Cyber Recovery
Provenance-aware recovery that restores by knowledge significance and verifies integrity before trust is re-extended.
Recovery Is a Knowledge Problem
Conventional recovery answers a storage question: how quickly can systems and volumes be restored. The harder question after a serious incident is a knowledge question: which assets matter most, which can be trusted, and in what order should confidence be rebuilt.
Restoring data whose integrity cannot be demonstrated re-establishes availability while leaving the underlying uncertainty in place, and in a contaminated environment, that can restore the adversary's position along with the organization's.
Significance-Ordered Restoration
Our research develops recovery sequencing derived from provenance rather than from volume or schedule: assets whose loss propagates furthest through the dependency graph, and whose lineage supports the most downstream work, are prioritized.
This produces a restoration order that reflects institutional consequence instead of storage topology.
Verify Before Trust
Recovery should be gated on demonstrable integrity. Where a tamper-evident record exists, restoration can be accompanied by verification that the record has not been altered, and by localization of exactly where alteration occurred if it has.
That converts recovery from an act of hope into an act of evidence.
What It Comprises
Dependency Propagation
Bounded traversal to determine what a compromise actually exposes.
Significance Scoring
Restoration priority derived from lineage and impact.
Integrity Verification
Tamper-evidence checked before trust is re-extended.
Isolated Preservation
Assets held in states that survive the incident that prompted recovery.