Cyber Resilience Review
Validates whether your organisation can actually recover, covering backup integrity, RTO/RPO realism, incident response plan quality, and a facilitated tabletop exercise.
Overview
A backup strategy is not the same as a recovery capability. An incident response plan is not the same as incident response readiness. Most organisations have the documentation; few have tested whether it actually works.
Opcode’s Cyber Resilience Review closes that gap. Over two to three weeks, we validate your recovery capability end-to-end: whether your backups are complete and restorable, whether your RTO and RPO targets are achievable, whether your IR plan is clear enough to execute under pressure, and whether your team can make the right decisions during a simulated incident.
The deliverable is a resilience gap report and tabletop exercise findings: evidence that your board can see, and a prioritised remediation list your team can action.
What’s included
- Backup and recovery validation: Review of backup coverage, frequency, retention, and integrity. Where possible, recovery tests are performed to validate that backups are restorable and complete. Identifies systems with no backup, backups that haven’t been tested, and recovery procedures that are out of date.
- RTO/RPO gap analysis: Comparison of documented recovery time and point objectives against what is actually achievable given current backup and infrastructure configuration. Many organisations discover their documented RTO assumes manual recovery steps that would take far longer than the target.
- Incident response plan review: Assessment of IR plan completeness, clarity, and executability. Reviews decision authority, escalation paths, external communication processes, and whether the plan accounts for common scenarios (ransomware, data breach, cloud outage).
- Tabletop exercise: A half-day facilitated exercise using a realistic scenario tailored to your industry and environment. Tests your team’s ability to make decisions, communicate, and execute under pressure. Findings feed directly into the gap report.
- Resilience gap report: Prioritised findings from all review activities, with risk ratings, evidence, and remediation recommendations. Suitable for board-level reporting.
How it works
- Scoping: Define which systems, environments, and scenarios are in scope. Review existing documentation (backup policies, IR plan, BCP/DR documentation).
- Documentation review: Assessment of backup configuration, RTO/RPO documentation, and IR plan against current environment reality.
- Recovery validation: Technical review of backup coverage and, where agreed, live restoration testing of selected systems.
- Tabletop exercise: Half-day session, delivered remotely or on-site. Realistic scenario, your team, your tools, facilitated by Opcode. Debrief immediately following.
- Gap report delivery: Findings consolidated into a prioritised report within five working days of the tabletop. Debrief call to walk through findings.
Distinction from CI Fortify
Opcode’s CI Fortify service (within Compliance & Audit) addresses the ASD’s specific guidance for critical infrastructure operators, providing a structured program for organisations with obligations under the Security of Critical Infrastructure Act. The Cyber Resilience Review is for any organisation that wants to know whether they can recover from a ransomware event, major cloud outage, or significant security incident. It does not require CI operator status or regulatory obligation.
Who this is for
- Organisations that haven’t tested their incident response plan in the last 12 months
- Companies that have experienced a security incident or near-miss and want to understand what they would do differently
- Boards and executive teams seeking assurance that recovery capability is real, not just documented
- Organisations with ISO 27001, CPS 234, or SOC 2 compliance requirements that include business continuity and IR controls
- Scale-ups that have grown quickly and whose recovery documentation hasn’t kept pace with their infrastructure
Ready to strengthen your security posture?
Let's talk about what Opcode can do for your organisation. Get in touch for a no-obligation discussion about your security challenges.