This week, several organizations publicly reported operational disruption following cyber incidents. One organization couldn't process property transactions. Another temporarily suspended production. In both cases, the operational disruption continued while the affected technology was being dealt with. Sometimes stopping is the right decision. Safety, regulatory requirements, product integrity, or simply not knowing enough about what's happening may leave no responsible alternative. But a technology outage doesn't automatically have to mean the entire operation stops. It's worth knowing ahead of time which business functions could continue safely, which ones couldn't, and what people would need in order to keep the critical work going. Most cyber recovery planning understandably focuses on restoring systems as quickly as possible. There's another period we need to plan for too: the hours or days before those systems are restored. What can the organization still do during that time? That may mean manual workarounds, alternate communications, reduced operations, different decision authorities, or temporarily delivering a service in a completely different way. 💬 Discussion question: If one critical technology your organization depends on disappeared tomorrow, what business function would leadership be most reluctant to stop—and why?