Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Minimal Viable Company: Cyber Recovery Strategy

Commvault
06/12/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Hello, and welcome to episode 15 of Strive, where we talk about security, technology, resilience and everything IT, all in a virtual environment. I'm Darren Thompson, your host, and today we're going to be diving into a critical concept for business survival in the wake of cyber attack, and that is the concept of Minimal Viable Company or MVC. But before we start today, my usual disclaimer, the information shared in this podcast is for general informational purposes only. It does not constitute legal advice or professional advice and it may be subject to change. Now let's get into Minimal Viable Company. What This comes from the agile software development world and it's where we create a streamlined version of a product that meets only the core needs of users. So what about Minimal Viable Company and what is this and why is it important in the context of a cyber resilience strategy? As we've discussed in previous episodes of Strive, today's world means that it's not a absolute minimum in terms of your business, the functions that are needed to survive and ultimately recover from a cyber attack. Think of it like this. After a ransomware attack, for example, your entire IT infrastructure could have gone away. You might lose access to critical applications, communication technology, customer data, supply chains, etc. Operations, of course, can't come to a standstill for too long, so you need to define a Minimal Viable Company which lays out what is absolutely required to keep the lights on for your business whilst full recovery can take place. Okay, but why does this matter in terms of resilience? Well, we found that traditional disaster recovery strategies often focus on full recovery. They assume that DR will be enabled and everything will be restored and that's largely because traditional DR strategies were really predicated around the idea of a physical failure and they assume that all data is clean. But let's issue a bit of a reality check here. Firstly, full recovery could take weeks or even months after a sophisticated cyber attack. Secondly, not all systems are equally important. Some can wait for recovery and others can't. And thirdly, every hour of downtime means lost revenue, reputational damage and potential regulatory fines. A well-defined Minimal Viable Company allows you to do a few things. Prioritize critical business functions, recover quickly from the disruption and maintain trust wherever possible with customers, employees and regulators. Okay, but what do we need to define to define essential? Let's break down essential at a high level. When defining MVC, you need to focus on three core areas. Number one, essential business functions. What absolutely must be running first? Think finance, customer service, supply chains and compliance related operations. If you're in healthcare, that could mean patient data systems. If you're in retail, it probably means point of sale and logistics. Number two, a minimal but functional IT environment needs to be defined. Not every application or system needs to be restored immediately. Identify the top base backups, isolated recovery zones, clean recovery environments, clean rooms. They all play a massive role here. And don't forget application dependencies, including software supply chains. And number three, people in process. Who are the key employees needed to run the business at a bare minimum? Do they have the accesses required to do that job? Do they have the necessary tools? What manual workarounds are possible if IT systems remain down for an extended period? And very importantly, how will these people communicate with one another? So how should we go about defining our minimal viable company? Well, I think a good way of thinking about this is to ask yourself the following questions. If your company were hit by ransomware today, could somebody tell you what is the absolute minimum IT infrastructure we need to operate? What data sets and applications must be restored first? Who are the critical employees and what access do they need? And lastly, what workarounds could be put in place whilst a full recovery happens? Importantly, refining your MVC isn't just a one-time exercise, of course. It requires a few things, including business impact analysis to identify mission critical assets, tabletop exercises to test how teams respond to cyber incidents, playbooks that document all of your recovery steps, communication plans, role assignments, and really importantly, exhaustive testing. How do you know that you can get your MVC back if you've only ever tried it on paper? This area is really rife right now with disruptive technologies such as air gapping, immutable data copies, and clean rooms. So to wrap up this session, cyber recovery isn't necessarily about getting back to 100% instantly. It's about keeping the business running with the essentials whilst you rebuild the rest. However, defining what is necessary is not trivial and this is where the concept of MVC comes into play. Your MVC could be the difference between survival and failure in the wake of a catastrophic cyber attack. I challenge you to take this conversation to your IT and security teams and ask the following questions. Do we have an MVC? How quickly could we pivot to minimal viable operations if we needed to? And what's missing in our current cyber recovery plans? Thank you for joining me on this episode of Strive. That's all we have time for today. Stay tuned for more stories and insights and until next time, stay informed, stay secure, and I will see you in the next one. you

TL;DR

  • Minimal Viable Company (MVC) defines the absolute minimum business functions, IT systems, and personnel needed to survive and recover from cyber attacks when full restoration may take weeks or months.
  • Traditional disaster recovery strategies fail in cyber scenarios because they assume clean data and full recovery, while sophisticated attacks require prioritized restoration of only mission-critical operations.
  • Defining MVC requires identifying essential business functions, minimal IT infrastructure with clean recovery environments, key personnel with proper access, and manual workarounds for extended downtime scenarios.

Summary

This episode introduces the concept of Minimal Viable Company (MVC), a critical framework for business survival during cyber attacks. Borrowed from agile software development's Minimal Viable Product concept, MVC defines the absolute minimum business functions, IT infrastructure, and personnel required to keep operations running while recovering from catastrophic incidents like ransomware. Host Darren Thomson explains why traditional disaster recovery strategies fall short in cyber scenarios, as they assume clean data and focus on full restoration rather than prioritized recovery. The framework addresses three core areas: essential business functions (finance, customer service, supply chains), minimal IT environment (critical applications, clean recovery zones, isolated backups), and key personnel with necessary access and communication channels. Thomson emphasizes that defining MVC requires business impact analysis, tabletop exercises, documented playbooks, and rigorous testing beyond theoretical scenarios. The episode concludes with a challenge to organizations: assess whether you have a defined MVC, how quickly you could pivot to minimal operations, and what gaps exist in current cyber recovery plans.

Chapters

0:00 - Introduction to MVC Concept
0:56 - Defining Minimal Viable Company
2:07 - Why MVC Matters for Resilience
3:07 - Three Core Areas of MVC
4:34 - Defining Your MVC Framework
6:06 - Challenge and Closing

Key Quotes

1:26 "After a ransomware attack, for example, your entire IT infrastructure could have gone away. You might lose access to critical applications, communication technology, customer data, supply chains, etc."
2:30 "Firstly, full recovery could take weeks or even months after a sophisticated cyber attack. Secondly, not all systems are equally important. Some can wait for recovery and others can't."
5:42 "Cyber recovery isn't necessarily about getting back to 100% instantly. It's about keeping the business running with the essentials whilst you rebuild the rest."

FAQ

How does Minimal Viable Company differ from traditional disaster recovery?

Traditional DR focuses on full system restoration and assumes clean data, typically designed for physical failures. MVC prioritizes only the absolute minimum business functions needed to survive during cyber attacks, recognizing that full recovery may take weeks or months and that not all systems are equally critical.

What are the three core areas to focus on when defining MVC?

The three core areas are: (1) essential business functions like finance, customer service, and compliance operations; (2) minimal but functional IT environment including critical applications, clean recovery zones, and isolated backups; and (3) key personnel with necessary access, tools, communication channels, and manual workarounds for extended downtime.


Categories:
  • » Webinar Library » Commvault
  • » Data Protection » Backup & Recovery
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Data Protection
  • Business Continuity
  • Best Practices
  • Technical Deep Dive
  • Minimal Viable Company
  • Cyber Recovery
  • Ransomware Response
  • Disaster Recovery
  • Business Impact Analysis
  • Incident Response
  • Clean Room Recovery
  • Cyber Resilience
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Minimal Viable Company: Cyber Recovery Strategy

              Upcoming Webinar Calendar

              • 06/17/2026
                12:00 PM
                06/17/2026
                Action1: The Remediation Gap: Vulnerability Management in the Age of AI
                https://www.truthinit.com/index.php/channel/2010/action1-the-remediation-gap-vulnerability-management-in-the-age-of-ai/
              • 06/23/2026
                01:00 PM
                06/23/2026
                The AI-Powered VMware Alternative
                https://www.truthinit.com/index.php/channel/2009/the-ai-powered-vmware-alternative/
              • 06/24/2026
                11:00 AM
                06/24/2026
                LATAM: Accelerating Insights on AI Through an Engaging Webinar Series
                https://www.truthinit.com/index.php/channel/2012/accelerating-insights-on-ai-through-an-engaging-webinar-series/
              • 06/25/2026
                01:00 PM
                06/25/2026
                Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier
                https://www.truthinit.com/index.php/channel/1998/generative-ai-security-preventing-ai-from-becoming-a-data-breach-multiplier/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Schutz von KI in Anwendungen, Agenten und APIs.
                https://www.truthinit.com/index.php/channel/2008/schutz-von-ki-in-anwendungen-agenten-und-apis/
              • 07/02/2026
                10:00 AM
                07/02/2026
                Resilience Insights from Hybrid Threats When the Cloud Faces Challenges
                https://www.truthinit.com/index.php/channel/2011/resilience-insights-from-hybrid-threats-when-the-cloud-faces-challenges/

              Upcoming Events

              • Jun
                17

                Action1: The Remediation Gap: Vulnerability Management in the Age of AI

                06/17/202612:00 PM ET
                • Jun
                  23

                  The AI-Powered VMware Alternative

                  06/23/202601:00 PM ET
                  • Jun
                    24

                    LATAM: Accelerating Insights on AI Through an Engaging Webinar Series

                    06/24/202611:00 AM ET
                    • Jun
                      25

                      Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier

                      06/25/202601:00 PM ET
                      • Jul
                        01

                        Schutz von KI in Anwendungen, Agenten und APIs.

                        07/01/202604:00 AM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version