Mission and audience
Restore trustworthy mission capability within agreed priorities after cyber, technology, supplier, or environmental disruption.
Recovery is not simply restoring a backup. It requires business priorities, dependencies, capacity, communications, trust validation, and criteria for returning to normal operations.
Guided phase
Understand mission dependencies
Identify critical services, external expectations, organizational dependencies, and prioritized assets.
Actions to take
- Map mission functions to systems, data, people, facilities, suppliers, and communications.
- Define impact, priority, RTO, RPO, and minimum service levels.
- Identify single points of failure and concentration risk.
External Stakeholder Dependencies
Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
Organizational Dependencies
Outcomes, capabilities, and services that the organization depends on are understood and communicated
Asset Prioritization
Assets are prioritized based on classification, criticality, resources, and impact on the mission
Guided phase
Plan resilience and capacity
Maintain operational plans and mechanisms that support normal and adverse conditions.
Actions to take
- Define continuity, disaster recovery, cyber recovery, and crisis coordination boundaries.
- Plan alternate capacity, identity, communications, and dependencies.
- Document degraded-mode and manual-workaround decisions.
Improve Incident Response and Cybersecurity Plans
Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
Resilience Mechanisms
Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
Maintain Resource Capacity
Adequate resource capacity to ensure availability is maintained
Guided phase
Protect and test recovery assets
Create protected backups and use tests and exercises to validate plans and identify improvements.
Actions to take
- Protect backup data, systems, credentials, and administration paths.
- Test restoration, failover, communications, and decision-making.
- Track exercise findings through closure.
Create, Protect, Maintain, and Test Backups
Backups of data are created, protected, maintained, and tested
Improvements from Tests and Exercises
Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
Guided phase
Initiate and perform recovery
Apply recovery criteria, select actions, verify restoration assets, and restore prioritized services.
Actions to take
- Define who can initiate recovery and under what conditions.
- Prioritize restoration based on mission and dependency order.
- Verify backups and build sources before use.
Apply Recovery Initiation Criteria
The criteria for initiating incident recovery are applied
Execute the Recovery Plan
The recovery portion of the incident response plan is executed once initiated from the incident response process
Select and Perform Recovery Actions
Recovery actions are selected, scoped, prioritized, and performed
Verify Backups and Restoration Assets
The integrity of backups and other restoration assets is verified before using them for restoration
Guided phase
Verify, communicate, and improve
Validate restored assets, establish operational norms, declare completion, and communicate progress.
Actions to take
- Validate identity, configuration, data, monitoring, and business function.
- Communicate recovery progress using approved messages.
- Complete documentation and convert lessons into owned improvements.
Establish Post-Incident Operational Norms
Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms
Verify Restored Assets and Normal Operations
The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed
Declare the End of Recovery
The end of incident recovery is declared based on criteria, and incident-related documentation is completed
Communicate Recovery Progress
Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
Share Public Recovery Updates
Public updates on incident recovery are shared using approved methods and messaging
Improvements from Evaluations
Improvements are identified from evaluations
Completion evidence
What should exist when this playbook is working?
- Business impact, dependency, and critical-service map.
- Approved recovery priorities, RTOs, RPOs, and minimum service levels.
- Continuity, disaster recovery, cyber recovery, and communication plans.
- Protected backup and alternate-capacity evidence.
- Exercise, failover, and restoration test results.
- Recovery validation, declaration, communication, and improvement records.
Relationship boundaries
Use the playbook as a decision aid.
Playbook sequence, priorities, checkpoints, and completion evidence are original Bare Metal Cyber editorial guidance. NIST informative references, source-control relationships, D3FEND semantic mappings, curated ATT&CK mitigation mappings, and inferred ATT&CK relationships retain their established labels and limitations.
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. This playbook does not establish legal applicability, contractual scope, compliance, control inheritance, product effectiveness, or guaranteed mitigation.