Resilience All-in-One series · Recovery

Cyber Recovery All-in-One by Kai London

Disaster recovery assumes the infrastructure failed. Cyber recovery assumes someone made it fail, is still present, and has had access to your backups. This book covers the harder discipline — rebuilding identity first, restoring data you can trust, and proving the environment is clean before the business returns to it.

Available on Amazon.

What is inside

Identity first

Rebuilding or cleaning the directory before anything else, because every other restoration depends on it.

Backup integrity

Immutability, isolation, retention and the uncomfortable question of whether your backups were encrypted too.

Clean-room recovery

Standing up an isolated environment, validating restored systems, and staging the return to production.

Cloud and SaaS restoration

Tenant recovery, configuration drift and the data your provider does not restore for you.

Logging through the incident

Preserving telemetry when the logging platform is itself in scope, and reconstructing the timeline afterwards.

Zero Trust continuity

Rebuilding to a better architecture rather than restoring the one that was breached.

Who it is for: infrastructure, identity and backup teams, incident responders and recovery leads, CISOs and continuity leaders, and executives who will be asked when the business will be back.

NIST SP 800-61NIST CSF 2.0ISO 22301Zero TrustDORA

Restore identity first. Everything else you rebuild on top of a compromised directory is rented from the attacker.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.