Glossary · Term

Recovery explained

Recovery is the return to normal operations after an incident or outage – usually governed by the DRP and the BCP.

At a glance
Meaning
Return to normal operations
Tools
DRP, BCP, tested backups
Metrics
RTO and RPO
Goal
Minimise damage and downtime
Updated
June 2026
Editorial team
Compliance Compass

What is recovery?

Recovery is the concrete activity by which systems, data and processes are brought back to normal operation after an incident – by restoring backups, rebuilding servers or switching to standby systems, for example. Whereas the DRP is the plan and Business continuity describes the overarching goal, recovery is the actual process: what really happens in an emergency. It forms the close of incident handling and decides how quickly an organisation is fully able to work again.

Backups alone are not enough

What matters is not that backups exist, but that in an emergency they can actually be restored. Only regularly tested recoveries give confidence – otherwise you face the nasty surprise that a backup is incomplete, out of date or encrypted along with everything else by ransomware. Backups kept off the network (offline) and documented restart tests have proven their worth.

In practice: a city administration becomes the target of a ransomware attack that encrypts its specialist systems. Because the IT team runs real recovery tests every quarter, it is known that the offline backups are clean and how long restoring them takes. Instead of panicked improvisation the recovery follows a fixed script, and citizen services are reachable again after a few days.

Recovery and contingency planning

Recovery is closely linked to the DRP (the technical plan) and the BCP (the business side) and is aligned to the metrics RTO (maximum recovery time) and RPO (maximum tolerable data loss). These target values set how fast and how completely recovery has to succeed.

Recovery and NIS2

NIS2 explicitly requires backup management and recovery among the risk management measures of Article 21. Recovery is the last step of Incident response and the precondition for real business continuity – without it contingency plans stay ineffective.

Further reading: ISO 22301 – business continuity and recovery (standard overview)

Frequently asked questions

What does recovery mean?

Recovery is the concrete return to normal operations after an incident or outage, for example by restoring backups, rebuilding servers or switching to standby systems. It is the actual activity in an emergency and forms the last step of incident response. Recovery is usually governed by the DRP for the technology and the BCP for the business side. NIS2 requires it explicitly among the risk management measures of Article 21.

Which tools help with recovery?

Recovery relies above all on regularly tested backups, the disaster recovery plan (DRP) for technical IT recovery and the business continuity plan (BCP) for keeping the business running. These tools are steered through the business continuity management system (BCMS) and aligned to the metrics RTO (maximum recovery time) and RPO (maximum tolerable data loss), which set how fast and how completely recovery has to succeed.

Why do backups have to be tested?

Backups have to be tested regularly, because only a rehearsed recovery works reliably in an emergency. Untested backups can be unusable, incomplete, out of date or encrypted along with everything else by ransomware, and that often only shows when you urgently need them and it is too late. Offline backups kept off the network and documented restart tests that evidence the procedure and the time it takes have proven their worth.

Resilience

Backups that actually work

Compliance Compass helps you plan, test and evidence recovery – for an RTO and an RPO that hold.