University of East London  |  CyberASAP, Innovate UK

From self-attestation
to machine-verifiable
recovery evidence

vRecover connects to your existing systems and automatically proves you can recover from a cyberattack - giving your insurer and contract partners the evidence they now require.

80%
of UK SMEs never test their backups (Sophos)
£197M
cyber insurance payouts, up 230% (ABI)
100k+
UK SMEs facing insurance and CE renewals now

Read-only in.
Assurance pack out.

vRecover sits outside your systems as an independent auditor. No agents installed, no passwords stored, no disruption. Like a continuous MOT for cyber recovery - not once a year.

01
Connect
Read-only API link to Microsoft 365, backup services, and cloud storage. OAuth tokens only — revoke any time.
No passwords stored
02
Verify
Checks MFA status, admin access, backup schedules, restore evidence, and RTO documentation against NCSC requirements.
NCSC-aligned
03
Prioritise
Plain-English ranked actions. Each one tells you exactly what to do and why it matters for your insurer or contract.
SME-friendly
04
Evidence
Machine-verifiable assurance pack for your insurer, Cyber Essentials assessor, NHS contract, or client due diligence. One run, multiple uses.
One run, multiple uses

See vRecover in action.
Simulated SME walkthrough.

Walk through the four steps using a simulated law firm. This is what your team or clients would experience during a real assessment.

app.vrecover.co.uk — Hartfield Legal LLP
⊞
Microsoft 365
Admin, MFA, user accounts
✓
◫
Backup service
Veeam, Acronis, Cove
✓
△
Google Workspace
Drive, admin, shared files
✓
◇
Azure / AWS
Cloud storage and vaults
✓
🔒 Read-only OAuth tokens only. vRecover never stores credentials or modifies anything on your systems.
Connecting to Microsoft 365...
Reading admin roles and MFA policies...
42
Recovery health score
42 / 100
Needs attention
6 checks run
3 critical failures
1 warning
2 passed
Critical
Run and document a full backup restore test. Generate a restore evidence log showing date, duration, and data integrity confirmation. Required by Hiscox, CFC, and Aviva for SME renewal.
Critical
Enable MFA on all 3 remaining admin accounts in Microsoft 365. Admin Centre → Users → Active users → enforce MFA policy. Estimated time: 20 minutes.
Medium
Document your recovery time objective (RTO) and recovery point objective (RPO). A one-page statement is sufficient for most insurance contracts and NHS supply chain requirements.
Advisory
Create separate admin-only accounts for 2 users currently using daily mailboxes as admin access. Reduces ransomware blast radius and meets NCSC Cyber Essentials requirements.
vRecover Assurance Pack
Generated: 11 June 2026  |  Ref: VR-2026-0611-A4F2
Score: 42/100
OrganisationHartfield Legal LLP
Systems verifiedMicrosoft 365, Veeam Backup
Checks passed2 / 6
Critical failures3 items — MFA, restore test, RTO
NCSC alignmentCyber Essentials partial
Last restore testNot found (over 90 days)
MFA coverage75% — 9 of 12 accounts
Offsite backupConfirmed — geo-replicated
Verification methodRead-only API, no agent installed
Next recommended scan11 July 2026
Cyber insurance renewal Cyber Essentials prep NHS / council contract Client due diligence Supply chain audit

Built for three types
of organisation.

⚖
SMEs in regulated sectors
Legal firms, accountancy practices, private healthcare, and engineering consultancies who need recovery evidence for insurers and contracts.
  • Proof for cyber insurance renewal
  • Evidence for NHS and council contracts
  • Cyber Essentials readiness
  • Client due diligence pack
⬡
Managed Service Providers
MSPs who manage UK SMEs and need an automated way to prove recovery compliance to their clients' insurers — and a product they can resell.
  • Add recovery assurance to your stack
  • White-label evidence packs for clients
  • Revenue share model available
  • No extra agents to deploy
◈
Insurers and brokers
Cyber insurers and brokers moving from self-attested forms to machine-verifiable third-party evidence at underwriting and renewal.
  • Replace self-attestation forms
  • Standardised technical evidence format
  • Potential premium discount qualifier
  • Continuous rather than annual checks

Nobody does SME-focused,
continuous recovery verification
.

Criteria Backup tools
Acronis, Veeam
Compliance platforms
CyberSmart, ISMS.online
Enterprise GRC
Vanta, Drata
Manual auditor
CE assessors
vRecover
Recovery testing ✗ ✗ Highly complex ✗ Automated, SME-ready
Verifiable evidence ✗ Self-attested ✗ Manual screenshot Assurance packs
Continuous verification ✗ ✗ ✗ Annual only Continuous
SME-friendly ✗ Partial Enterprise-heavy High friction Built for SMEs
Read-only integration ✗ Yes ✗ Disruptive audits Read-only API
Cost accessible ✗ Yes High cost High per visit ~£2k/yr SaaS

A £200M serviceable
opportunity.

TAM
AI and knowledge-based UK SMEs
1.56M  |  £3.1B
SAM
Regulated SMEs using M365 or Google
250k  |  £500M
SOM
Insurance and CE renewal cycle
100k  |  £200M
Target
0.5% of SOM — Year 3
500 SMEs  |  £1M ARR

Pricing: approximately £2,000 per year per SME. Route to market: direct, MSP channel, and insurer partnerships.

Year Customers ARR
Year 150£100k
Year 2200£400k
Year 3500£1M
Why now
NCSC directs SMEs to MSPs — the channel exists but no recovery-verification product is on it. Insurers are shifting from self-attestation to evidence-based underwriting. Cyber Essentials and cyber insurance are now required for NHS, council, and legal contracts.

Researchers and developers with
20+ years of combined experience.

Prof. Atiq
Prof. Dr. Atiq Ahad
Principal Investigator
Cybersecurity, IoT, AI
Mamun
Md Mamun
Research Assistant
Compliance, cyber policy
Tasnim
T. Ferdous
Research Assistant
SaaS, system architecture
Morsheda
M. Aktari
Research Assistant
Cloud, data engineering
University of East London
CyberASAP, Innovate UK
Phase 1B Market Validation

Help us validate
vRecover.

We are at market validation stage and need to hear from real organisations. Your feedback will directly shape what we build. It takes under 5 minutes.

SME owner or manager
Tell us whether recovery evidence is something your insurer or clients already ask for, and what you currently do about it.
Take the Survey →
MSP or IT service provider
Tell us whether recovery assurance is a gap in your current service stack and whether you could see yourself reselling vRecover.
Take the Survey →
Insurance broker or underwriter
Tell us whether you are moving toward evidence-based underwriting and what format of recovery proof you would actually accept.
Take the Survey →

University of East London  ·  CyberASAP, Innovate UK  ·  Phase 1B market validation 2026