Recovering the Business, Not Just the Systems: PwC on Cyber Resilience
Recently Tech TV’s Pete Warren met up with PwC’s Karen Penman and Rachel Higham, at the Cohesity Catalyst London event to hear why cyber recovery has become a whole-business challenge — and why rehearsing for it now matters more than ever. Penman, who leads PwC’s digital and cyber resilience business in the UK and across EMEA, helps iconic UK brands prepare for the eventuality of a ransomware attack. Higham advises PwC on business resilience, working across its teams to deliver client outcomes.
Cyber recovery, Penman explained, differs enormously from the traditional disaster recovery most of us grew up with. In a ransomware scenario you face a vast number of unknowns and immense complexity: you are not restoring a few failed systems but recovering the entire business, at pace, under tremendous pressure, and making tough calls without the information you would normally want. It is fundamentally a business-led challenge, no longer something confined to the technologists. She offered a sobering real-life example — a client who worked around the clock for two full days to recover, only to find the attackers still lurking in their environment, ready to strike again. The human toll is severe, she noted, because recovery scenarios that once lasted days are now stretching into weeks and months, and none of us are wired to sustain that pressure. Hence the importance of rehearsing.
Higham broke down the capabilities needed before, during and after an incident. Beforehand, the priority is defining your “minimum viable company” — the roughly 10 to 15 percent of business outcomes you must recover fast to prevent harm to customers and colleagues, meet regulatory obligations, avoid catastrophic loss and retain market trust. Defining this “survival life raft” in peacetime removes cognitive overload in the moment. During an incident, clear command and control is critical: defined accountabilities, delegated authorities, and the right escalation and communication flows so every stakeholder understands the state of play. Afterwards, organisations must embed the lessons learned and take time to harden their environment against newly exposed vulnerabilities, recognising their risk appetite has likely dropped. How quickly is “quickly”? That, Higham said, is a business decision defined by outage tolerance — typically days, not weeks or months.
Both stressed that rehearsing traditional BCP and DR plans is no longer enough, because those plans assume technology remains in place and cope only with single-point events, not the complexity of a destructive cyber incident. Repeated rehearsal builds the muscle memory — and the emotional memory — of making critical decisions with imperfect, shifting information. Higham was strikingly candid about personal resilience too, describing a routine of sleep, healthy eating, daily yoga, weekly coaching and non-crisis conversations to avoid burnout during prolonged incidents.
On why PwC partnered with Cohesity, Penman pointed to phenomenal technology and a shared recognition that no single party can solve this alone — protecting critical national infrastructure demands an ecosystem of effective partners pulling in the same direction. The stakes, she warned, are rising: ransomware increasingly threatens not just revenue or solvency but lives, as attacks on hospitals have already shown — sometimes carried out by attackers young enough not to grasp the consequences.
-
Host: Pete WarrenTech TV Presenter
-
Guest: Karen PenmanPwC
-
Guest: Rachel HighamPwC