The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/The Business of Cybersecurity
The Business of Cybersecurity artwork

Commvault On Cyber Recovery Why Disaster Plans Fall Short

The Business of Cybersecurity · 2026-05-03 · 31 min

0:00--:--

Key moments - from our scoring

Substance score

60 / 100

Five dimensions, 20 points each

Insight Density12 / 20
Originality10 / 20
Guest Caliber14 / 20
Specificity & Evidence11 / 20
Conversational Craft13 / 20

The UK Cybersecurity and Resilience Bill represents a significant regulatory evolution, marking the first major update to UK cyber legislation since NIS 2018. Mark Molyneux explains that while regulations like DORA and the CSRB are often treated as compliance checkboxes, recent high-impact incidents - including the JLR ransomware attack that cost £1.9 billion and disrupted manufacturing for four weeks - are forcing genuine organizational rethinking. The critical insight is that cyber resilience differs fundamentally from disaster recovery. Traditional disaster recovery assumes your systems and backups are intact and accessible; cyber recovery must assume attackers have compromised everything, including identity systems like Active Directory. This requires new metrics: mean time to clean recovery, cyber recovery time objectives, and cyber recovery point objectives instead of standard RTO/RPO frameworks. Organizations should adopt established frameworks like NIST Cybersecurity Framework (which underpins DORA), conduct honest self-assessments of recovery capabilities, and recognize that recovery windows - currently often exceeding 30 days - represent material business risk. The conversation addresses how to connect resilience investments to executive ROI through tabletop exercises that demonstrate the real impact of extended downtime.

Key takeaways

  • →Cyber resilience is fundamentally different from disaster recovery because it assumes attackers have compromised all systems including identity infrastructure, requiring new metrics like mean time to clean recovery rather than traditional RTO/RPO.
  • →The UK Cybersecurity and Resilience Bill has been years in development and faces a 1-2 year adoption timeline post-passage, meaning organizations shouldn't wait for legislation to drive action but should implement frameworks now.
  • →Recent major incidents like JLR (£1.9 billion impact, four-week manufacturing downtime) demonstrate that well-resourced organizations still lack cyber recovery capabilities, making this a business continuity issue, not just IT security.
  • →Organizations should select a single cybersecurity framework like NIST and build against it rather than attempting to juggle multiple compliance regimes, and small-to-medium businesses can start with Cyber Essentials Plus as a baseline.
  • →Tabletop exercises showing C-level executives how cyber incidents extend traditional recovery windows from hours to weeks or months are more effective at securing resilience investment than abstract risk discussions.

In this episode

  1. 1Introduction to the UK Cybersecurity and Resilience Bill
  2. 2Why the Bill is Being Introduced Now and Recent Major Incidents
  3. 3Understanding the Scope and Evolution of CSRB
  4. 4Compliance vs. Genuine Resilience Preparation
  5. 5Framework Selection and Regulatory Alignment Strategy
  6. 6Shifting from Disaster Recovery to Cyber Recovery Metrics
  7. 7Practical First Steps for Organizations of All Sizes
  8. 8Connecting Resilience Investments to Board-Level ROI

Mentioned

CommvaultDenodoNordLayerMark MolyneuxNational Cyber Security CentreJaguar Land RoverSynnovisBritish LibraryNIST Cybersecurity FrameworkCyber EssentialsDORA

Guests

Mark Molyneux

Topics in this episode

NIST Cybersecurity FrameworkUK Cybersecurity and Resilience Bill (CSRB)Cyber recovery versus disaster recoveryMean time to clean recovery (MTCR)Digital Operational Resiliency Act (DORA)Cyber Essentials PlusNetwork and Information Systems Regulation (NIS 2018)JLR ransomware attackSynovus ransomware incidentRecovery Time Objective (RTO)

Questions this episode answers

What is the UK Cybersecurity and Resilience Bill and why is it being introduced now?

The CSRB is legislation updating UK cyber requirements since NIS 2018, designed to strengthen defenses for essential services like healthcare, energy, and water through stronger resilience requirements, improved reporting, and aligned fines similar to GDPR. It's being introduced now because cyber threats have evolved significantly since 2018 and recent major incidents like JLR and Synovus ransomware attacks demonstrated gaps in current protections.

What is the difference between cyber recovery and disaster recovery?

Disaster recovery assumes systems and backups remain intact and accessible, using standard metrics like RTO and RPO. Cyber recovery must assume attackers have compromised everything including identity systems, requiring different metrics like mean time to clean recovery and cyber RTO/RPO that account for forensic validation and clean restoration of corrupted data.

How long does it typically take for cyber regulations to be fully implemented after passage?

Based on UK operational resilience (PS 21-3), regulations can take 5-6 years from initial discussion to full compliance adoption, meaning the CSRB could have a 1-2 year adoption timeline after parliamentary passage during which organizations should not wait to begin implementation.

What framework should organizations choose to prepare for cyber resilience requirements?

Organizations should select the NIST Cybersecurity Framework as their primary guide, as it underpins both DORA (Digital Operational Resiliency Act) for EU financial services and provides a strong metric for implementing cybersecurity across industries, rather than attempting to manage multiple compliance frameworks simultaneously.

What are the first practical steps a small-to-medium business should take to prepare for the CSRB?

SMBs should pursue Cyber Essentials or Cyber Essentials Plus certification from the National Cyber Security Center as a baseline, conduct self-assessments of current recovery capabilities, and recognize that mean time to clean recovery is likely north of 30 days and requires improvement.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

12 / 20

The episode contains solid foundational concepts about cyber recovery vs. disaster recovery and the difference between prevention-focused and resilience-focused strategies. However, much of the content revolves around regulatory timeline explanation and framework selection (NIST, Cyber Essentials) that are well-established practices. The distinction between recovery time objectives and mean time to clean recovery is valuable, but specific technical depth on implementation is limited. Several segments repeat earlier points rather than layering new insights.

cyber resiliency is very different to that because the expectation is a cyber threat act has got into the system and none of those capabilities are available
You need to look at the meantime to clean recovery rather than the recovery time objects

Originality

10 / 20

The core framing of cyber recovery as distinct from disaster recovery is useful but not novel - this distinction has been established in security literature for several years. The minimum viable company concept is repackaged thinking from established business continuity practices. The regulatory timeline commentary and framework recommendations (NIST, DORA, NIS 2) are standard industry references. The JLR example is current but used mainly to illustrate compliance rationale rather than to surface contrarian or first-principles thinking.

Select a cybersecurity framework and stick to it. Don't try to run from two or three or four. Pick an industry leader like the NIST cybersecurity framework, for example.
Why do I need a clean room? Why do I need forensic tools when I've got antivirus installed or, you know, I'm really secure on the perimeter.

Guest Caliber

14 / 20

Mark Molyneux brings 35 years of IT industry experience, 28 in financial services, and has held CTO roles at multiple vendors. He demonstrates fluency with regulatory timelines, frameworks, and real incident analysis. However, his current role as Field CTO focused on thought leadership and business development rather than hands-on execution of large-scale cyber recovery operations limits his direct practitioner credibility. He speaks authoritatively but somewhat at a consulting/advisory level rather than from recent operational crisis management.

I've worked in the IT industry for 35 years, 28 of those, I was in financial services companies, started off as a programmer, moved into leading technology groups
I focus primarily on business development, so thought leadership, vision discussions with prospects and customers

Specificity & Evidence

11 / 20

The episode references specific incidents (JLR £1.9bn loss, Synovus ransomware, British Library breach) and regulatory frameworks (CSRB, DORA, NIS 2, PS 21-3) with approximate timelines. However, concrete numbers on recovery metrics, specific technical configurations, or named implementation examples are sparse. The JLR recovery timeline (four weeks down) is inferred rather than confirmed. General references to 'north of 30 days' for mean time to clean recovery lack supporting data. Most practical guidance remains framework-level rather than specific tactical detail.

the cyber attack on Jaguar Land Rover, I think it cost an estimated £1.9 billion, not dollars, pounds
their mean time to clean recovery was really long... given the fact that they had manufacturing down for four weeks

Conversational Craft

13 / 20

The host demonstrates competent questioning around regulatory intent, business case justification, and implementation steps. Follow-ups are generally logical (asking how to manage complexity, how to connect to board ROI, whether regulation keeps pace with threats). However, questions tend to accept the guest's framing without substantive pushback or challenge. There is no attempt to probe contradictions - for instance, the claim that companies will move beyond compliance because of recent incidents versus the historical pattern of tick-box compliance after GDPR. Softball transitions and affirming statements ('so many big takeaways') limit critical depth.

So how should they approach this without creating more complexity or duplication of effort?
And I think a decade ago, the board infamously struggled to understand the value in what might happen. But thankfully, that mindset has largely changed.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

cyber48recovery28resiliency22resilience18security18different15today13bill13start13disaster12seen11regulation11example11minimum11back10long10

Episode notes

What happens when cyber resilience shifts from an IT concern to something that directly impacts revenue, operations, and even national stability? In this episode of The Business of Cybersecurity, I sit down with Mark Molyneux, Field CTO for Northern Europe at Commvault, to break down the UK’s Cyber Security and Resilience Bill and what it really means for organizations trying to stay ahead of increasingly complex threats. At first glance, legislation like this can feel distant, something for compliance teams to worry about later. But as Mark explains, the reality is far more immediate. This bill has been years in the making, shaped by a growing pattern of incidents that have moved beyond isolated IT problems and into events with real economic and societal impact. The conversation quickly shifts from what the bill says to why it matters right now, especially as cyber threats continue to evolve faster than regulation can keep up. One of the most valuable takeaways from our discussion is the distinction between disaster recovery and true cyber recovery. Many organizations believe they are prepared because they have invested heavily in backup systems and failover environments.

Full transcript

31 min

Transcribed and scored by The B2B Podcast Index.

I'd like to thank Denodo for supporting the Tech Talks Network and helping us bring so many different stories to life. Because every business needs data that its teams can actually trust. So if you need data your teams can trust, Denodo can help your organization deliver curated, governed and easy to use data products for analysts, business users and AI applications alike. And you can learn more by simply visiting denodo .

com. What happens when cyber resilience stops being a technical discussion and starts becoming a boardroom issue with very real economic consequences? Well on today's episode I'm going to be joined by Mark Molyneux, Field CTO for Northern Europe at Commvault. And our conversation today feels for me especially timely because while regulations don't always make the headlines in the same way as a major breach or ransomware attack, they do often tell us where governments, industries and security leaders believe the biggest risks now sit.

And one of the things I'm looking forward to chatting with Mark about is he doesn't treat the bill as some dry legal update that only compliance teams need to care about. Instead... He brings it back to what really matters for business leaders. Why is this happening now?

What has changed? Will this actually improve resilience or are we heading towards another check the box exercise that looks good on paper but changes very little in practice? So today we're going to get into the very real gap between disaster recovery and cyber recovery. Understand why cyber...

understand why resilience now has to mean much more than prevention and what organisations should be doing right now rather than just waiting for legislation to slowly make its way through Parliament. And there's also a big point in here today about the difference between being technically compliant and being genuinely prepared. and I think this is something that every leader needs to hear. So if you're trying to make sense of what the UK Cybersecurity and Resilience Bill means, and more importantly, what does it mean for you and your organisation, you should find a lot of value in this one.

As someone that records 65 plus interviews a month, I've personally seen a huge increase in browser -based attacks over the past year, whether that be phishing, malicious extensions, account takeovers, the list is long. And it's all happening where people spend most of their time inside the browser. So Nordlayer's new business browser that's built to address exactly that. It blocks malicious sites before they load.

It limits risky behaviors like uncontrolled downloads or data sharing and gives you visibility into how your team interacts with web apps. And it also helps you stay compliant by controlling access and enforcing policies without the need to rely on multiple disconnected tools. So for anyone listening that is thinking seriously about reducing risk in SAS -heavy environments, this feels like a smarter and more focused approach. And you can learn more about it by visiting NordLayer .

com slash browser. Let me know what you think. But enough from me. Let me introduce you to my guest now.

So a massive warm welcome to the show, Mark. Can you tell everyone listening a little about who you are and what you do? So I'm Mark Molyneux. I'm the CTO for Northern Europe for Commvault.

At Commvault, I focus primarily on business development, so thought leadership, vision discussions with prospects and customers, focused on outcomes rather than product items. So I do online articles for press, speaking at trade events, media engagements, that kind of thing. I've worked in the IT industry for 35 years, 28 of those, I was in financial services companies, started off as a programmer, moved into leading technology groups, and then I jumped over to the vendor side.

where I've held CTO roles at two other technology firms before I joined Commvault. Excellent. Well, thank you so much for joining me today. There's so much I want to talk about.

I mean, I know we will have people listening all around the world. Here in the UK, the cyber security and resilience bell is gaining some traction right now. But for anyone that's hearing about that bell for the first time on this podcast, can you just give us an overview of what it is, what it's aiming to change and why it's being introduced now? I'll start with the end.

So why is it being introduced now? I think it's long overdue. So the UK hasn't materially updated any of its cyber security legislation since NIS came along in 2018, Network and Information Security Regulation. And given the speed that cyber threats have evolved, it's a significant gap.

So the bill was proposed originally back in 2022 to address the shortcomings of that original NIS 2018. And then there's a gap. And in 2024, the King's speech to Parliament, they went into more detail on cyber resiliency, announced the intention to enshrine capability into law. They created the Cybersecurity Resiliency Bill outline in September of that year, 24.

policy statement was in April 25, its first reading in parliament was November 25, now it's had its second reading and it's just in committee stage, so I think why is it being introduced now? It's actually been years in the making and still is, you know, it's expected to move through parliament but not at some huge pace, so I think it's long overdue, but what it's designed to do is deliver a fundamental step change in the UK's national security. So basically strengthening cyber defences for essential services like healthcare transport, drinking water providers, energy companies.

It reforms and adds to the NIS 2018 regulations. So it also learns from the EU's NIS 2 directive. It aligns where it's applicable, but obviously learns what they've done with NIS 2 and implements that as well. it better protect services that public are relying on to go about their normal lives, but overall it's regulating to implement stronger cyber resilience, improving reporting, application of fines, so very much aligned to GDPR in the way that it does its fines, and increasing scope through designated critical suppliers.

Now it does actually reduce the number of in -scope sectors to a more focused list, which could be a bit of a concern, but In a nutshell, that's effectively what the Cyber Security Resiliency Bill is. I'll call it CSRB for simplicity. And if we look at last year, I think the cyber attack on Jaguar Land Rover, I think it cost an estimated £1 .9 billion, not dollars, pounds.

It's been called the most economically damaging cyber event in UK history. So I completely agree with you. This is long overdue. We've seen so many major incidents recently.

So to what extent is this bill maybe a response to the evolving landscape, including ransomware and supply chain attacks, et cetera? Yeah, I think, I mean, certainly the JLR one is a more recent example of that. We've got some that go back further. If you think about in 24, when they were putting the King's speech together, just prior to that, they had the Synovus incident, which was effectively ransomware hitting a couple of trusts in the London area, but also supply chain as well.

And it was ransomware that didn't just hit systems, it cancelled operations, it disrupts, blood tested. triggers a national appeal for blood donors, and it had a societal impact. And that's not something that was easily forgotten. And we were also coming off the back of an incident, a fairly major incident with the British Library as well.

So the government were reacting to those things when they started looking at the Cybersecurity and Resiliency Bill. Now, I think part of the challenge that we've seen more recently is, if you think about the impacts on the retail and the manufacturing sectors, you've obviously mentioned JLR, but we've also seen fairly public events happening to you others in the retail district. Neither of those manufacturing or retail are included in the CSRB as critical. which is quite interesting, I think, because I wonder if part of what we see now with the delays in parliament is a reconsideration of what we might actually include in there, because I don't think anybody really expected an impact on a company like JLR, for example, to actually impact the economy of a country.

Now, if you think about how financial services regulation evolved, that evolved right the way back from the 2008 financial crisis because of the impact on the national financial capability. So they evolved that. They split the regulators. They created a bunch of different regulations to ensure that the financial industry could never suffer like that again, including cyber resiliency stuff, which we can talk about later.

But I think I do wonder if now we will see some changes. into the construct of the CSRB to include maybe manufacturing and retail and perhaps some other industries that you would actually now classify as critical but would fall between the lines of what CSRB is trying to do and what critical national infrastructure is defined as. It's such a great point there and I'm curious from your perspective at Commvault, do you see this legislation actually improving resilience or is there a risk it could fall into the trap of becoming just another compliance exercise or are you quite optimistic about this?

I think I'm more optimistic about this than I've been about other things. We've seen operational resilience, let's call it operational resilience, sneaking into a lot of regulation across various verticals. and that has been more of a tip box exercise, it's you know what's the bare minimum that I can do to actually be compliant to this in terms of resiliency because we all know we can be resilient, we know what we've got a disaster recovery plan. I think cyber took a different angle to that and even though we've had bad things happen to us in the last couple of years I think those will now derive a far better take up of regulation, a far more candid approach to how they do it rather than just treating it as a tick box exercise, because I don't think companies have realised up until we have those major public events that things were so bad, because a lot of companies keep these things back, you know, they'll talk to the National Cyber Security Centre, they'll talk to the police, etc.

And most things don't get public, you don't really know what's happened until they happen. When you've got an event like JLR that affects the economy, and the government are talking about it, and it's in the media every day, it really brings it out at the sea level of every company wondering, hey, could this happen to us? And the realisation that it will. happen to us.

And, you know, it's probably it's not a case of if now it's when it happens to us. Can we recover? So I do think companies will go a lot further with it, but I do worry as with every other regulation. I mean, I, I talked through that timeline a minute ago for a reason.

You can see just how long it is from a discussion to the reality of it happening. And then there's also adoption times. You know, you, you think financial services, UK operational resiliency, which was called PS 21 dash three. That was talked about in 2018 into 19.

It came into life in 2020. It only became, let's call it, fully compliant in 2025. That's five years, six years. Wow, that's phenomenal.

I mean, five, six years in today's climate, the speed of technological change. You look at how much has changed in the last, what, two to three years alone. That's a long time, isn't it? It's crazy, really, when you think about it.

And like I said, if you think about the CSRB, it will almost certainly have an adoption time scale that comes after it. And that could be a year, it could be 18 months, it could be two years, depending on how much they feel that companies have evolved in the meantime. companies that wait for regulation to come along and then look at how they can be you know how they can be compliant to it are basically looking at the minimum side of things and that's not how they should be approaching things they should be really looking at a case of you know of when we get attacked how can we recover from it and can we react super quickly to do that can we change now You know, CSRB is written, you know, that what happens to it now is going to be, you know, elements of parliamentary change.

And as I say, perhaps some scope increase in terms of what happens with manufacturing and retail. But the lion's share of it's already there. So it's something that can be implemented immediately and also not just looked at by companies that are in that mix of health care or, you know, energy companies or whatever. Anyone can really pick that up in the same way that they can pick up copies of Dora and do the same thing.

100 % with you and we will have people listening from organisations that maybe already feel stretched by existing frameworks and regulations trying to keep up to speed with those. So how should they approach this without creating more complexity or duplication of effort? because it can feel incredibly overwhelming when there's something else that you need to follow. Yeah, of course it can, I think.

And that's the challenge with compliance, isn't it? You know, where do you stop? You know, you've got so many different laws that are requiring you to do different things, you know, be it the privacy of a person or the security of a company, you know, the safety, et cetera. So where do you start?

I mean, probably the best place to start really is... Select a cybersecurity framework and stick to it. Don't try to run from two or three or four. Pick an industry leader like the NIST cybersecurity framework, for example.

I use NIST because NIST was also the basis for DORA, the Digital Operational Resiliency Act, which is spanning the EU countries in financial services and supporting companies. That framework gives you a really strong metric in how to implement cybersecurity. So I would say from a start of a 10 pick a framework. There's other things that you can do in terms of training, et cetera, but that's got to be the start of a 10.

And I also think... If you're in an industry that isn't necessarily as tightly governed, you know, say, for example, you are in an industry that doesn't have a door or it doesn't have the impacts of the CSRB, there's no reason why you can't pick those things up. You haven't got a regulator leaning over your back. You're not going to see those regulatory fines coming your way.

So why not pick it up and start looking at it and learning from it and saying, you know what, actually, these are the bare minimum things that we can do. And also, you know, educate the C level of your company and the capability for cyber recovery, cyber resiliency, not just disaster recovery, which is where I think a lot of people are at the moment. And I think there's one word we've both mentioned multiple times in our conversation so far, that is resilience. And the bill places a very strong emphasis on resilience, not just prevention.

So how does this shift the way businesses think about cyber security strategies and investment? It feels like there's a slight pivot there. Yeah, there is. Yeah.

Yeah. Resilient resiliency is about the ability to maintain operations in the face of any craziness that happens. And I think in the past, everybody's been looking at, you know, they've been looking at operational resiliency, which is different to cyber resiliency. You know, if you think about how your recovery of your company is usually split into three, it's operational resiliency, it's disaster recovery, and then it's cyber resiliency.

And those three things, you know, are the things that everyone has, but they have the first two. They don't necessarily have the cyber resiliency aspect. And I think if you think about how people need to look at this in terms of their investment. Look at the way that your metrics at the moment for disaster recovery.

It's usually based on standard metrics like recovery time objective, recovery point objective, mean time to detect, loads of different types of sec ops and IT operations metrics that determine the ability to be able to recover from a disaster. And all your investment's gone into that. Probably a huge amount of investment because they're usually a mirror copy of production. And cyber resiliency is very different to that because the expectation is a cyber threat act has got into the system and none of those capabilities are available.

So what do you then do? You have to have a different metric. So you need to look at the meantime to clean recovery rather than the recovery time objects. If you've got a recovery time objective for a tier one application of five seconds or five minutes or five hours, none of those are going to work if you can't even access the system because say, for example, your Identity system like Active Directory, for example, has been compromised.

So how do you, you can't even go to those metrics. So you need, you know, do you need something like cyber recovery time objective, cyber recovery point objective, and operate that within mean time to clean recovery. So you've got that whole window that says, if an event happens, this is what we look like. And that's your baseline.

And it will be terrible. It will be north of 30 days, probably. You speak to somebody and they probably wouldn't have thought that it would have been that long until it happened to them. JLR was the same.

We don't know for certain, but we can guesstimate it with JLR, for example, given the fact that they had manufacturing down for four weeks. So we know that their mean time to clean recovery was really long. and their ability to shorten that wasn't there. And that's what companies need to look at now in the way that they're investing it.

It's how can we bring those timelines down? How can we look at our data and recover it in a clean manner, forensically check it to make sure that we're not reinfecting ourselves? And many companies will be listening or people listening from companies will be listening and they'll still be quite early on that cyber maturity journey that many organizations are on right now. But what would you say are the first practical steps that they should be taking right now to prepare for what's coming, especially as we're talking about agentic AR, we're adding more things into the mix.

But what should they be thinking about now to prepare for the bill? I think it all depends on the size of the company, I would say. If you're a small to medium business, you should be looking at something fairly standard like Cyber Essentials, Cyber Essentials Plus. That's recommended by the National Cyber Security Center as a, let's call it a start of a 10, for improving your capability in cyber.

cybersecurity and cyber resiliency. Now, there are negatives to cyber essentials plus in that it's a point in time audit of your capability. So on that given day in the area that the auditors check, you might actually be compliant, but in another area, you might not be compliant, but it's better to start somewhere than nowhere. And that's a really good way of being able to say, well, okay, this is the government and the NCSC recommendations.

So this is a good investment for a starter for 10. And I think if you're a bigger company, if you're in the enterprise capability, there's a good chance you've already started on this journey anyway. And as I said, I think you need to select a cybersecurity framework to operate to. I think you need to recognize that there are capabilities out there in terms of already written material.

We've mentioned Dora, for example. I think those are very good, very strong. cyber resiliency frameworks that can be picked up and learned from and and then take a look at yourself you've got to do a self -assessment to be realistic and say can i can i recover from a cyber event as i said a minute ago those metrics that you live by that are enshrined in disaster recovery and they're in there for a reason. You've defined resiliency categories, you've defined impact tolerances so you know how long you can be without a system before there's a serious problem.

You might have defined a manual operation, you know, where you've got 20 people that sit in a room and just do that job for so many days. But what's the longevity of that? Can you do that for two weeks, two months or six months? That's the sort of thing that you've got to look at.

You've got to look at yourself and say, what are my capabilities today? How can I improve them? what do I need to do as the start of a tenon as I said I think certainly cyber essentials plus the cyber security framework picking up a copy of an existing material talking to companies like us you know people like me are good to talk to in terms of advice and guidance and areas to look at You know, trying to pick through the stew of some of the things that are out there, like, you know, why do I need a clean room?

Why do I need forensic tools when I've got antivirus installed or, you know, I'm really secure on the perimeter. Those kind of things are great. But when you talk to companies like us and we can give you real life examples that say, well, OK, look at what happened to JLR. They probably had all of those things in place as well, but it still happened.

And because it happened, what could they then have done to do things differently? And this is where we're looking at now in terms of the practical steps. And one of the other ongoing challenges in cyber security is proving the return on investment to the board. And I think a decade ago, the board infamously struggled to understand the value in what might happen.

But thankfully, that mindset has largely changed. But how can leaders still connect resilience investments to real business outcomes in a way that gets that executive buying? Yeah, so it's a real challenge, isn't it? I think it's not dissimilar to the challenge that we faced when we were trying to secure funding for disaster recovery environments.

Why do we need that? It'll never happen. And then we did see events that happened. The go back 30 years and the cited example of disaster recovery was a plane hit in a building.

Well, of course, we've seen that happen in real life. We've seen floods because we've seen what happened in Japan. We've seen fires. We've seen theft.

earthquakes, depending on the region that you're in, all of these things cause chaos for DR, which secured funding. What we've now got is really good examples of cyber incidents where companies that you could say with absolute certainty had spent a fortune on defensive perimeter and disaster recovery were still exposed and were still down for a considerable amount of time. I think that's a good example to be able to show to the board. But I think the only way you're going to be able to link it to the ROI is by First of all, running the tabletop exercise.

I found that to be really good. When I've run tabletop exercises with C level executives, their eyes are opened because they don't realize just what can happen. You know, we're running them through a real life event where a threat actor gets into the system irrespective and corrupts everything. They can't do anything.

They don't know where to start. You know, they can't even get access to the building in some cases if they've taken out access control. So run them through a tabletop exercise. Use their existing metrics, like I said before, with RPO and RTO, show them what they've got today in terms of their disaster capabilities for recovery, and then play that cyber over the top of it and say, well, OK, that two hours is now two days.

What does that mean to your business? And that's how you start to show the ROI, because most of these C -level executives will understand what it means for that business to be down for 24 hours. But what happens if it's two weeks? You know, suddenly it's orders of magnitude different.

They need to be educated on the requirements for a minimum viable company. And that doesn't mean throwing absolutely everything that you own into a cyber secure vault, an air -gapped vault. It's defining a minimum viability. What is the absolute minimum that I can have online to continue my business?

So that's not every single application, every single person's business, maybe even every person logging on. It's the minimum viability. And that includes technology groups as well. So in my MVC, I'm going to have all of my IT stuff.

I'm going to have elements of Active Directory, networking, storage, server, et cetera. And then building up through that stack, that's minimum viability. And that's another way of being able to show to the board what their return on investment is. Because it's saying, well, OK, you might not be able to get all of this other stuff online for two weeks.

But if I can bring up minimum viable capability within, say, six hours, that's a material difference to be able to continue my business and it might be the difference between staying operational and folding as a company. Wow, so many big takeaways in your answer there and if we were to dare to look further ahead, do you think regulations like this will keep pace with the speed of cyber threats, the speed of technological change or will organisations still need to go beyond compliance to truly stay protected?

How do you see them getting that balance right? I think it's really hard with regulation to keep in lockstep. And I think we've used a really good example earlier with the cyber security resiliency bill and the amount of time it's taken to do that. And we can even say with DORA, DORA is an exceptional framework for cyber security and financial services, but it was still years in the making and then another two years to become enforceable.

NIS 2 is another really good one across the EU, you know, it's a directive so it isn't immediately enshrined into law, it's taken way longer than it should have done to be enshrined into law and it still isn't in law in many countries. So I think regulation has proven that it can't keep in lockstep, but... The frameworks move the needle, and that's all IT security is, is risk management. It's moving that needle.

And if you don't do anything, you're going to be in a terrible state. So what you've got to do is you've got to take a framework and you've got to start implementing these capabilities. You've got to start giving yourself the ability to have a clean room, to be able to do forensic assessment of data, to be able to do recovery, to have a minimum viable company concept and actually test it. you know, part of these resiliency requirements is continuous testing.

It isn't like a once a year DR test. It's tested every week, if you can, because it gets it ingrained into people's DNA. They understand what it is that they've got to do when these things happen. And I think regulation can never keep up with that, but companies can go further.

They can say, well, OK, this is what it looks like today. I need to move that needle because if there is going to be something different, AI is going to drive a very different way that cyber happens. We've already seen that at the basic level with DDoS attacks, where it was, you know, sometimes it was a kid in a room just firing off DDoS. Now it's AI that just tries and tries and tries and tries and tries until it finds the hit.

That's the difference. You know, it's going to be. quicker to get into a company than ever before. Once they're in there, they can use AI to be able to laterally move in a very different way and to be able to do data collection in a very different way and gain elevated privileges.

So drawing all of that back, number one, regulation is never going to keep up with that. And number two, yes, organisations have to go beyond what the compliance requirement is to stay protected, but you're never going to be 100%. But you have to move that needle. I think that is a powerful moment to end on and we did cover a lot there in a short amount of time and for anyone listening who equally feel somewhat inspired having listened to there it makes more sense now and they want to talk more about the UK cyber security and resilience bill or read more about some of the preparations some of the things that you're doing at Commvault I'm sure you guys create a lot of content as well on this.

Where can people keep up to speed with anything we've talked about today? Any way you want me to point them? Yeah, cool. So yeah, a couple of websites, I'd say readyverse .

com, which is R -E -A -D -I -V -E -R -S -E, readyverse .com. That's a Commvault website that talks about resiliency operations, which is a capability that we're looking to try and socialize across companies to be more resilient. It talks about AI security, trust, et cetera, how to survive cyber events.

And of course, Commvault .com, obviously. And then you can hit me up as well. I'm on LinkedIn.

Awesome, I'll have links to absolutely everything and please wherever you are listening in the world, anything that resonated with you, anything that you're doing, you're doing differently or anything you're having challenges with, please feedback to myself or Mark and we'd love to hear from you and hear what you're doing at the moment. But more than anything, Mark, thank you for sitting down with me, starting this conversation and putting it in a language everyone can understand.

Really appreciate your time today. No, my pleasure, Neil. Thanks for having me. Wow.

There is a lot in this conversation with Mark that stood out today, but the biggest takeaway for me is probably that compliance might tell you what the minimum looks like, but resilience, that is about whether you can actually keep the business alive when something goes badly wrong. And that is a very different mindset, and I think Mark explained it brilliantly today. Too often organisations have treated cyber as something to prevent, to monitor, to report on, all while hoping recovery plans will somehow take care of the rest.

But cyber recovery is not the same as disaster recovery. Because if core systems, identities and trusted environments are compromised, the old assumptions around recovery times and failover plans, they can unravel very quickly. And I also thought his point about tabletop exercises was an important one too, because it's easy for executives to approve budgets in theory or sign off policies that sound sensible, but it's much, much harder to sit in a room, walk through a realistic attack scenario and face the actual consequences of what downtime, uncertainty and slow recovery actually mean for your business.

And this is where resilience stops being abstract. This is also where the conversation around the UK Security and Resilience Bill becomes much more interesting, because whatever happens next in Parliament, and however long that full process takes, the underlying message here is already clear. Waiting for regulation to force action is possibly the slowest and weakest response available. The smarter move is to use this moment as a push to assess your own readiness right now.

But I'd love to hear your take on this one. Will legislation like the Cybersecurity and Resilience Bill genuinely strengthen organisational resilience or will the real difference still come down to which businesses decide to go further than compliance and prepare properly before they have to? As always techtalksnetwork .com let me know your thoughts on this one and I'll be back again very soon with another guest.

Speak to you then. Bye for now. Bye.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • AI Governance Essentials: Navigating Security and Compliance in Enterprise AI with Walter HaydockCyber Sentries: AI Insight to Cloud Security · on NIST Cybersecurity Framework85 / 100
  • The Illusion of Control: Cybersecurity, AI and the Risks Beneath the SurfaceThe Financial Executives Edge · on NIST Cybersecurity Framework72 / 100
  • Special Episode - EliteCast Episode 1Purple Squad Security · on NIST Cybersecurity Framework41 / 100
  • 012 - Imperative 5 Better Equip Government to Function Effectively and Securely in the Digital AgeReport on Securing and Growing the Digital Economy · on NIST Cybersecurity Framework38 / 100
  • NIST Cybersecurity Framework for Nonprofits | Shaun St.HillTech & Main Presents · on NIST Cybersecurity Framework38 / 100

More from The Business of Cybersecurity

All episodes →
  • Closing the AI Vulnerability Remediation Gap With Cobalt74 / 100
  • Mimecast CISO On Why AI Has Become A Cybersecurity Risk60 / 100
  • Orange Cyberdefense On The New FCA Cyber Reporting Rules76 / 100
  • Deepfakes, AI Agents, and the Collapse of Traditional Identity Security66 / 100
  • When Identity Becomes The Front Line Of Cybersecurity71 / 100
All The Business of Cybersecurity episodes →