
For years, cyber-security has rewarded speed of detection. The faster an organisation identified a threat, the better protected it was assumed to be against malicious activity. As a result, metrics like Mean Time to Detect (MTTD) became gold-standard frameworks.
Frameworks like MITRE ATT&CK also reinforced a detection-first logic designed to identify attack patterns, surface indicators and respond to minimise operational impact. At the time, this approach suited a landscape that was moving at human pace, not machine speed.
However, recent developments have highlighted just how quickly the landscape is changing. In an unprecedented attack, OpenAI technology recently ‘went rogue’ during a cyber-security test and attacked Hugging Face, an AI tool that can carry out tasks autonomously. Hugging Face described this attack as unlike anything they had experienced; it was done at unprecedented speed, performing 17,000 actions in less than two days.
Security teams are no longer operating against attackers working at human pace, but against systems capable of discovering vulnerabilities, making decisions and executing attacks in minutes. As AI compresses the timeline of cyber-attacks, recovery is becoming the defining measure of an organisation’s resilience.
Time-to-recovery (TTR) is emerging as one of the most meaningful measurements of modern cyber-resilience. Rather than measuring how quickly an alert is raised, TTR focuses on how long it takes an organisation to restore business operations after an attack.
For executives focused on customer needs, TTR is a vital metric. Customers do not judge an organisation based on how quickly a security team spots malicious activity behind the scenes; they care about whether essential services remain available, transactions continue uninterrupted, and the organisation can recover without prolonged disruption.
Despite this, many organisations have only a theoretical understanding of their recovery capability. Plans exist, documentation has been written, and recovery processes have been designed, but relatively few businesses have validated how long recovery would actually take during a real cyber-incident involving multiple interconnected systems.
Until that test happens, TTR is often an assumption rather than a measurement.
Research shows that 43% of organisations would take between 25 and 48 hours to recover their identity infrastructure following a compromise. Considering identity now sits at the centre of almost every enterprise application and service, even short periods of disruption can quickly escalate into financial loss and regulatory exposure. With AI-driven threats on the rise, organisations have less time to prevent incidents before they occur. When the window between vulnerability discovery and exploitation collapses from weeks to minutes, as emerging research suggests, downtime becomes a question of ‘when’, not ‘if’.
Extended outages can halt production, interrupt customer services and delay critical operations, while placing intense scrutiny on leadership teams. Rubrik Zero Labs research found that more than one-third of significant cyber-incidents are followed by changes within the C-suite. The frequency of these leadership changes demonstrates that recovery has become a boardroom accountability issue, rather than just a concern for the IT department. Often, it is not the breach itself that shapes the long-term consequences, but how effectively the organisation responds and recovers.
Prevention remains essential, and controls such as firewalls, endpoint protection and vulnerability management are foundational. However, prevention can no longer be viewed as the sole measure of resilience. Organisations also need confidence that they can restore operations rapidly when preventative controls fail. That means investing in immutable backups, isolated recovery environments and automated recovery processes that minimise manual intervention during high-pressure incidents.
Organisations must invest in capabilities that allow systems to be restored quickly and safely. Key measures include immutable backups that cannot be altered, isolated recovery environments that prevent reinfection, and orchestrated workflows that reduce manual intervention under pressure. Critically, businesses must have regular testing that produces a realistic, evidence-based TTR. The organisations gaining an advantage are those that have elevated TTR from a technical metric to a board-level KPI.
Leadership does not need to understand the mechanics of immutable storage, but it does need to understand how long the business can tolerate disruption, which services need to be restored first, and whether those assumptions have been validated under realistic conditions.
In the AI era, minimising disruption, restoring trusted operations quickly and demonstrating confidence in the integrity of recovered systems is what will distinguish the most proactive organisations.
Time-to-Recovery is a practical measure of organisational resilience and increasingly an important indicator of how prepared a business truly is for the threats of a modern cyber-attack. As AI continues to change the timeline of cyber-attacks, organisations must stop asking just how quickly they can detect an incident and start asking how quickly they can recover from one.
Richard Cassidy is EMEA CISO at Rubrik
Main image courtesy of iStockPhoto.com and Supatman
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543