Incident Response, Data Security

Lean and mean: How the concept of a minimum viable company speeds recovery and boosts resilience

An enterprise cybersecurity team analyzing monitoring logs.

Recovery from cyberattacks or other IT disruption is usually treated as a technical exercise. The goal is to restore all systems, bring applications back online and return the IT environment exactly to its pre-attack state.

Yet that approach often confuses the means with the objective. The real goal should not be to restore all systems, but to keep the organization functioning, maintain delivery to customers, and minimize business disruption.

This distinction matters because businesses may waste time on restoring systems that are not mission-critical. Furthermore, recovery from real incidents rarely proceeds as quickly as planned.

To achieve swift restoration of critical business practices and maximize resilience, organizations need to delineate their "minimum viable company," or the processes, systems, dependencies and personnel that are necessary to get the business back up and running.

During the recovery process, the primary goal should be to get the minimum viable company restored, and nothing more. Once that has been achieved, restoration of less-critical systems can begin.

"It focuses the effort because you have an explicit prioritization," explained Cohesity VP of Product and Solution Marketing Rob Sadowski in a recent interview with Enterprise Security Weekly's Jackie McGuire. "The vast majority of organizations haven't really put that context into their plan."

Why incident response is shifting to business-centric resilience

The traditional recovery model assumes incidents can be contained before recovery begins, dependencies are known and restoration can proceed sequentially.

Unfortunately, modern environments make those assumptions increasingly unreliable. Cloud, SaaS, APIs and AI have multiplied dependencies, while attackers can disrupt operations across interconnected systems.

Yet in Cohesity's 2026 survey of 3,200 IT and security decision-makers, 78% of respondents said their recovery plans still focus more on restoring IT systems than on maintaining critical operations or serving customers.

Doing so would be a waste of precious time and resources. In the same survey, 76% of organizations that experienced a cyberattack overshot their recovery-time objective, with recovery averaging nearly twice as long as planned. Seventy percent discovered that the affected scope of the attack expanded during recovery.

"That's really the difference between the quick recovery that they're looking for and business disruption that they absolutely don't want," said Sadowski.

He argued that recovery should instead be organized around business outcomes. Organizations need to know which systems, applications and data are indispensable — and the dependencies, such as identity infrastructure, required to make them work.

"We used to have a much simpler environment, and it used to be very focused on systems recovery," Sadowski said. "That worked for a while, but today's reality is not that."

The definition of the minimum viable company

That leads to the concept of the minimum viable company (MVC), which Cohesity in its most recent Global Cyber Resilience Report defines as "the smallest, essential version of the business that can continue serving customers and maintaining critical operations while broader recovery continues."

An MVC defines what must be restored first during a recovery process. That means identifying critical business processes and the systems, data, applications, people and dependencies necessary to support them. Everything else can follow later.

This approach narrows the scope of initial recovery scope and creates explicit priorities. But adoption remains limited: Only 37% of organizations that Cohesity surveyed had defined their MVC, and 22% said they had formally documented and tested it.

Among those that had tested their MVC, however, 92% said it influenced recovery priorities, and 64% said it directly determined what was restored first during an attack.

Testing is essential. As Sadowski puts it, an untested recovery plan may be little more than a document whose assumptions have never encountered reality.

"If you haven't tested it, you almost really don't even have a plan," he said. "Does it reflect reality? Can it happen in the way you want?"

Why the impetus for the minimum viable company must come from leadership

The IT department alone cannot define the MVC because technology teams are not positioned to decide which customer commitments, revenue streams and business processes matter most.

Sadowski says the business priorities must come "from the top down," while technical and operational teams map the dependencies necessary to support them.

"You've really got to get those two layers to meet, and I don't think they are meeting that often," he added.

MVC planning must be cross-functional. Executives and business owners can define essential operations. Security, risk and IT teams can translate those requirements into systems, dependencies and recovery sequences. Organizations should then test the model repeatedly, including whether restored systems are clean and safe before production use.

Recovery plans should no longer ask simply, “How quickly can we restore everything?” A more useful question is, “What must we restore first to keep the business operating?”

The minimum viable company provides that organizing principle. By defining critical operations before an incident, mapping dependencies and repeatedly testing the resulting plan, organizations can concentrate scarce recovery resources where they matter most.

Resilience then becomes less about rebuilding everything quickly and more about restoring the right things first, keeping customers served and the business functioning while the broader recovery continues.

Paul Wagenseil

Paul Wagenseil is a custom content strategist for CyberRisk Alliance, leading creation of content developed from CRA research and aligned to the most critical topics of interest for the cybersecurity community. He previously held editor roles focused on the security market at Tom’s Guide, Laptop Magazine, TechNewsDaily.com and SecurityNewsDaily.com.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds