-
-
Disaster Recovery Authority: The Missing Layer in Most Recovery Plans
Most disaster recovery programs are built around three questions: what systems need to recover, in what order, and within what timeframe. Those are legitimate questions. They produce dependency maps, runbooks, RTO targets, and recovery priority tiers. What they don’t produce is an answer to the question that precedes all of them: who still has the…
-
-
MCP, Tool Use, and the New Attack Surface Nobody Is Mapping
The agent wasn’t compromised. The model wasn’t compromised. The tool wasn’t compromised. Every component did exactly what it was designed to do. The system still executed an action nobody authorized. That is not a vulnerability in the traditional sense. There was no implementation flaw to patch, no misconfigured permission to revoke, no anomalous credential activity…
-
-
Your DR Test Passed. The Assumptions Didn’t.
DR plan failure rarely happens where you tested. It happens at the assumptions the exercise never reached — the dependencies that weren’t in scope, the runbook written for last year’s architecture, the authority chain nobody tested at 2am.
-
-
-
-
Your Backup System Is Part of the Blast Radius
The call came in at 02:00. Production encrypted. By 02:10, recovery had been declared. By 02:15, the backup console was unreachable. By 02:20, the identity provider was down — same AD domain as production. By 02:30, the repository had been located. By 02:35, nobody could authenticate to it. By 02:40, the team understood what had…
