What is the Minimum Viable Company (MVC) Approach?
The Minimum Viable Company concept encourages organizations facing a major cyberattack to resist the urge to restore every system immediately. Instead, the MVC approach involves identifying and focusing on the core people, processes, technology, documentation, and third-party dependencies that are absolutely essential for survival and minimal business operations. This strategy defines the smallest functional version of the company that can operate and deliver value, even under duress.
Why Restoring Everything Slows Cyber Recovery
Attempting to bring back every service and system all at once after an incident can delay overall recovery, increase the chance of reintroducing security risks, and cause confusion across teams. Compromised networks may still harbor threats, and incomplete recovery efforts risk undermining trust with customers and partners.
- Risk propagation: Rushing may activate unresolved threats hiding on less vital systems.
- Resource constraints: IT and incident response teams get spread thin, slowing progress on the truly critical workloads.
- Reputational impact: If unstable or partially recovered systems are exposed, business credibility can suffer further.
How to Identify Your MVC
Successfully implementing the MVC concept depends on clear, collaborative planning and testing. Key steps include:
- Map critical services to business value: Identify what must work in the first 24, 72 hours, and first week after an attack.
- Establish a trusted recovery foundation (Tier 0): Protect core identity, security, network, and access infrastructure, keeping it separate from compromised zones.
- Isolate recovery assets: Backups, clean system snapshots, and recovery tools should be kept separately to avoid infection during restoration.
- Build clean-room recovery: Prepare an isolated, secure environment or kit (“digital jump bag”) to rebuild essential systems safely.
- Practice and validate: Run crisis simulations to ensure the plan works under real-world pressure and can answer time-to-recovery questions for leadership.
Who Benefits From the MVC Approach—and Who May Not
The MVC strategy is especially suited for medium and large organizations with many interdependent systems and compliance requirements. It prepares businesses for the reality that full restoration may take days or weeks, focusing first on essential value delivery and stakeholder trust.
- Who should consider MVC: Enterprises with complex IT and operational dependencies, regulated industries, or critical infrastructure providers.
- Who may require different priorities: Small businesses with only a handful of systems could find whole-environment recovery feasible and faster. In low-risk scenarios, a more traditional restore-all strategy might suffice.
The Takeaway: Prioritizing What Matters Accelerates Cyber Resilience
Trying to restore everything at once after a cyberattack usually leads to longer outages and higher risk. The MVC approach shifts the mindset from blanket recovery to prioritized, trusted restoration, increasing the odds of a safe and timely return to business operations. Teams that define and practice MVC-centered recovery are better equipped to meet both technical and stakeholders’ expectations when the worst happens.
