Why every organisation needs a minimum viable company strategy

By Bhavyan Mehta, Vice President – Engineering, Commvault

As Indian enterprises accelerate digital and cloud adoption, cyber resilience is emerging as a critical business priority. For modern organisations, the main challenge associated with cyber-attacks has shifted from whether an attack will occur to how quickly they can restore essential operations once it does. In India, this shift is becoming increasingly urgent as cyber risk moves from an IT concern to a boardroom priority. Recent findings from the FICCI–EY Risk Survey 2026 show that 51% of Indian enterprises rank cybersecurity breaches as the top risk to organisational performance, while 61% of leaders highlight cyberattacks as a major financial and reputational threat. This growing risk landscape is forcing organisations to rethink resilience, with recovery speed, data integrity, and operational continuity now central to business strategy.

The Minimum Viable Company

Dealing with this kind of sobering reality requires a fundamental shift in perspective. A significant part of the problem is that traditional disaster recovery strategies typically focus on restoring the entire IT environment, a process that can take months, leaving even the most well-resourced businesses unable to function properly in the meantime.

The alternative lies in rethinking how organisations approach resilience. This is where the Minimum Viable Company (MVC) concept comes into play. An MVC is the leanest version of a business that is still capable of operating and serving its customers if parts of its systems or processes are disrupted. This approach helps organisations maintain continuous business, even amidst a cyber-attack.

From an operational and IT point of view, what constitutes minimum viability will vary from one organisation to another, but typically the emphasis falls on areas such as communication and collaboration platforms, identity and access management systems, and the core business applications that underpin supply chains, logistics, finance, customer services, and core operational functions.

Without these essential services up and running, even a business that is technically “recovering” can remain unable to function. The MVC, therefore, represents a practical starting point for resilience planning, bridging the gap between immediate continuity and longer-term restoration. In today’s environment, this also means ensuring that both data and identities can be recovered cleanly and reliably to restore operational trust.

Defining an MVC

While the logic behind the MVC is straightforward, and recent research found that 36% of businesses recognise with its value, most organisations struggle to define and size it. The biggest barriers were found to be the complexity of existing systems and applications (52%), keeping recovery plans in line with changing business needs (47%), and difficulties separating ‘core’ systems from ‘broader’ operations (30%). Large enterprises in particular often lack a clear, documented view of the systems and processes that make up their minimum viable state, and even fewer have tested that view end to end.

A key part of the difficulty lies in the way IT functions are typically structured. Teams responsible for networking, storage, cloud platforms, collaboration tools and servers tend to operate in silos, which means critical dependencies between systems are easily overlooked. A customer-facing application, for example, may rely on ERP, warehousing and CRM platforms in the background. Without all of these aligned, restoring the front-end service alone achieves very little.

The complexity of hybrid infrastructures is another factor. With on-premises, SaaS, and cloud-native services running in parallel, determining what to recover and in what order is far from straightforward.

For many Indian enterprises, accelerating cloud adoption, this complexity is further amplified by distributed environments and multi-cloud strategies. The result is that organisations remain vulnerable to extended disruption, even when they believe they have resilience plans in place.

When a major incident occurs, incident response and recovery teams both need access to the same infrastructure under intense pressure. Safeguards that organisations expect to rely on frequently fail, as disaster recovery sites can be compromised if they share the same domain, and backups are often corrupted or encrypted.

As a result, identifying a clean restore point can take days, with further time needed to build infrastructure and validate applications. Total downtime of 20 to 23 days is not unusual — a period many organisations would struggle to withstand. The need to move beyond traditional recovery metrics toward clean, validated recovery is becoming a core resilience requirement. This underlines why defining an MVC in advance is critical: it provides a baseline for recovery that avoids weeks of paralysis.

Sizing an MVC
As a rule of thumb, allocating around 20% of production in terms of storage, compute and workload scope offers a workable resource baseline. This subset should be made immutable and air-gapped to protect it from compromise, with around 10% of that allocation reserved for a cleanroom or isolated recovery environment.

For example, an organisation with a 4-petabyte production estate could begin with 800 terabytes of immutable backup, of which 80 terabytes are set aside for clean recovery. While not a substitute for full MVC analysis, this approach provides a foundational layer of resilience while longer-term planning continues.

By knowing in advance which systems and data to prioritise, organisations avoid the inefficiency of trying to restore everything at once. Recovery efforts can focus on the core environment that keeps operations moving, while the broader IT estate is brought back in parallel.

Added to this, modern recovery platforms can also cut downtime dramatically. By continuously scanning backup copies for malware, identifying clean restore points, spinning up isolated recovery environments on demand and orchestrating application rebuilds with dependencies intact, recovery that once took 20 days can be reduced to a matter of hours or a single day. This shift reflects a broader move toward resilience operations (ResOps), where recovery readiness, validation, and orchestration are embedded into everyday operations rather than treated as a one-time event.

Equally, bringing incident response and recovery into a single pane of glass is a big advantage, not least because it enables teams to ensure the right systems are restored in the right order. For smaller organisations, this can begin with a minimal package such as immutable backup of Microsoft 365 and secure Active Directory recovery, while enterprises can scale the same principles with consulting support. For Indian enterprises navigating rapid cloud adoption and increasingly complex hybrid environments, this unified approach becomes even more critical to maintaining operational continuity.

Either way, establishing a Minimum Viable Company, with a focus on clean recovery and identity resilience, can go a long way to mitigating the headline-grabbing risks of business downtime.

Minimum Viable Company
Comments (0)
Add Comment