An approved recovery target expresses what the organization needs. It does not demonstrate what its current people, technology, suppliers and workarounds can deliver.

Three states that should never be collapsed

01

Recovery requirement

The approved business need: for example, restore identity-dependent access within two hours or maintain a defined minimum service throughout disruption.

02

Planned capability

What the designed strategy, documented procedure and allocated resources are intended to achieve under stated conditions.

03

Observed capability

What tests, exercises, incidents and operational measurements show the organization actually achieved, including conditions and limitations.

These states can legitimately differ. The requirement may be two hours, the design may claim ninety minutes and the latest representative exercise may show three hours and twenty minutes. Reporting only the RTO conceals the decision-relevant gap.

How false assurance is created

False assurance often starts with reasonable-looking records that are given the wrong evidence status. A recovery plan says a system can be restored in one hour, so the one-hour figure is repeated as capability. A supplier contract promises a response time, so the promise is treated as an observed outcome. A tabletop exercise confirms that participants understand the procedure, so it is interpreted as technical recovery proof.

The figures may still be useful, but they answer different questions. A target supports prioritization. A design estimate supports planning. A contractual commitment supports accountability. Only representative observation supports a claim about demonstrated capability.

Evidence quality is not a single score. It depends on what was observed, under which conditions, at what scope and for which decision.

An identity-outage example

Consider a critical service with an approved two-hour recovery requirement and a manual workaround. The technology team reports that identity infrastructure recovered in 1.8 hours during the latest exercise. That observation is useful, but management still needs to test the boundary of the claim.

  • Did the 1.8 hours measure infrastructure availability, user access or end-to-end business service restoration?
  • Were privileged access, network, DNS, cloud and staffing prerequisites available?
  • Did the exercise include the same user volume, locations and security controls expected during a real outage?
  • Could the manual workaround sustain the required minimum service, and for how long?
  • Was the result observed repeatedly or only once?

The correct conclusion may be that one important recovery prerequisite has demonstrated a 1.8-hour result under specified conditions. That is more defensible than claiming the entire critical service can recover within two hours.

Build an evidence ladder

A useful capability view arranges evidence by what it can legitimately support.

  1. Approved requirementThe business or regulatory threshold that defines the need.
  2. Architecture and strategyThe designed recovery route, resources and prerequisite assumptions.
  3. Procedure confirmationEvidence that owners, access and steps are documented and understood.
  4. Component testObserved recovery of an individual system, supplier or workaround.
  5. Integrated exerciseObserved behavior across material dependencies and business service conditions.
  6. Real incident evidenceWhat the organization achieved under actual disruption, with context and limitations preserved.

Higher rungs do not automatically invalidate lower ones. They refine what can be claimed and where uncertainty remains.

What management should receive

A decision-ready recovery view should show the requirement, planned capability, observed capability, conditions, evidence date, material dependency gaps and decision consequence side by side. It should also distinguish a hard constraint from a preference: safety, regulatory and minimum-service obligations cannot be averaged away through a maturity score.

The result is not merely a red or green status. It is an accountable answer to a management question: Is the gap tolerable, what action is feasible, who owns it and what evidence will demonstrate effectiveness?