Analyst reviewing resilience status on the Horizon dashboard
Secure Chain Horizon

Know whether you could actually recover — and prove it.

The Cyber Resilience Dashboard in Horizon brings recovery testing, incident response exercising and detection coverage into one tracked view, so resilience is something you can evidence rather than assume.

Recovery tests logged
24
Response exercise
1
Detection gaps open
5
Illustrative figures
The challenge

Most organisations assume they can recover. Few can show it.

Ask most boards whether the organisation could recover from a serious ransomware event or a prolonged outage, and the honest answer is usually 'we think so'. Backups are running, there's an incident response plan somewhere on a shared drive, and IT has never raised the alarm. That's reassurance, not evidence, and the difference matters enormously the day it's actually tested.

Recovery readiness quietly decays. A backup job can run successfully every night for months while the restore itself has never been attempted, or has been attempted once, years ago, on a system that has since changed shape. Incident response plans are written, signed off, and then left untouched while the people named in them change roles, leave the organisation, or simply forget the plan exists.

Detection has the same problem in reverse. New systems, new cloud services and new suppliers get added to the environment continuously, but monitoring coverage doesn't automatically extend to match. A gap that was accepted as low risk eighteen months ago because the system was minor can quietly become significant once that system starts holding customer data or connecting to something critical.

Regulators and insurers have stopped accepting reassurance as an answer. Operational resilience expectations in financial services, healthcare and critical infrastructure increasingly require dated, specific evidence: when was the last successful restore, when was the incident response plan last exercised, what does the dependency map look like for the systems that would take the business down if they failed. Producing that evidence under pressure, during a renewal deadline or a regulatory return, is a poor time to discover it doesn't exist.

Boards, meanwhile, are being asked sharper questions by non-executives, auditors and clients alike — not 'do you have a plan' but 'when did you last test it, and what did it show'. Without a consistent record, that conversation defaults to whoever in the room sounds most confident, which is not a sound basis for a resilience judgement.

  • Backup jobs that run successfully with restores never actually verified
  • Incident response plans that are current on paper but untested in practice
  • Detection coverage that hasn't kept pace with new systems and suppliers
  • Evidence assembled from memory and email threads under audit or renewal pressure
Our approach

We help you build the evidence trail, and Horizon holds it.

We start by working through what resilience actually looks like for your organisation: which systems and services genuinely matter if they fail, what recovery time is realistic against what's expected, and where the current gaps sit between the two. That's consultancy work, done with your team, not something a dashboard produces on its own.

From there, backup and restore testing gets a proper cadence. We help set a realistic testing schedule for critical systems, and each result — success, failure, time taken, issues found — is logged in Horizon rather than left in an engineer's notebook. Over time this builds a record that shows whether recovery capability is improving, holding steady, or quietly slipping.

Incident response plans get the same treatment. We support tabletop exercises and, where appropriate, more realistic simulations, and record the date, participants, findings and follow-up actions in Horizon. A plan that hasn't been exercised in over a year is flagged automatically rather than relying on someone remembering to check the calendar.

Detection coverage is mapped against your actual estate: systems, cloud services and third-party dependencies, cross-referenced with what's genuinely monitored today. Known gaps go into Horizon as tracked items with an owner and a target date, so they move from 'a finding in last year's report' to something actively closed down.

None of this replaces the people who do the recovering — your IT team, your incident responders, your suppliers. Horizon's job is to hold the record straight: what's been tested, what's overdue, what's improved and what hasn't, presented in a form a board, an insurer or a regulator can actually use.

  • Recovery testing scheduled and logged, not assumed from a green backup job
  • Incident response exercises dated, with findings tracked to closure
  • Detection gaps mapped against the real estate and dependencies, not a generic checklist
  • One evidence trail, exportable, instead of scattered spreadsheets and inboxes
What's included

Everything in the engagement, set out up front.

A resilience-focused build within Horizon, set up around your critical systems and dependencies.

Critical system identification

A structured session to agree which systems and suppliers genuinely matter to recovery time, before anything is tracked.

Recovery test tracking

Backup and restore results logged against a schedule, with overdue tests flagged rather than assumed complete.

Response plan and exercise log

Plan review dates, exercise dates, participants and follow-up actions held in one record, not a shared drive.

Detection coverage register

Known monitoring and alerting gaps tracked as owned items with target dates, mapped against your actual estate.

Dependency mapping

A working map of the systems, services and suppliers a serious incident would realistically affect.

Board and third-party export

Resilience status exported in a format suited to board packs, insurer questionnaires and regulatory returns.

Deliverables

What you receive.

  • Critical systems and dependency map
  • Backup and restore testing schedule with logged outcomes
  • Incident response plan status and exercise history
  • Detection coverage gap register with owners
  • Resilience summary suitable for board reporting
  • Exportable evidence pack for insurers or regulators
  • Overdue-item alerting for recovery and exercise dates
  • Role-based access for IT, risk and executive stakeholders
Who it suits

Built for organisations that need the work done properly.

Boards asked sharper resilience questions

Organisations whose non-executives, auditors or clients now ask when things were tested, not just whether a plan exists.

Regulated and critical-sector organisations

Financial services, healthcare and infrastructure firms facing explicit operational resilience expectations from their regulator.

Firms renewing cyber insurance

Businesses whose insurer now asks for dated recovery and response evidence rather than a general description of controls.

Organisations that have grown their estate

Businesses where new systems and suppliers have outpaced monitoring coverage, and nobody currently has a clear view of the gap.

Outcomes & benefits

What changes once the work is done.

What's different once resilience is tracked rather than assumed.

A real answer, not a guess

Leadership can state, with a date attached, when recovery was last tested and what it showed.

Response plans stay live

Exercises happen on a schedule instead of drifting, and findings from each one get closed rather than filed.

Detection gaps get owners

Known monitoring blind spots are tracked to closure instead of resurfacing in next year's review.

Faster insurer and regulator responses

Evidence exports directly instead of being reconstructed from memory against a deadline.

Dependencies made visible

A clear map of what a serious incident would actually affect, rather than an assumption drawn up on the day.

One record for everyone

IT, risk and the board work from the same evidence, rather than separate and sometimes conflicting versions.

Tracking resilience honestly, not performing it.

There's a temptation, understandable under audit or renewal pressure, to make the paperwork look better than the reality. Horizon is built the other way round: it reports what's actually been tested and what hasn't, including the gaps that are inconvenient to admit. A dashboard that only shows good news isn't resilience evidence, it's a liability waiting to be discovered at the worst possible time.

That honesty matters most in the moments nobody plans for. If a serious incident does happen, the organisations that recover well are almost always the ones who'd already rehearsed the plan and knew their backups actually restored, not the ones with the most polished policy document. Horizon can't do that rehearsal for you, but it can make sure the rehearsal happens on a schedule and the result is on record.

We work with clients across Chesterfield, Sheffield, Derby, Nottingham, Leeds, Manchester, Birmingham and London on exactly this problem, and the pattern repeats regardless of sector: the technical capability to recover is often better than the evidence suggests, because nobody has been tracking it consistently. Getting the record straight is frequently more valuable, and considerably cheaper, than buying additional tooling.

This dashboard sits alongside the rest of Horizon rather than replacing any of it — the risk register, control management and supplier register all feed a fuller picture of exposure. Resilience is what happens when that exposure turns into an actual incident, and this is the part of Horizon built specifically to show whether you're ready for that day, with evidence rather than confidence.

Frequently asked questions

Questions we are asked most often.

What does the Cyber Resilience Dashboard actually track?

It tracks the evidence of resilience: when backups were last tested and whether restores succeeded, whether the incident response plan has been exercised and when, known detection coverage gaps, and dependency mapping for critical systems and suppliers. It reports status against those markers over time so patterns of drift are visible, rather than being rediscovered during an incident.

Is this the same as the Horizon executive dashboard?

No. The executive dashboard gives leadership a broad view across risk and compliance. This view is narrower and specifically resilience-focused — recovery readiness, response exercising and detection coverage — for teams and boards who need to answer one question directly: could we detect, respond to and recover from a serious incident, and can we prove it?

Does Horizon perform the backup or recovery testing itself?

No. Horizon records the outcome of tests your team or provider carries out — restore success, time taken, issues found — and flags when a system is overdue a test. The testing itself, and any fixes it identifies, remain the responsibility of your operations team or managed service provider.

Can this replace our incident response plan?

No. Horizon tracks whether a plan exists, when it was last reviewed, and when it was last exercised — plus any actions raised from that exercise. Writing and rehearsing the plan is still work your team, or a consultant supporting you, needs to do. The dashboard exists to stop that plan going stale unnoticed between exercises.

How does this help with insurance renewal or regulatory questions?

Insurers and regulators in sectors with operational resilience expectations increasingly ask for evidence, not assurances: proof of tested backups, a dated incident response exercise, a record of detection coverage. Horizon exports that evidence in a format that can go directly into a renewal questionnaire or a regulatory return, cutting down the scramble to assemble it manually.

What counts as a detection coverage gap in Horizon?

It's a logged area where monitoring, alerting or visibility is known to be absent or incomplete — an unmonitored system, a log source not yet feeding your SIEM, or a device class outside current endpoint coverage. Horizon holds these as tracked items with an owner and a target date, rather than as a one-off finding in a report that gets filed and forgotten.

Do we need a SOC or managed detection service to use this?

It helps, but it isn't mandatory. Horizon records whatever detection and monitoring arrangements you have, including gaps where none exist yet, and reports honestly on the state of coverage either way. Many clients use the dashboard to build the business case for extending monitoring before commissioning that work.

How often should recovery and response evidence be updated?

Most organisations we work with review recovery test evidence quarterly and log a response exercise at least annually, more often in regulated sectors. Horizon flags items as they approach their review date rather than waiting for them to lapse, so updates happen on a predictable cycle instead of in a rush before an audit.

Want to see where your resilience evidence actually stands?

Book a low-pressure resilience review or a short walkthrough of the dashboard, and we'll talk through what's already tracked and what isn't.

Book a resilience review