British Library: recovery can outlast initial disruption
The British Library's disruption lasted far longer than the attack, because so much had to be rebuilt rather than restored.
Systems that were old, interdependent and in some cases no longer supported could not simply be brought back. It is the case to point at when recovery time objectives are being set optimistically: the constraint is often not the backups but whether the thing you are restoring onto still exists.
More on Real incident lessons
- Equifax: knowing about a vulnerability is not knowing it is patchedThe list said five
- Target: supplier access showed why third-party portals need strong segmentation from sensitive systemsThe partitions stop short
- Colonial Pipeline: business shutdown can follow IT compromiseNothing touched the pipe
- Help-desk identity processes are attack surfaces when social engineering can trigger password resets or MFA transferThree answers, and it moves
- Hawaii false missile alert: test and live alert paths need separation because confirmation prompts cannot correct a convinced operatorA hand apart
- CrowdStrike 2024: trusted security software can be concentration riskOne roller, every machine
