Cyberattacks making the ability to quickly move critical data a crucial issue for companies in Europe. Swedish organizations risk being unprepared for a serious IT crisis if their systems are knocked out by a cyberattack, a system collapse or a geopolitical conflict.
Today, simply having a backup is no longer enough. Organizations must be able to act immediately when an incident is detected. According to experts, companies should be able to initiate an evacuation of critical data within ten minutes. Otherwise, businesses risk long downtimes, financial losses, and serious damage to the trust of customers and partners.
Cloud dependence creates new risks
In recent years, many companies have moved large parts of their IT systems to public cloud platforms. This development has provided flexibility, scalability and faster innovation. At the same time, it has created new dependencies.
When organizations build their entire infrastructure on a single cloud provider, it can be difficult to quickly move data or recover systems if something goes wrong. In complex environments built on container platforms and automated DevOps processes, restoring entire environments can take significantly longer than planned.
This means that many companies in practice lack a clear plan for how they will act if their primary platform suddenly becomes unavailable.
The dangerous illusion that everything can be rebuilt
In modern systems development, there is often a perception that systems can be quickly rebuilt from code and automated pipelines.
However, experts warn that this can be a dangerous illusion.
Historically, many organizations have underestimated the risks in their IT environments. In the past, some companies believed that disaster plans were unnecessary because servers could be easily reinstalled. Today, the same argument is being made in the cloud world, where everything can be recreated automatically.
The problem is that reality is often more complex than theory. Once an attack occurs, system dependencies, lack of documentation, and cloud lock-in can make recovery much more difficult than planned.
EU regulations drive resilience demands
New European regulations that DORA and NIS2 also places higher demands on organizations' ability to handle IT incidents and protect critical information.
The regulations are not just about cybersecurity, but also about operational resilience. Organizations must be able to continue operating even when something goes wrong.
In practice, this means that organizations need to
• clear incident plans
• working backup strategies
• offline copies of critical data
• regular testing of recovery processes
Companies that lack these processes risk both regulatory consequences and significant financial losses in the event of a major incident.
Ten minutes to plan B
A key recommendation from security experts is that organizations must have a plan B for their data.
This means that companies should be able to quickly
1 identify which systems are business-critical
2 begin data migration or isolation
3 Restoring services in an alternative environment
The goal is for this process to be able to start within ten minutes of an incident being detected.
Another crucial component is having an offline backup that cannot be accessed by attackers. Despite this, many organizations still lack such solutions.
Future risks AI and hidden dependencies
The rapid development of AI-based systems also creates new types of risks.
Automated AI agents can create dependencies in IT environments that the organization does not fully control. If such a function stops working, it can be difficult to recreate the system because you do not know exactly how it was built in the first place.
This makes the requirements for documentation, redundancy, and tested recovery strategies even more important.
From cyber protection to cyber resilience
The modern security strategy is therefore not only about preventing attacks but also about being able to handle them when they occur.
Organizations need to move from a focus on protection to a focus on resilience. This means being able to quickly detect breaches, limit damage, and restore operations without further disruption.
For Swedish companies, the ability to move or restore critical data within minutes could be crucial when the next major cyber crisis occurs.








