Research pillar · Zero Security Theatre

Recovery as a first-class discipline

Prevention attracts budget and attention. Recovery is usually delegated to infrastructure, measured by job success, and rehearsed rarely. This pillar studies whether recovery capability is systematically underinvested relative to its effect on total loss.

The question

What is the shortest honest path from a destructive event back to validated operation?

Active · since 2026 · Zero Security Theatre

The core distinction

observation

A successful backup job is not evidence of recoverability. A successful restore is. The two are frequently conflated in reporting, and the difference only becomes visible during the worst week the organisation will have.

Restores fail for ordinary reasons: the backup captured the data but not the configuration, the recovery environment depends on the systems that are down, the credentials needed to restore were stored in the system being restored, or the restore works but takes four days when the business assumed four hours.

Proving that a backup can be restoredTake an isolated copy, restore it into a clean environment, ask the business to validate it, and record the elapsed time and data loss.Backup jobreported successIsolated copyimmutable and offlineClean rebuildtrusted environmentRestoredata and serviceValidatethe business accepts itTimed resultdemonstrated RTO and RPO
A finished backup job proves only that a copy was made.

Capabilities under study

recommendation

Recovery has several parts. Each fails in its own way and needs its own test.

Immutable and isolated copies

Copies an attacker with administrative credentials cannot alter or delete, held where the production identity system has no authority.

Clean-room rebuild

The ability to construct a trusted environment when the existing one must be assumed compromised, including the identity layer.

Credential reset at scale

Rotating every credential, key, token, and service account quickly, which is rehearsed almost nowhere and required in most serious intrusions.

Degraded-mode operation

Running the essential part of the business without the systems that are down, specified in advance rather than improvised.

Dependency recovery

Knowing which third parties must recover before you can, and whether their timelines are compatible with yours.

Recovery communications

What is said to customers, regulators, staff, and partners, with the decision owners named before the event.

The hypothesis about underinvestment

hypothesis

The claim is that recovery testing predicts readiness for destructive attacks better than backup configuration does, and that budget allocation does not reflect this. Both halves need evidence: the predictive claim from incident outcome data, the allocation claim from spending patterns.

What would prove us wrong?

unknown

The pillar assumes recovery capability is underweighted relative to prevention.

  • Outcome data showing that organisations with strong prevention rarely reach the point where recovery capability determines the loss.
  • Evidence that recovery drills at meaningful scale cost more in disruption than the expected loss they mitigate.
  • Cases where backup configuration quality alone predicted successful recovery as well as rehearsed restores did.

Put this to work

Research decision record

Use the question “What is the shortest honest path from a destructive event back to validated operation?” on a real case and produce a record another person can challenge.

For
Practitioners, researchers, founders, and operating leaders.
What you keep
A research decision record you can review, revise, and send.
What counts as sound
  • Answers a named decision
  • Separates evidence from assumptions
  • Includes the strongest contrary case
  • Names missing evidence
  • Ends with a test, owner, and date

The result is a working analysis. Check it against source evidence and qualified judgment.

Nothing entered here is stored or sent. Review the prompt before sharing confidential, personal, patient, or privileged information.

Review the prompt

You can leave any field blank. The prompt will mark it as not provided.

If the record survives your review, send the question, evidence, unknowns, and requested next step.

Experiments for this pillar

Patterns and anti-patterns

  • Pattern

    Publish the demonstrated result beside the target

    Every recovery objective appears with the timed result of the last real restore and its date. Empty cells are the honest output for systems that have never been recovered.

  • Anti-pattern

    Reporting backup job success as recoverability

    A finished job says the data was copied. Recoverability is demonstrated by a timed restore into a clean environment that the business accepts.

See the full patterns register

Evidence for this pillar

Read the full evidence library

Notes under this pillar

Operating Theorys