Documented recovery plans for crown-jewel services with RTO/RPO targets agreed with the business; restoration ordering based on dependencies (from IDENTIFY).
RC-2
Trusted restoration
Verify integrity of backups and systems before reconnecting (assume ransomware persistence); rebuild-from-known-good procedures; credential rotation as standard recovery step.
RC-3
Recovery execution & verification
Ability to execute restores at scale; post-restore validation that services function and are clean.
RC-4
Recovery communication
Status communication to internal stakeholders, customers, authorities (final NIS2/DORA reports), and the public where relevant (CSF 2.0 RC.CO).
RC-5
Lessons learned & improvement loop
Blameless post-incident reviews with tracked actions; findings feed the improvement backlog (CSF 2.0 ID.IM) and update playbooks, detections and controls.
RC-6
Business continuity integration
CDC recovery plans aligned with enterprise BCM/DR; joint exercises.
Restoration improvised; backups untested; no post-incident reviews.
2 — Managed
Recovery plans and RTO/RPO for critical services; annual restore test; post-incident reviews held for major incidents.
3 — Established
Rebuild-from-known-good procedures; integrity verification gates before reconnection; lessons-learned actions tracked to closure; joint BCM/CDC exercise annually.
4 — Optimising
Recovery time capabilities measured against RTO in realistic exercises (incl. ransomware-scale scenarios); improvement loop metrics show incidents driving control changes; supplier recovery dependencies tested.