Organisations need critical data context to move beyond blind restores toward more intelligent, business-aware recovery strategies.
It’s 2:00 AM. Identity systems are down, the network is compromised, and endpoints are dark. Only one question matters to the board: Can we open the doors tomorrow?
For years, cybersecurity strategies have centered on keeping attackers out. But as breaches become harder to prevent, the real measure of resilience is shifting toward how fast organisations can restore operations and limit business disruption – with the global average cost of a breach at USD $4.44 million.
We discovered why the data layer has become the foundation of business continuity, and the role AI and regulations will play in business resilience, in this interview with Matthew Oostveen, Chief Technology Officer, Asia Pacific & Japan, Everpure.

Matthew Oostveen, Chief Technology Officer, Asia Pacific & Japan, Everpure.
In cybersecurity, the foregone conclusion is that total prevention is impossible. However, detection without recovery remains a liability. What benchmarks should organisations in Asia Pacific use to measure cyber resilience?
Oostveen: Total prevention is a myth; if a nation-state or a determined adversary wants in, they are getting in. That means resilience isn’t about building higher walls, it’s about how fast you get back on your feet when those walls are breached.
For organisations across Asia Pacific, the ultimate metric of cyber resilience is MTTR — Mean Time to Recovery. It’s the clock that ticks between the moment an attack disrupts your business and the moment you are fully operational again.
But containment is only half the battle. Your true resilience benchmark is your MTTR. In a region where digital transformation is outpacing security budgets, a resilient organization aims for an MTTR measured in hours, not days or weeks.
If your recovery strategy relies on dusting off backups you haven’t tested in six months, your MTTR is going to kill your business long before the hackers do. Detection without recovery isn’t just a liability, it’s a corporate death sentence.
How does the data layer serve as the foundation of business continuity?
Oostveen: You can rebuild applications in minutes and reroute networks with a click. But if you lose the data layer, you aren’t recovering a business, you’re starting a new one from scratch.
The data layer dictates your survival metrics. Your RTO (Recovery Time Objective – how fast you recover) and RPO (Recovery Point Objective – how much data you lose) are entirely bound to your data architecture.
When I speak to CIO customers, I remind them that integrity is the real recovery. Spinning servers back up is useless if the data inside them is corrupted or encrypted. A resilient data layer uses immutable storage, meaning hackers can’t touch your safety net.
What role does government regulation play in cyber incident recovery and business continuity planning?
Oostveen: Government regulators are no longer treating cyber-attacks as an IT problem, they are treating them as a national security risk. Compliance is no longer about avoiding a fine; it’s about proving your business has the right to exist in a digital economy.
Singapore is a good example, with recent updates to its Cybersecurity Act and the upcoming Digital Infrastructure Act placing greater focus on recovery readiness, incident response and continuity planning for critical infrastructure operators.
Regulations now dictate minimum standards for business continuity. If you don’t have tested, immutable backups and a proven MTTR, you aren’t just vulnerable to hackers, you are facing massive regulatory fines and personal liability for executives and board members.
How do you see AI helping in an organization’s resiliency strategy today and in the future?
Oostveen: Today AI can be used to compress your MTTR (Mean Time to Recovery). When a breach occurs at 3:00 AM, AI doesn’t wait for a human analyst to wake up. It instantly identifies anomalous behavior, cuts off network segments, isolates infected endpoints, and triggers automated playbooks in seconds.
In the future, I expect next-generation AI will continuously ingest infrastructure telemetry, global threat intelligence, and more to predict outages and simulate failures before they happen.
