Start with the business, not the technology
Organisations that recover fastest in this new AI era do not begin by asking how to restore everything. They ask what must keep operating for the organisation to survive. This is the value of defining a Minimum Viable Company: the smallest combination of services, people, processes, data, systems, suppliers and decision paths required to continue operating safely during a crisis.
Five priorities for AI-era business resilience
First, map critical services to business value. AI further compresses attacker timelines, with agentic tools able to support reconnaissance, lateral movement and elements of extortion with less human input, so recovery priorities must be clear before an incident. Leaders should know what must function in the first 24 hours, 72 hours and the first week, and which systems, identities, data sets and third parties those services depend on.
Second, protect the trusted foundation. Identity, privileged access, networking, DNS, security tooling and secure communications form the control plane for recovery. If these foundations are compromised, organisations may restore systems quickly but still be unable to trust them. Zero Trust principles, strong access controls, and secure-by-design practices matter more as attackers use AI to move faster and test more routes into the environment.
Third, protect recovery from agentic attacks. Organisations need immutable, isolated recovery points that attackers cannot alter or delete, supported by AI-driven anomaly detection within the data estate, not only at the network edge. Traditional perimeter defences and periodic backups are no longer enough on their own.
Fourth, secure AI agents as critical assets. AI can strengthen recovery by scanning backup snapshots for malware, classifying sensitive data, and helping teams see what happened, what was affected, and what can safely return online. But as AI agents interact with infrastructure and business data, they must themselves be carefully considered in the overall prioritisation of critical business processes, and therefore protected, monitored, and, if necessary, rolled back to a known-good state.
Fifth, rehearse recovery under realistic conditions. A plan that has not been tested is only a theory. Organisations should run simulations that assume compromised identities, unavailable systems, uncertain data integrity and incomplete information.
38 WWW. INTELLIGENTCISO. COM