Placed within a unified operational framework, the three components are vital for maintaining resilience during pessimistic scenarios. Their interconnection integrates them into a comprehensive sequence to ensure damage is minimized. The goal is rapid recovery of operations without halting organizational processes. Risks of incidents and attacks are inevitable, but these principles enable preliminary preparation and prescriptions for how to overcome them with minimal damage, which is rarely only material.
“Incident response” represents a complex set of coordinated actions used to detect, analyze, contain, and remediate potential system breaches, with preparation for future ones being an integral part of the process. Preparation itself is the first of four phases in the NIST-prescribed incident response lifecycle[1]. The subsequent phases are detection and analysis, containment, eradication, and recovery, and the cycle concludes with post-incident activities.
Each of these stages has strictly defined properties and prescribed steps for execution under specific circumstances. IBM Corporation points to three directions in which AI is used to implement the incident response plan [2]. By accelerating anomaly detection with the help of AI, which is a proactive process for response and forecasting of likely attacks, approximately 2.2 million US dollars on average could be saved per cybersecurity breach [3].
Business continuity also requires a detailed plan to ensure that essential operations remain active during a crisis. The plan contains four important components that cover not only the digital dimensions of security, but also other important domains, such as supply chains, human resources, and communications[4]. The creation of such a plan involves conducting a business impact analysis as a core element of the risk management process. Incident response systematization is the second component, where organizations establish the execution of corresponding actions for expected or unexpected threats.
Establishing roles in the plan is the third element, which aims to organize and order the efforts of the human factor and prioritize resource utilization in a given direction. The final element is the continuous process of testing and improving the plan for the sake of the most adequate response during crises. Generative AI could be used at every stage of plan development, but in practice, its implementation could lead to over-reliance on automated systems and dangerous overconfidence by the human factor.
“Disaster recovery” is the last critical principle of the triad under consideration, which focuses on data and technical infrastructure recovery[5]. “Disaster recovery” is inextricably linked to the previous two elements and is the final part of the efforts to address breaches and mitigate damage. To be consistent and complete, recovery is woven into the plans of the previous two principles, and in addition to them, a complete inventory of owned assets is prepared [6].
Without this detail, there could be no clarity in the recovery process, and for this purpose, assets are categorized as critical, important, and non-essential[7]. The sum of these principles is the foundation of cyber resilience, and while some of the mentioned principles have a preventive nature, “incident response,” “business continuity,” and “disaster recovery” bring clarity for emerging from crisis situations through a systemic response. In this context, generative AI could play a role in each of the mentioned elements to accelerate the process of building an effective anti-crisis plan.
[1] NIST, NIST Special Publication 800-61r3, April 2025, https://doi.org/10.6028/NIST.SP.800-61r3
[2] Jim Holdsworth, Matthew Kosinski, What is incident response?, IBM, https://www.ibm.com/think/topics/incident-response
[3] Ibid.
[4] Rine Diane Caballar, Cole Stryker, What is business continuity?, IBM, https://www.ibm.com/think/topics/business-continuity
[5] NIST, NIST SP 800-61 Rev. 3- Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile, April 2025, https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r3.pdf
[6]Tselkov, V., & Sredkov, G. (2023). CYBERSECURITY RESILIENCE OF STATE AND LOCAL ADMINISTRATION DURING DISASTERS, ACCIDENTS AND CATASTROPHES, Burgas Free University, http://research.bfu.bg:4000/items/75d0574e-41da-470c-b402-37d995c4619e
[7] IBM, What is a disaster recovery plan (DRP)?, https://www.ibm.com/think/topics/disaster-recovery-plan


