Part V. Recover
Rising from the Ashes Stronger Than Before
The NIST Cybersecurity Framework’s Recover function is about restoring capabilities and services impaired by a cybersecurity incident, and implementing improvements based on lessons learned. The containment walls are holding, the threat is eradicated, and now comes the part everyone’s been waiting for: getting back to business. But recovery isn’t just about speed—it’s about doing it right so you don’t end up right back where you started and coming back stronger than you were before.
Chapter 15, “Restore and Recover”, tackles the methodical process of bringing your organization back to life. You’ll prioritize critical systems, make informed decisions about restore points, and leverage sandbox environments to verify everything is clean before going to production. We’ll cover operating system restoration options (from full reinstalls to golden images), data restoration challenges (including curated restore techniques), and cloud-based recovery strategies. The chapter emphasizes that recovery is a marathon, not a sprint—rushing this phase is how 80% of reinfections happen.
Chapter 16, “Post-Mortem Analysis”, transforms your painful experience into organizational strength. You’ll conduct structured post-mortem meetings with clear documentation, identify root causes through methodical analysis, and turn mistakes into actionable ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access