- Meaning
- Return to normal operations
- Tools
- DRP, BCP, tested backups
- Metrics
- RTO and RPO
- Goal
- Minimise damage and downtime
- Updated
- June 2026
- Editorial team
- Compliance Compass
What is recovery?
Recovery is the concrete activity by which systems, data and processes are brought back to normal operation after an incident – by restoring backups, rebuilding servers or switching to standby systems, for example. Whereas the DRP is the plan and Business continuity describes the overarching goal, recovery is the actual process: what really happens in an emergency. It forms the close of incident handling and decides how quickly an organisation is fully able to work again.
Backups alone are not enough
What matters is not that backups exist, but that in an emergency they can actually be restored. Only regularly tested recoveries give confidence – otherwise you face the nasty surprise that a backup is incomplete, out of date or encrypted along with everything else by ransomware. Backups kept off the network (offline) and documented restart tests have proven their worth.
In practice: a city administration becomes the target of a ransomware attack that encrypts its specialist systems. Because the IT team runs real recovery tests every quarter, it is known that the offline backups are clean and how long restoring them takes. Instead of panicked improvisation the recovery follows a fixed script, and citizen services are reachable again after a few days.
Recovery and contingency planning
Recovery is closely linked to the DRP (the technical plan) and the BCP (the business side) and is aligned to the metrics RTO (maximum recovery time) and RPO (maximum tolerable data loss). These target values set how fast and how completely recovery has to succeed.
Recovery and NIS2
NIS2 explicitly requires backup management and recovery among the risk management measures of Article 21. Recovery is the last step of Incident response and the precondition for real business continuity – without it contingency plans stay ineffective.
Further reading: ISO 22301 – business continuity and recovery (standard overview)
Frequently asked questions
What does recovery mean?
Recovery is the concrete return to normal operations after an incident or outage, for example by restoring backups, rebuilding servers or switching to standby systems. It is the actual activity in an emergency and forms the last step of incident response. Recovery is usually governed by the DRP for the technology and the BCP for the business side. NIS2 requires it explicitly among the risk management measures of Article 21.
Which tools help with recovery?
Recovery relies above all on regularly tested backups, the disaster recovery plan (DRP) for technical IT recovery and the business continuity plan (BCP) for keeping the business running. These tools are steered through the business continuity management system (BCMS) and aligned to the metrics RTO (maximum recovery time) and RPO (maximum tolerable data loss), which set how fast and how completely recovery has to succeed.
Why do backups have to be tested?
Backups have to be tested regularly, because only a rehearsed recovery works reliably in an emergency. Untested backups can be unusable, incomplete, out of date or encrypted along with everything else by ransomware, and that often only shows when you urgently need them and it is too late. Offline backups kept off the network and documented restart tests that evidence the procedure and the time it takes have proven their worth.