establish identity and access control independently of compromised systems. This includes identity and access management, networking and DNS, privileged access controls, core security tooling, physical access systems, and secure communication channels. It also covers non-technical dependencies that are easy to overlook until they’re missing, such as incident response playbooks, contact lists and escalation paths, insurance policies, and contracts with external responders. These are the foundations underpinning the critical systems that need to be restored after a cyber incident. Without this layer, a trusted recovery is not possible.
- Isolation of recovery assets: In the event of a cybersecurity breach, organisations must establish control of their most critical systems. This requires recovering data separately from clean snapshots and investigating in parallel, not sequentially, to ensure the recovered systems are not exposed to reinfection risk. As part of this process, backups, configurations, and recovery tooling must be protected from the same blast radius as production. If key recovery assets can’t be isolated, a rapid and trusted control of critical systems can’t be achieved.
- Clean-room recovery capability: A clean-room provides an isolated environment where teams can examine data, validate recovery points, rebuild systems, test configurations, and coordinate recovery activity without relying on the compromised production environment. To achieve this, organisations need to set up what we call a ‘Digital Jump Bag’. This is a secure, isolated repository containing everything required to establish a trusted recovery starting point to rebuild systems without reintroducing compromise. This matters because cyber recovery is not just a restore operation. It is a trust validation process. A clean environment gives teams the space to make those determinations before reconnecting recovered services to the broader business.
- Validated ability to operate: The next step is to validate the ability of the MVC to operate through realistic crisis scenarios. Across the Asia-Pacific region, many organisations have recovery technology. Fewer have a tested operating model for recovering to a trusted state under active compromise. A Minimum Viable Company bridges that gap. It connects technical recovery with business survivability. Practise is important here because an untested plan remains theoretical. Rehearsals will also help to answer the increasingly pointed question every board asks: How long will it take to restore our critical services to a trusted state?
Recovery as a competitive capability
The real risk isn’t failed backups. It is failing to define what must come back first and how to restore it in a state that can be trusted. Organisations that recover the fastest are the ones who know what must come back first, what must be trusted before it returns. They restore enough to operate, stabilise, and rebuild with confidence. That’s the difference between treating recovery as a process and treating it as a capability.