Distinguish failure from a hostile event
Conventional disaster recovery assumes that management systems and backup controls remain trustworthy. After an attack, that assumption is unsafe: an intruder may have changed jobs, deleted recovery points, persisted in an image or obtained administrative authority. Recovery therefore begins with isolation and a new root of trust, not immediate restoration of the latest copy.
Define the minimum viable business
Management sets sequence by business capability rather than server list: identity, communications, payments, production and customer service. Record dependencies, minimum data, RPO, RTO and an acceptable manual mode for each capability.
A plan in which every system is priority one is not a plan.
Prepare the clean room
The clean environment is separated from the compromised estate by network, identity and management planes. It contains verified images, new administrative identities, analysis tools, logging and a controlled path for recovery data. Build infrastructure from code or approved templates rather than cloning an unknown environment.
Limit access to the recovery team, record all activity and inspect every transfer across the boundary.
Validate data and application together
A successfully restored volume is not a restored service. Check hashes, malicious indicators, database integrity, schema versions, secrets, integrations, business transactions and logs. Choose a recovery point using evidence of cleanliness and acceptable data loss, not date alone.
Reconnect through trust stages
Run the service in isolation first, then connect limited dependencies, a test user group and finally production traffic. Each transition has criteria, an accountable approver and rollback. Old tokens, certificates and passwords must not return with the data.
Measure readiness through exercises
A regular exercise should include an unfamiliar scenario, realistic volume, identity recovery, technical and business validation, and an executive decision to release service. Measure time to trusted environment, time to minimum service, achieved RPO, missing dependencies and manual steps. Those indicators show readiness; a green backup-job status does not.

