Known-Good-State Recovery

Known-Good-State Recovery is the recovery from a data or system state that was assessed as functional and trustworthy before the restore is carried out. Especially after cyberattacks, it is not sufficient to simply use the most recent backup, because it too may already contain damaged, manipulated or unwanted changes.

A “known good state” is therefore selected and validated on the basis of defined criteria. These can include integrity checks, malware scans, the time reference to the incident, configuration checks and functional tests of the applications. The aim is to reduce the probability that compromised data or faulty settings re-enter the production environment during restart.

Known-good-state recovery connects technical recovery with IT Security and Automated Security Validation. Especially in the case of ransomware and targeted attacks, the reliable determination of a clean starting state is a central component of recovery planning and of the restart itself.