Glossary · OT cybersecurity
Disaster recovery
Also known as: DR, IT disaster recovery
German: Notfallwiederherstellung
In business continuity management, disaster recovery is the planned set of procedures and resources for restoring systems, data and infrastructure after a major disruption, such as a fire, flood or cyberattack, within defined recovery time and recovery point objectives.
- OT security
In one sentence
Disaster recovery is the planned restoration of systems, data and infrastructure after a major disruption within defined recovery time and point objectives.
Example
After ransomware encrypted the SCADA servers, the plant followed its disaster recovery plan: rebuilding servers from clean images, restoring the last verified backups and restarting lines in a defined order.
How it applies
- Planning: Disaster recovery plans set a recovery time objective (how long a system may be down) and a recovery point objective (how much data may be lost), and list priorities, responsible people, spare hardware and clean installation media.
- Operation: In OT, recovery must follow the process: restarting controllers in the wrong order or with inconsistent data can create unsafe states. Safety functions must be checked before production resumes.
- Maintenance: Plans must be tested, for example in exercises. They go out of date quickly when systems change.
- Documentation: Manufacturers support recovery with clear restore and recommissioning procedures, lists of required software and license files, and restart instructions. Keep copies of essential manuals available offline, since a disaster may take the document portal down too.
Disaster recovery vs. incident response
Incident response contains and investigates a Security incident. Disaster recovery restores operations afterward. After a cyberattack, recovery should start only once the cause is understood, or the attacker may return with the restored systems.