Protect and secure your data from cyber attacks
Data Protection
Data Security
Data Insights
The 5 Steps to Cyber Resilience
Cloud & SaaS
Enterprise
Industries
A minimum viable company (MVC) defines the people, processes, systems, and data your enterprise must restore first to keep operating after a major outage or cyber incident. This framework gives recovery teams a preapproved sequence of decisions made in advance, rather than under the extreme pressure of a live ransomware attack or infrastructure outage.
An MVC plan turns cyber recovery into a business continuity exercise with clear priorities by identifying what systems must come back online first, who makes the decisions, and how teams prove recovered data and infrastructure are safe to use.
A minimum viable company is the smallest workable version of your organization that can keep delivering essential services after a disruption. In the context of cyber resilience, MVC includes the core applications, datasets, infrastructure, business processes, and people needed to restart operations. Your MVC plan should answer one primary operational question: if most of your environment is rendered unsafe or unavailable, what do you need to restore to continue serving customers, meeting legal obligations, and protecting the business?
While the term sounds similar to "minimum viable product,” a startup concept focused on testing a new product with early users, minimum viability here means preserving the organization's ability to function during a crisis.
Defining your MVC before an incident gives your recovery teams a shared, business-approved order of operations when time and capacity are limited. Without this framework, IT and security teams can lose hours debating which application matters most. Business leaders may push competing priorities because of siloed ad hoc decisions.
An MVC framework helps enterprises:
The result is a recovery strategy built around business viability, rather than a generic goal of restoring every system as quickly as possible.
A practical MVC framework starts with business outcomes, then traces backward through the applications, data, infrastructure, and people needed to produce them.
Start with the business services that must continue to function during a disruption. Ask what the company must be able to do in the first 24 hours, the first week, and the first month post-incident. The answers to these questions will dictate which services you start with.
For a manufacturer, it may be accepting orders, communicating with suppliers, scheduling production, and processing payroll. For a financial services company, it may mean customer portal access, payment processing, regulatory reporting, and identity verification.
Document each process in plain language. Then identify the application, data source, team, and dependencies each process depends on. This keeps the exercise grounded in how the organization’s work actually gets done.
Application tiering translates business priorities into a recovery sequence. A useful model often has three or four tiers, though the labels matter less than clarity of definitions. Tier 0 commonly includes foundational services like identity, DNS, network services, and privileged access controls. Tier 1 might include the applications and datasets required to run required business processes, while lower tiers contain important but deferrable systems.
Each tier should have a documented business owner, recovery target, dependency map, and recovery method. Teams also need to know where the protected data resides and whether it can be restored into an isolated environment for validation.
Cohesity DataProtect supports enterprise data protection across on-premises, cloud, and SaaS environments, helping teams secure, back up, and recover data needed for business continuity.
A Tier 1 application rarely runs alone, so build a dependency map for each MVC service, including technical and operational dependencies. Examples here include the administrator who holds the necessary credentials, the vendor required to reestablish a connection, or the business approver who validates a recovered workflow. Dependency mapping exposes a common recovery failure: restoring an application successfully but leaving it inaccessible, untrusted, or unable to exchange data with the systems around it.
Recovery time objectives (RTOs) set the maximum acceptable downtime for a system or service. Recovery point objectives (RPOs) define how much data loss the business can tolerate. Work with business process owners to set these targets.
A payroll platform that must be available within 8 hours has a different backup frequency, recovery workflow, and testing requirements than a reporting tool that can wait several days. Make the targets as specific as possible. “Restore quickly” leaves too much room for argument during an incident. “Restore identity services within four hours and payroll processing within 12 hours using a recovery point no more than four hours old” gives teams something concrete.
An MVC framework only works when authority, ownership, and escalation paths are assigned before the pressure of an active incident. There are five primary roles to assign, each with their own responsibilities:
Role
Executive sponsor
Incident commander
IT operations lead
Security lead
Communications lead
Primary responsibility during MVC recovery
Sets business priorities, resolves high-level conflicts, and approves major tradeoffs.
Coordinates the response, sets the recovery rhythm, and maintains a single operating picture.
Restores infrastructure, applications, and access according to the approved sequence.
Directs containment, investigation, threat hunting, and validation of clean recovery points.
Manages timely, consistent updates for employees, customers, partners, and other stakeholders.
The executive sponsor owns the business case for MVC planning. During recovery, they make cross-functional decisions, such as whether to prioritize customer transactions over internal reporting or whether to operate in a limited mode while other systems remain offline. This role needs enough authority within the company hierarchy to settle disputes quickly.
The incident commander runs the recovery process. They coordinate technical and business teams, track decisions, manage escalations, and keep the group focused on the defined MVC sequence. They do not need to be the deepest technical expert in the room; their job is to keep recovery work organized, time-bound, and tied to the enterprise’s stated priorities.
The IT operations lead turns recovery objectives into technical workflows. This role coordinates infrastructure restoration, application owners, cloud teams, data teams, and service providers. They also report progress and blockers to the incident commander in business-relevant terms.
The security lead determines whether systems and data are safe to restore and reconnect to the wider network. This includes investigating an intrusion, identifying affected assets, reviewing recovery points, setting controls for the recovery environment, and assessing overall threat protection status.
The communications lead creates a reliable flow of information for employees, customers, partners, regulators, and leadership. They coordinate with legal, HR, customer support, and public relations teams to ensure everyone knows what is available, what is restricted, and where to get accurate updates.
An untested MVC plan is an assumption, and assumptions tend to fail under pressure. Testing can confirm clean recovery points, document dependencies, and verify the right people can make decisions in the confusion of an active incident.
There are several test formats relevant here:
Run tabletop exercises at least twice a year and test technical recovery on a schedule matched to the importance of each tier. Review the MVC framework outside this schedule when you complete a major infrastructure project, change critical vendors, or face new regulatory requirements.
Explore Cohesity’s AI-powered solutions to see how data security, recovery, and validation capabilities can support these recurring recovery exercises.
Cohesity helps enterprises identify, protect, validate, and recover the systems and data that make up their minimum viable company. It starts with clear priorities: which applications and datasets are crucial for resuming essential operations, what dependencies they require, and what recovery targets the business can support.
Our AI-powered data security platform supports data protection and cyber resilience across hybrid and multicloud environments with tiered protection policies, recovery workflows, and isolated validation practice functionality.
A documented, tested MVC gives your enterprise a usable survival plan when disruption hits. Explore Cohesity’s minimum viable company capabilities to see how your organization can prepare for recovery before your next incident.