Phased Roadmap: 30 / 60 / 90 / 180 Days
Each phase builds on the prior one. Dates assume program kickoff at day 0 with an assigned executive sponsor already in place.
| Phase 1 — Days 0-30 Foundation, Governance, and Risk Baseline |
Goal: understand current exposure and get organizational alignment before any technology is purchased.
- Secure executive sponsorship, publish program charter, and stand up the cross-functional steering committee (security, infrastructure, apps, legal, risk).
- Complete data classification and criticality tiering (Tier 0-3) across on-prem, AWS, Azure, and SaaS workloads.
- Define draft RTO/RPO targets per tier with business unit sign-off.
- Audit current backup environment: Rubrik/Cohesity configuration, AWS Backup and Azure Backup settings, existing immutability features, and SaaS backup coverage (or lack thereof).
- Map the attack surface of backup infrastructure: credentials, service accounts, network paths, and admin console exposure.
- Run a gap analysis against NIST CSF 2.0 / NIST SP 800-209 to document a defensible baseline.
- Run an initial ransomware tabletop exercise with IT, security, and leadership to surface assumptions and authority gaps.
- Decide VaaS vs. private managed vault direction based on data sovereignty, cost, and operational capacity (final selection in Phase 2).
Phase 1 exit criteria: charter signed, tiering complete, baseline gap report delivered, tabletop findings documented, vault approach selected.
| Phase 2 — Days 31-60 Vault Build and Identity Recovery Foundations |
Goal: stand up the isolated, immutable vault and start closing the identity recovery gap in parallel.
- Deploy the selected vault (VaaS such as Rubrik Cyber Recovery Vault or Cohesity FortKnox, or a private managed vault) with network isolation from production AD and management planes.
- Enable WORM immutability enforcement: S3 Object Lock, Azure Immutable Blob Storage, or vendor-native immutability with retention locks administrators cannot shorten.
- Architect one-way replication into the vault; confirm no standing inbound path exists from the vault to production.
- Harden native cloud backup: apply AWS Backup Vault Lock and Azure Backup immutable vault settings on top of existing jobs.
- Establish cross-account/cross-tenant isolation for cloud backup copies with break-glass-only access.
- Extend protection to SaaS platforms (M365, Salesforce, etc.) using dedicated third-party SaaS backup tooling.
- Begin Active Directory forest recovery planning: system state backups, offline-secured admin credentials, documented rebuild sequence.
- Begin Entra ID / cloud identity recovery planning: back up Conditional Access policies, MFA settings, admin roles, and app registrations.
- Stand up break-glass accounts and Privileged Access Workstations (PAWs) for recovery personnel.
- Implement role-based access, MFA, and just-in-time privileged access for all backup and vault admin accounts.
Phase 2 exit criteria: vault operational with immutability enforced, cloud/SaaS hardening complete, AD and Entra ID recovery plans drafted, PAWs and break-glass accounts live.
| Phase 3 — Days 61-90 Clean Room, Recovery Sequencing, and First Full Test |
Goal: prove the architecture works end-to-end, not just that data landed in the vault.
- Build the permanent cyber recovery clean room: an isolated network segment for restoring, scanning, and validating systems before reconnecting to production.
- Stand up a golden image repository of validated server, VM, workstation, and container images in immutable storage.
- Complete application dependency mapping across database, identity, and network layers for Tier 0/1 systems.
- Define Minimum Business Viable Operations (MBVO) and build the initial business service recovery catalog.
- Publish a recovery sequencing framework aligning infrastructure, identity, database, application, and end-user service restoration order.
- Write tier-specific recovery runbooks with named owners and validation checkpoints, including credential and identity recovery steps.
- Deploy anomaly/ransomware detection scanning on backup snapshots and malware scanning of vault-hosted recovery points.
- Run the first full-scale recovery test simulating total compromise: production, AD, and primary backup infrastructure assumed lost, recovering entirely from the vault.
- Forward backup platform logs (retention changes, deletion attempts, vault access, failed MFA, privilege escalation) to the SIEM.
Phase 3 exit criteria: clean room operational, first full simulated recovery completed and documented, recovery runbooks published for Tier 0/1, SIEM integration live.
| Days 91-180 Maturity, Coverage Expansion, and Continuous Validation |
Goal: extend coverage beyond Tier 0/1, formalize testing cadence, and convert the program into a measured, sustained capability.
- Extend vault coverage, dependency mapping, and recovery runbooks to Tier 2/3 systems.
- Establish a recurring recovery testing cadence (quarterly minimum for Tier 0/1) with automated test recovery tooling.
- Launch a formal recovery certification process; track systems that fail exercises the same way security vulnerabilities are tracked.
- Protect infrastructure-as-code and CI/CD assets: source repositories, container registries, Terraform/CloudFormation/ARM/Bicep templates, Ansible playbooks.
- Stand up threat hunting specifically focused on backup infrastructure, on a recurring schedule.
- Implement insider threat controls: separation of duties, approval workflows, immutable retention, extensive audit logging.
- Confirm vendor recovery support agreements (Rubrik, Cohesity, AWS, Azure, security and application vendors) include emergency/24×7 coverage, not business-hours only.
- Build an out-of-band recovery communications plan independent of production email, Teams, Slack, and VPN.
- Assess critical third-party, MSP/MSSP, and software supply chain dependencies for recovery impact.
- Deploy the recovery scoring dashboard: readiness score, percent of workloads tested, vault coverage, immutable coverage, RTO/RPO compliance.
- Roll out the cyber recovery maturity assessment and Key Risk Indicators (KRIs); brief executives in business-risk language (data loss exposure, recovery time, functions at risk).
- Establish the annual program review cycle for continuous improvement as threats and tooling evolve.
180-day exit criteria: full-tier vault and runbook coverage, quarterly test cadence running, maturity model and KRIs reporting to executives, vendor and communications continuity confirmed.
Beyond Day 180: the program shifts from build to sustain — quarterly testing, annual maturity review, and continuous expansion of coverage as the environment changes.