Only 26% of Canadian businesses had written cyber security policies in place in 2023, according to Statistics Canada. For everyone else, the question of what Lower Mainland businesses should restore first gets answered mid-outage, with every department insisting its system matters most.
That is a hard moment to make a calm decision. Phones are ringing, the team is idle, and the person who knows where the backups live may be on holiday. A recovery order written in advance turns that scramble into a checklist.
Recovery Is a Sequence, Not a Switch
Most people picture recovery as a single event: the systems were down, and then they were back. In practice, systems return one at a time, and each one depends on something underneath it. An accounting platform is useless if nobody can sign in, and signing in is impossible while the internet connection is still out.
That dependency chain is why order matters. Restore the wrong system first and staff will sit in front of a working application they cannot reach. Put the right foundation back first and everything above it returns faster.
Ransomware raises the stakes on sequence. Statistics Canada found that 13% of Canadian businesses impacted by a cyber incident in 2023 were hit with ransomware, and 88% of those victims did not pay. For many, that means the road back runs through their own backups, one system at a time.
Three Numbers That Set the Order
The Canadian Centre for Cyber Security (the Cyber Centre) recommends that every IT recovery plan define how much disruption the organization can tolerate. Three measures do most of the work, and none of them require technical training to understand.
- Maximum tolerable downtime: how long a process can stay unavailable before it causes significant harm to the business.
- Recovery point objective: how much data you can afford to lose, measured as the gap between the last good backup and the outage.
- Recovery time objective: how quickly a system needs to be running at the minimum level its owner expects.
These numbers are business decisions, not IT settings. An office manager knows that invoicing can slip a day. The controller knows whether payroll runs this Friday, and leadership knows which client deadlines carry penalties.
Once each process has its tolerances written down, the restore order largely sorts itself. Whatever has the shortest tolerable downtime goes near the top, and anything that can wait a week drops to the bottom.
Dependencies Hide in Plain Sight
Cloud services change the recovery picture, but they do not remove it. A cloud accounting platform may be running perfectly while your office has no internet, or while every staff account is locked after a password reset. From the desk of an employee, that looks the same as an outage.
Hybrid environments add another layer. Many organizations across the Lower Mainland run a mix of cloud applications, a server or two in a back room, and specialized software tied to a single workstation. Each piece has its own path back, and those paths often cross in ways nobody has written down.
The fastest way to expose those links is to ask the same questions about every system before anything goes wrong:
- Where does it run: in the office, in a data centre, or in a cloud service?
- What does it need before it works, such as internet, sign-in, or another application?
- Where is its backup, and when was a restore last tested successfully?
- Who is the vendor contact, and is that number written somewhere outside the network?
- Which staff member can confirm it is working properly once it returns?
A label printer that only works from one computer, or a licence server nobody remembers, can quietly hold up an entire department.
Running the Payroll Versus Email Test
So which wins, payroll or email? It depends on the calendar. On the day before payroll runs, the payroll system may be the most urgent thing in the building, yet two weeks later it can comfortably wait while client communication comes back.
That is why a single fixed ranking rarely holds up. A better approach for working out what Lower Mainland businesses should restore first is to group systems into tiers, then note the specific dates that move something up a tier.
Tier One: The Foundation
Nothing else works without these. Internet connectivity, user sign-in, and the secure backup copies themselves sit at the base. Security tools that confirm the environment is clean belong here too, since restoring onto a compromised network only restarts the problem.
Tier Two: The Work That Pays the Bills
These are the systems tied directly to revenue and client commitments. For a professional services firm, that might mean document management and time tracking. In construction or manufacturing, it could be project files, scheduling, and the estimating software crews rely on. A non-profit might put donor records and program scheduling in this tier instead.
Tier Three: What Can Wait a Day
Some systems feel urgent but rarely are. Archived files, internal wikis, and reporting dashboards can usually stay offline while core work resumes.
A typical tier list for a 40-person professional office in the region might look like this:
- Tier one: internet and firewall, sign-in accounts, verified clean backups, and endpoint security.
- Tier two: email, phones, the practice management or accounting system, and shared client files.
- Tier three: archives, intranet pages, analytics, and nonessential applications.
- Date-driven exceptions: payroll moves to tier one in the two days before each pay run, and accounting moves up at month-end and ahead of tax filing deadlines.
Details will differ for every company. The structure is what makes the decision fast.
The Step That Comes Before Any Restore
Speed can work against recovery. After a cyber attack, restoring files onto systems that are still infected can hand the attacker a second chance.
The Cyber Centre's ransomware guidance sets out a clear order of operations. Affected devices are isolated first, then the point of entry is identified and closed before anything reconnects to the network. Backups get scanned for malware before they are used, and passwords across systems and accounts are reset because attackers often keep stolen credentials for later.
Those copies need protection long before an incident. The Cyber Centre advises keeping backups encrypted and stored offline, since anything connected to the network can be infected along with everything else. A recovery order means little if the copies it depends on are compromised.
Before any tier-one system comes back, a short checklist helps:
- Confirm affected devices are disconnected from the network.
- Identify how the attacker got in and close that gap.
- Scan backup files for malware before restoring from them.
- Reset passwords on all systems, devices, and accounts.
- Record what was found, since insurers and investigators may ask.
- Bring tier-one systems back in order, confirming each one works before starting the next.
Not every outage is an attack. A failed server, a flooded office, or a lengthy power cut skips the forensic steps but still follows the same tiered order.
Who Decides, and Where the Plan Lives
According to the Cyber Centre, a recovery plan should document what needs to be recovered, when, where, and by whom. That last part is often missing. A clear answer to what Lower Mainland businesses should restore first only helps if someone has the authority to act on it.
Each tier needs an owner who can approve its restoration and confirm it works. That person does not need to be technical. They need to know what "working" looks like for their team, so IT knows when to move on to the next system.
Where the plan is stored matters as much as what it says. The Cyber Centre recommends keeping response plans available offline, because a document saved on the encrypted server is no help during the outage. A printed copy in the office and another with a senior leader covers most situations.
The Cyber Centre also recommends a communications plan for key stakeholders, plus training so employees understand their roles and the order of operations during an unplanned outage. When staff know which systems return first and roughly when, they can give clients a useful update instead of a guess. A short, honest message to clients on day one earns far more goodwill than silence.
Where Insurance Fits In
Insurance belongs in this conversation but cannot replace it. Statistics Canada reported that 22% of Canadian businesses carried cyber risk insurance in 2023. Among those policies, 44% covered restoration of software, hardware, and data, and 39% covered business interruption. A policy may help with recovery costs, but it will not tell the team which system comes back first.
Recovery is also getting more expensive. Statistics Canada found that total spending on recovery from cyber incidents doubled between 2021 and 2023, even as the share of businesses impacted declined. The agency notes this may mean the consequences of each incident are becoming more severe.
Building the List in an Afternoon
A recovery order does not need to be a binder. For most small and mid-sized organizations, a working first version can come together in one focused session with the right people in the room.
- List every system the business uses, including cloud services, phones, and line-of-business software.
- Ask each department head how long their process can be down before it causes serious harm.
- Note the dates that change priorities, such as payroll, month-end, and seasonal peaks.
- Sort systems into three tiers and name an owner for each.
- Print the plan and store copies outside the office network, including one with a senior leader at home.
- Walk through it once with the team, reading each step aloud without enacting it.
The Cyber Centre describes several ways to test a plan, from a simple read-through to a full simulation. Even the read-through tends to surface gaps, such as a vendor contact nobody has or a password that lives in one person's head.
Plans also age. New software, a new office, or staff turnover can quietly reshuffle priorities, so the list deserves a fresh look whenever the business changes and at least once a year.
The Order Is the Plan
Knowing what Lower Mainland businesses should restore first is less about technology than about priorities leadership already understands. The hard part is settling them while things are quiet and writing them where the team can find them.
When the next outage arrives, the difference shows up in the first hour. One team argues about where to start. The other picks up a sheet of paper and begins at line one.
Sources:
- Statistics Canada, "Impact of cybercrime on Canadian businesses, 2023," The Daily: www150.statcan.gc.ca/n1/daily-quotidien/241021/dq241021a-eng.htm
- Canadian Centre for Cyber Security, "Developing your IT recovery plan (ITSAP.40.004)": cyber.gc.ca/en/guidance/developing-your-it-recovery-plan-itsap40004
- Canadian Centre for Cyber Security, "Ransomware: How to prevent and recover (ITSAP.00.099)": cyber.gc.ca/en/guidance/ransomware-how-prevent-and-recover-itsap00099