error
Subscriptions are not available for this site while you are logged into your current account.
close
Skip to main content

Loading

The page is loading.

Please wait...


      More than 600,000 UK businesses were hit by a cyber attack over the past year¹ and the National Cyber Security Centre managed more than 200 incidents on the UK’s critical national infrastructure.² As business and cyber security leaders assess their own resilience, the concept of the Minimum Viable Company is moving up the agenda. This article explains why and what it takes to build one.

      What is an MVC?

      A Minimum Viable Company (MVC) defines the minimum set of capabilities, data, technology, people and third parties an organisation needs to keep operating during a crisis, particularly when critical digital services are compromised.

      The idea started life in cybersecurity continuity planning. Today, it's grown into a full technology resilience strategy, covering not just cyber incidents but geopolitical instability, supply chain failures and cloud outages.

      Tom Bragg

      Cloud Director

      KPMG in the UK


      Janina Herrmann

      Director, Consulting Cyber and Resilience

      KPMG in the UK


      Business resilience now depends on preparing for severe, systemic digital disruption. That means shifting from a focus on preventing incidents to instead prioritising the ability to ensure it can recover rapidly when major disruptions occur.

      Five reasons why MVPs are moving up the business resilience agenda

      • Geopolitical cyber activity is becoming more disruptive.

        Attacks increasingly target identity systems, cloud hosting and operational technology.

      • Cloud and SaaS reliance creates systemic dependencies.

        A single provider outage can cascade into organisation-wide disruption without a plan for data portability and rapid rebuild.

      • Ransomware now targets backups and identity systems directly.

        Modern attacks aim to maximise restoration difficulty.

      • Interconnected supply chains amplify exposure.

        A disruption at one partner can propagate quickly through shared APIs and systems.

      • Continuity is table stakes.

        Customers, regulators and shareholders have far less tolerance for downtime.


      In a period defined by volatility, the MVC has moved well beyond a niche cybersecurity concept to become a board-level resilience strategy. Done well, it means your organisation can stay operational under severe digital stress, restore critical services fast and give leadership genuine clarity on where they should invest in order to ensure they can deliver on their service obligations no matter what.


      Three key cyber resilience considerations for the MVC

      For an organisation to remain operational during extreme disruption, the MVC should define the minimum viable set of:


      Core capabilities:

      Identity and access management with emergency controls, crisis communications, financial continuity and the operational workflows unique to your business.

      Core data:

      Essential customer and supplier data, operational schedules and core financial and legal datasets, along with a clear plan to reintegrate this with full system restores.

      Core technology infrastructure:

      Resilient cloud landing zones, air-gapped backups, clean-room recovery environments and rapid rebuild automation for critical systems.

      Getting started with an MVC

      When KPMG professionals help leading organisations to design, execute and update their MVC programmes, we typically guide our clients through four phases: analysis, to identify the business processes you cannot survive without and their maximum outage window; design, translating those processes into supporting applications and blueprint architectures; implementation of the tooling; and continuous, automated testing to keep the MVC fit for purpose as the business evolves.


      This isn't a heavy lift. The focus is on refining and reinforcing the resilience measures you already have and proving they hold up when it counts. Working through these steps iteratively delivers early ROI and starts protecting the organisation from day one.

      Oisin Fouere, Global Crisis and Incident Response Lead

      KPMG LLP

      5 common pitfalls to avoid

      At KPMG, our people bring significant experience helping organisations large and small to stand up a working copy of their critical business systems. Based on our experience, here are five common pitfalls that every organisation should avoid when developing an MVC.


      • Taking a systems-led approach.

        Focus on the business processes that actually need restoring.

      • Protecting the kitchen sink

        Be realistic about what's truly needed to keep customers served.

      • Treating everything equally.

        Make sure you put your focus exactly where it matters most.

      • Focusing on applications only

        Recovery speeds up once you define the minimal data needed.

      • Ignoring the full recovery journey

        Plan for day two and onwards, not just the initial recovery.


      How KPMG can help

      KPMG helps organisations define, build and test their MVC, from identifying critical business processes through to implementing resilient architecture and running continuous recovery testing.

      Our approach blends deep technical delivery with practical business prioritisation, so your resilience investment protects what really matters.

      Check out our cyber services website here or contact your trusted KPMG advisor to learn more.


      Download

      Minimum Viable Company (MVC): Building Resilience Against Cyber and Operational Disruption

      A KPMG guide to Non-Human Identity (NHI) Management, covering machine identities, service accounts, API keys, cloud workloads, AI agents, and automated systems.


      Our advisory insights

      Something went wrong

      Oops!! Something went wrong, please try again

      MTD

      Get in touch


      Discover why organisations across the UK trust KPMG to make the difference and how we can help you to do the same.