The urgency trap
Restoring by business loudness instead of technical readiness brings compromised credentials and persistence back in.
A structured, dependency-driven approach to restarting critical IT services after a destructive cyber incident. Vendor-neutral, sector-agnostic, and free to adopt as your organization's own template under a Creative Commons non-commercial license.
Why a restart framework
Technical restoration does not equal trust.
After a destructive cyber incident, such as a wiper attack or enterprise-wide ransomware, one of the most dangerous moments is the rush to get back online. Pressure to restore whatever the loudest part of the business needs, rather than what is technically ready, reintroduces compromised credentials and persistence into an environment that was just cleaned. A booted server is not a clean server. Restoration is not remediation.
The Restart Framework governs that gap: the high-consequence period between containment and eradication on one side, and safe business-as-usual operations on the other. It replaces ad hoc, urgency-driven restoration with disciplined sequencing based on hard technical dependencies.
Restoring by business loudness instead of technical readiness brings compromised credentials and persistence back in.
A restored application does not prove a clean environment or verified data integrity.
EDR telemetry, Zero Trust isolation and identity validation must come before network reconnection, not after it.
Recovery follows hard technical dependencies (identity, network, data), not departmental urgency or convenience.
Scope
The framework complements these disciplines. It does not replace them.
Principles
The framework rests on eleven principles drawn from frontline incident response experience and established cyber resilience standards.
Credentials, code, configuration and access rights are validated before they are reintroduced.
Deliberate, calibrated information flow between technology leaders, the board, regulators and third parties.
Stability and non-reinfection outweigh arbitrary timelines and commercial pressure.
Re-establish core survival infrastructure and a minimum viable business before full feature sets.
Trust requires communicating root cause, current state and remedies, backed by verified system integrity.
Services recover by hard technical prerequisite, such as DNS and identity, not by business urgency.
Telemetry, segmentation, EDR and monitoring are operational before production platforms are revived.
No layer progresses without governance sign-off. The CISO and the Executive Recovery Governance Committee hold veto power.
Iterative, throttled restoration. Mass simultaneous boots create instability and reinfection vectors.
Heightened logging, telemetry and active scanning cover every revived asset.
The full recovery trail is documented and governed, supporting compliance with DORA and NIS2.
Lifecycle
Determine exploit type, vector and blast radius. Sever hybrid sync links. Establish out-of-band communication channels.
Purge threat-actor footprints. Restore infrastructure to known-clean baselines using a hybrid brownfield / greenfield approach.
Verify data and system integrity end to end. Complete Active Directory schema audits and finalize signed executive attestations.
Re-establish connectivity through low-value synthetic test transactions, throttled network adjacency and heightened SOC telemetry.
Each phase requires explicit risk acceptance and sign-off before the next begins. No phase is skipped under pressure. The phase structure is adapted from the CMORG Reconnection Framework (UK financial sector, v3.0, July 2025).
Sequence
Critical IT services are grouped into six layers, sequenced by hard technical dependency. Each layer gates the next.
Out-of-band collaboration and communication, emergency and break-glass access, crisis response archive, internal user communication.
Gate before next layer: All four services operational and free of indicators of compromise.
Data center, network (WAN/LAN, perimeter, DNS/DHCP/NTP, cloud network, secure remote access, Zero Trust segmentation) and compute (hypervisor, storage, app and web servers, enterprise monitoring).
Gate before next layer: Clean baseline reached; hypervisor restored from a clean image; enterprise monitoring live.
EDR, SIEM, DLP, identity and access management, cryptography and PKI, systems and device management.
Gate before next layer: Most controls return in parallel. DLP waits until IAM reaches a baseline operational state.
An air-gapped, immutable environment used to stage, scan and validate clean backups before anything returns to production.
Gate before next layer: Recovery environment network-isolated and confirmed clean before any promotion.
Application recovery plan execution, integrations and middleware, data pipelines, application-level service desk.
Gate before next layer: Layers 2–4 operational; application runbooks and clean backups available.
Executive and major-event support, service desk, onsite support, manufacturing and supply chain support, file shares, productivity software, campus and wireless LAN.
Gate before next layer: Layer 2 operational; IAM in place for access-dependent services.
RTOs are illustrative planning targets for a mature organization, not guarantees. Actual recovery time depends on incident severity, backup posture and preparedness. Real destructive events have taken weeks to fully reconnect.
Recovery model
The framework assumes a hybrid recovery model rather than a full rebuild by default.
Remediate and restore on top of existing infrastructure. It preserves forensic evidence, is faster, and avoids the false confidence a rebuild can create when the true scope of compromise is not yet known.
Use when
A full rebuild, reserved for situations where trust in the existing estate cannot be re-established.
Use when
In practice, most organizations run both at once: hardened components such as identity, PKI and the isolated recovery vault are rebuilt greenfield, while the wider estate is remediated brownfield.
Governance
The CISO and the Executive Recovery Governance Committee hold veto power at every layer threshold.
Incident response / forensics and GRC leads both sign off before any production interconnect.
Verified clean backup hashes, credential rotation and cleared SOC telemetry are required.
Essential services run in temporary, restricted modes while wider recovery continues.
Manual approval queues, read-only database states and restricted user cohorts.
Aggressive EDR policies and real-time egress monitoring during mid-recovery operations.
Adopt it
This is a starting point, not a fixed prescription. Map your own services, set your own targets, and rehearse before you need it.
Place your own critical IT services into the six recovery layers.
Calibrate the illustrative targets to your environment and backup posture.
Name the CISO and GRC owners accountable for each layer's sign-off.
Run tabletop exercises so the sequencing is trusted, not theoretical.
Map the governance evidence to obligations such as DORA and NIS2.
Downloads
Both resources are published by the Cyber Resilience Manifesto under the Creative Commons Attribution-NonCommercial 4.0 license (CC BY-NC 4.0): free to share and adapt for non-commercial use, with attribution.
Submit your contact details once to unlock the handbook and the spreadsheet. The same access applies to both files.
The full framework: scope and boundaries, definitions, the eleven principles, the four-phase lifecycle, the brownfield vs. greenfield decision criteria, the six-layer restart sequence matrix with minimum activation criteria, and the governance and sign-off controls.
Critical-IT-Services-Restart-Framework-Handbook.pdf
The restart sequence matrix in working form. Every critical IT service with its recovery layer ID, domain and sub-domain, service definition, illustrative RTO, sequencing type (series or parallel) and minimum requirements prior to activation. Adapt it to your own estate.
Critical-IT-Services-Restart-Framework-Spreadsheet.xlsx
Submit the form to unlock the files below.
Credits
Francesco Chiarini, Patrick Lechner, Shwetha Babu Prasad
Saketh Varma Namburi, Alex Sharpe, Jordan Schoenherr
© 2026 Cyber Resilience Manifesto. Licensed under CC BY-NC 4.0. License terms
Audience
Cyber resilience leaders, CISOs, incident response and disaster recovery teams, infrastructure and operations leaders, business continuity professionals, technology risk leaders, recovery governance committees and executive decision makers.