AI Attack Readiness | Resilience Program
Know which critical systems are ready for recovery.
See which systems meet your recovery requirements, which business units remain exposed, and what needs to change. The Resilience Program gives your board evidence of what is proven, what is unproven, and what has been excluded.
One bar, three buckets. Proven is your number, Unproven is your work, Excluded is your record.
As of Nov 18 2026: 437 total assets: 354 in-scope and 83 excluded. 322 of the 354 in-scope assets hold a proven clean recovery point. 5 of 119 critical-class assets do not hold a clean recovery point. 118 machine images are hunted for threats and carry no recovery commitment.
Named 345 + Default 9 + Excluded 83 = 437 assets.
Not provably recoverable today. Click a class or count to drill in.
See recovery commitments by business unit. Illustrative screen values and date, not a customer outcome.
Set recovery commitments by business importance.
A critical payment system and a development server do not carry the same business consequence. Their recovery requirements should reflect that.
Group systems by business unit, application, or environment using existing tags. Assign Critical, Important, or Standard classes and set the commitments each class must meet.
Review the resulting policies before committing the plan. New policies start paused so your team controls when they take effect.
Map existing inventory to business priorities and recovery commitments.
Author your Plan: assign each asset a Resilience Class, preview the policies that result, and commit. Every policy is created paused.
Every asset we found, grouped automatically by its tags. You do not build these groups: we read each asset's tags and place it for you, so the groups update on their own as assets or tags change. Set a resilience class on any group and everything inside it takes that class. If a group above it is set stricter, the stricter class wins. When the assets in a group look more important than the class you set, we flag it so you can take a second look. Switch the grouping tag to organize the same assets a different way. Nothing is saved until you sign off.
Order the discovered tags into the shape of your estate. Each tag becomes a level, and its unique values become the groups at that level.
437 assets · 7 groups · 3 levels deep49 excluded assets carry a Critical-mapped tag.
119 Critical + 116 Important + 119 Standard + 83 Excluded = 437 assets.
Standard includes 10 assets in the Default Bucket, 4 of them carry no tags. They show in the tree as the in-tree Default rows, so nothing floats outside the four classes.
354 committed, 83 excluded.
Know what makes recovery provable.
A clean copy and a protected recovery path answer different questions. Elastio brings the evidence together against the requirements set for each system.
| Recovery question | Evidence to review |
|---|---|
| Is the system backed up? | Backup coverage and available recovery copies. |
| Is the copy clean? | Pursuit finds no attack and Hunt finds no ransomware in the same copy, with analysis scope and completion recorded. |
| Is it recent enough? | The age of the latest proven clean copy, measured against the recovery target. |
| Is it protected from alteration or deletion? | Immutability and retention where required. |
| Is it isolated from production access? | Isolation from the production identity domain where required. A second region alone does not establish isolation. |
| Are the checks running? | Analysis coverage, completion, and enabled detection controls. |
Posture flags violations where requirements are not met. The Resilience Program reports recovery commitments for the systems in its scope, with exclusions and exceptions on record.
The evidence establishes a clean recovery point and its protections. Your team validates application recovery and measures how long the restore takes.
See where the business remains exposed.
A strong overall result can hide a critical system without an acceptable clean recovery point. See unmet commitments by business unit and identify the critical systems that need attention.
Proven. Evidence establishes that the system meets its recovery commitment.
Unproven. The commitment is not yet backed by sufficient evidence. A clean copy may be missing, too old, or still awaiting analysis.
Excluded. The system is outside the program under a recorded decision. Exclusions remain visible for review.
The result shows the scope and the evidence behind it. Teams can focus on the systems whose failure would matter most to the business.
Turn unproven results into a worklist.
Open an unmet commitment to see what needs attention. Align analysis policies, investigate findings, or establish a clean recovery point within the required target.
Pursuit investigates attacker activity. Hunt supplies recovery intelligence: threats and damage found in the data, clean results, and recovery history. Together, they establish which copies are clean. The Resilience Program evaluates recovery evidence against your business commitments.
A clean copy must also be recent enough to meet the requirement. Record exceptions when a commitment is relaxed, and review exclusions that affect critical systems.
Give the board evidence behind the result.
Report readiness with a dated statement: the systems in scope, the commitments met, the critical systems still exposed, and the exclusions on record.
Download a board pack in PowerPoint or Word. The evidence ledger provides the asset-level detail behind the result, including findings and recovery evidence. Security teams and leadership can review the same record at the level they need.
The Summary reports whether systems meet the Program’s recovery commitments. Evidence Detail shows the assets individually assessed in this export and their clean recovery points. These are different assessments; the report reconciles their populations and results.
Explore the sample ledger below. Start with the board summary, then open Evidence Detail and filter to Unproven to see the asset, the missing evidence, and the required action.
For example, cos-finance-vault-03 has no covering policy and no clean recovery point on record. The ledger identifies the next action: bring it into a policy and prove a recovery point.
Recovery evidence supports the commitment. Your team also validates that recovered applications and services work.
Sample report: synthetic inventory with actual Pursuit and Hunt findings. The Program summary and individually attested asset results use different populations and criteria; the report explains both.
The population this report covers is the resilience program's, so the reader can judge completeness rather than assume it. The resilience program covers 437 assets (354 in scope, 83 excluded). This report line-items all 437 assets in the program scope, uncapped, and individually attests 253 of them (184 fold into a parent asset and are not line-itemed individually).
| Verdict | Count | In the denominator? |
|---|---|---|
| Proven | 322 | Yes (numerator) |
| Unproven | 32 | Yes |
| Excluded | 83 | No |
| In-scope total | 354 | = denominator |
| Provable | 91% | 322 / 354 |
| Business unit | Assets | Proven | Unproven | Excluded | Not attested | Provable % (attested) | Threats | R-RPO Class |
|---|---|---|---|---|---|---|---|---|
| capital-markets | 101 | 43 | 3 | 15 | 40 | 93.5% | 22 | Standard |
| retail-banking | 89 | 30 | 3 | 21 | 35 | 90.9% | 3 | Critical |
| corporate | 86 | 24 | 5 | 17 | 40 | 82.8% | 3 | Important |
| mortgage | 84 | 34 | 0 | 20 | 30 | 100% | 1 | Critical |
| wealth | 65 | 20 | 2 | 8 | 35 | 90.9% | 2 | Critical |
| No Business unit | 11 | 0 | 5 | 2 | 4 | 0% | 0 | Standard |
| compliance | 1 | 0 | 1 | 0 | 0 | 0% | 0 | Standard |
| All business units | 437 | 151 | 19 | 83 | 184 | 88.8% | 31 | 51 critical, 46 important, 73 standard assets |
What this is. A board-facing evidence report from the resilience program. Summary is the executive view; Evidence Detail lists the assets with their recovery verdict and the findings behind it. Hashing and documentation follow the practices in NIST SP 800-86 and ISO/IEC 27037.
Sample disclaimer. The asset inventory is a synthetic demonstration list; the findings shown are actual results from real Pursuit analyses and Hunts. It is a format demonstration, not a live attestation of one environment.
Integrity. No cryptographic integrity seal is applied to sample data: a hash over a synthetic inventory would be technically true about fabricated bytes and misleading as evidence, so none is shown.
The population this report covers is the resilience program's, so the reader can judge completeness rather than assume it. The resilience program covers 437 assets (354 in scope, 83 excluded). This report line-items all 437 assets in the program scope, uncapped, and individually attests 253 of them (184 fold into a parent asset and are not line-itemed individually).
| Asset | Business unit | Class | Verdict | Threat | Last clean recovery point | Recovery action |
|---|---|---|---|---|---|---|
| cos-finance-vault-03 | corporate | Critical | Unproven | None | None on record | No covering policy; this asset has no proven backup. Bring it into a policy and prove a recovery point. |
| fsxvol-fin-erp-01 | retail-banking | Critical | Unproven | None | None on record | No covering policy; this asset has no proven backup. Bring it into a policy and prove a recovery point. |
| fsxvol-fin-erp-02 | wealth | Critical | Unproven | None | None on record | No covering policy; this asset has no proven backup. Bring it into a policy and prove a recovery point. |
| mt-loan-documents | corporate | Critical | Unproven | None | None on record | No covering policy; this asset has no proven backup. Bring it into a policy and prove a recovery point. |
| vol-orphan-finance-002 | corporate | Critical | Unproven | None | None on record | No covering policy; this asset has no proven backup. Bring it into a policy and prove a recovery point. |
| fsxvol-marketing-04 | corporate | Important | Unproven | None | None on record | No covering policy; this asset has no proven backup. Bring it into a policy and prove a recovery point. |
| mt-cos-regulatory-archive | capital-markets | Important | Unproven | None | None on record | No covering policy; this asset has no proven backup. Bring it into a policy and prove a recovery point. |
| vol-orphan-eng-003 | corporate | Important | Unproven | None | None on record | No covering policy; this asset has no proven backup. Bring it into a policy and prove a recovery point. |
| vol-orphan-prod-001 | capital-markets | Important | Unproven | None | None on record | No covering policy; this asset has no proven backup. Bring it into a policy and prove a recovery point. |
| crown-app-12 | retail-banking | Standard | Unproven | Pursuit: active intrusions Active intrusion / persistence detected | None on record | No clean recovery point on record; contain, then rebuild from a vaulted copy. |
| crown-app-17 | retail-banking | Standard | Unproven | Pursuit: active intrusions Active intrusion / persistence detected | None on record | No clean recovery point on record; contain, then rebuild from a vaulted copy. |
| fin-etl-03 | capital-markets | Standard | Unproven | Pursuit: active intrusions Active intrusion / persistence detected | None on record | No clean recovery point on record; contain, then rebuild from a vaulted copy. |
| fsxvol-eng-shared-03 | wealth | Standard | Unproven | None | None on record | No covering policy; this asset has no proven backup. Bring it into a policy and prove a recovery point. |
| host-eng-build-03 | No Business unit | Standard | Unproven | None | None on record | No covering policy; this asset has no proven backup. Bring it into a policy and prove a recovery point. |
| host-finance-build-01 | No Business unit | Standard | Unproven | None | None on record | No covering policy; this asset has no proven backup. Bring it into a policy and prove a recovery point. |
| host-finance-jump-02 | No Business unit | Standard | Unproven | None | None on record | No covering policy; this asset has no proven backup. Bring it into a policy and prove a recovery point. |
| mt-cos-dr-replica | compliance | Standard | Unproven | None | None on record | No covering policy; this asset has no proven backup. Bring it into a policy and prove a recovery point. |
| ova-legacy-erp-02 | No Business unit | Standard | Unproven | None | None on record | No covering policy; this asset has no proven backup. Bring it into a policy and prove a recovery point. |
| ova-legacy-fileserver-03 | No Business unit | Standard | Unproven | None | None on record | No covering policy; this asset has no proven backup. Bring it into a policy and prove a recovery point. |
What this is. A board-facing evidence report from the resilience program. Summary is the executive view; Evidence Detail lists the assets with their recovery verdict and the findings behind it. Hashing and documentation follow the practices in NIST SP 800-86 and ISO/IEC 27037.
Sample disclaimer. The asset inventory is a synthetic demonstration list; the findings shown are actual results from real Pursuit analyses and Hunts. It is a format demonstration, not a live attestation of one environment.
Integrity. No cryptographic integrity seal is applied to sample data: a hash over a synthetic inventory would be technically true about fabricated bytes and misleading as evidence, so none is shown.
Keep daily security work connected to the commitment.
Recurring Pursuit and Hunt analysis updates the evidence at the frequency you set. Active Intrusions directs responders to attackers. Posture identifies control violations. The Resilience Program connects recovery evidence to business commitments and board reporting.
Use the findings to direct response, close unmet recovery requirements, and report which commitments are backed by evidence.
Review readiness for your critical systems.
Map your business priorities to recovery commitments. See the unmet requirements, the work ahead, and the evidence your board will receive.
Request a demo