When organizations experience a cyberattack, executives often focus on recovery timelines, business impact, and regulatory obligations. Yet the outcome of those conversations is often determined long before recovery begins.