When SEBI designed the CSCRF around the NIST Cybersecurity Framework structure, it included all five functions: Identify, Protect, Detect, Respond, and Recover. Of these, Recovery is frequently the least mature function in practice.

The irony is painful: recovery is arguably the most important function. When everything else fails — when prevention fails, when detection is too late, when response cannot contain the damage — recovery is what keeps the organization alive. Yet it receives the least investment, the least testing, and the least evidence discipline.