MVDE Architecture Reference
Minimum Viable Digital Enterprise

Stay operational.
Not just recoverable.

Traditional business continuity asks what you can restore after an attack. The MVDE reframes the question: which digital assets must remain unaffected during one. Four vendors. One architecture. Zero tolerance for 24-day recoveries.

80–90%
of digital business stays operational during breach
24d
avg ransomware recovery under traditional MVE
60–90%
reduction in attack propagation via microsegmentation

The shift

From recovery to resilience

MVDE evolves three established frameworks into a single architectural posture.

Origin
Minimum Viable Company
KPMG / PwC business continuity planning. Defines the smallest organisation that can serve customers. Recovery-focused: how do we come back?
Evolution
Minimum Viable Enterprise
Veeam / Rubrik data resilience framing. Which systems must be restored first? Accepts disruption; optimises recovery time and data loss.
Current state
Minimum Viable Digital Enterprise
ColorTokens / Zero Trust architecture. Which systems must never go down? Prevention and containment — disruption becomes a local event, not a company crisis.
Architecture layers

The four-vendor stack

Click each layer to explore what it does, how it integrates, and what signals it passes to the layer below.

Layer 1 — Access control
Zscaler Zero Trust SASE
North-south perimeter · who reaches the MVDE boundary
ZIA ZPA SD-WAN DSPM
What it does
  • Controls all user, device, and branch access to applications before traffic enters the internal estate
  • Enforces identity-aware, least-privilege access — no implicit network trust
  • DSPM surfaces sensitive data exposure across cloud and SaaS, informing which workloads belong inside MVDE scope
MVDE role
  • Defines who can reach MVDE assets — the first gate before microsegmentation applies
  • Passes user context and device posture signals down to ColorTokens to enrich segmentation policy
  • DSPM output identifies which data workloads are crown jewels — feeds MVDE scope definition
Key integration signal
Passes user identity, device health, and data sensitivity classification to ColorTokens Xshield. Xshield uses this context to apply differentiated microsegmentation policy — a compromised device in ZPA can trigger automatic quarantine before lateral movement begins.
user context · device posture · data sensitivity
MVDE operational boundary
Layer 2 — Enforcement fabric
ColorTokens Xshield
East-west microsegmentation · blast radius containment · MVDE definition
Policy engine Agent + agentless OT/IoT MAMI KPIs
What it does
  • Divides the digital estate into microsegments — workload-level isolation prevents lateral movement between zones
  • The policy engine is where the MVDE scope is operationalised: which workloads are in-scope, what communication is permitted
  • AI agent automates policy creation and responds to quarantine triggers at machine speed
MVDE role
  • Central orchestrator of the MVDE architecture — owns the blast radius calculation
  • Keeps 80–90% of digital business unaffected by containing breaches to their originating microsegment
  • Produces the MVDE and MAMI metrics consumed at board level via DORA / SEC reporting
Key integration signals
Receives device context from Zscaler. Sends quarantine events and workload map to Rubrik and Veeam — triggering clean recovery of the affected microsegment while the rest of the MVDE stays live. Ingests EDR telemetry from CrowdStrike / SentinelOne to automate containment.
anomaly signals · quarantine triggers · workload scope
Layer 3 — Detection & response
EDR / SIEM / SOAR
Threat detection telemetry feeding Xshield containment
CrowdStrike SentinelOne Splunk / Sentinel Xshield AI
What it does
  • EDR agents (CrowdStrike, SentinelOne) provide real-time endpoint telemetry to Xshield without requiring additional agent installation
  • Anomalous behaviour triggers automated microsegment quarantine — containing the threat before human response
  • Zscaler DSPM contributes data-layer anomaly detection to this signal set
MVDE role
  • The feedback loop that makes containment automatic rather than manual
  • Defines the "time to quarantine" metric — the speed at which a breach is confined to its microsegment
  • Reduces the 15–20% affected zone that requires BCM / recovery activation
Key integration signal
Detection events trigger Xshield policy enforcement updates in near-real-time. The same event is passed to Rubrik and Veeam as a recovery signal — identifying which workloads may need clean-room validation and in what priority order.
clean restore targets · MVC priority order · RTO targets
Layer 4a — Cyber recovery
Rubrik Security Cloud
Crown jewel data · DSPM · clean recovery
What it does
  • Zero Trust data protection: immutable backups, clean-room validation against malware before restore
  • MVC profiles define critical personnel and data workloads that must recover first
  • DSPM integrated into recovery — identifies whether sensitive data in the affected microsegment was exfiltrated
  • Turbo Threat Hunting scans 75,000 backups in 60 seconds to identify clean restore point
MVDE role
  • Manages recovery of the 15–20% affected zone after ColorTokens has contained the breach
  • Provides the data-security posture view that determines whether the MVDE scope definition needs updating post-incident
  • Best fit: regulated industries, cloud-first, crown jewel data workloads
Layer 4b — Operational recovery
Veeam Data Platform
MVB-ordered restore · hybrid/legacy · DORA
What it does
  • Defines and enforces MVB restore priority — which systems come back first based on business criticality
  • Strongest breadth across hybrid environments: VMware, physical, legacy OT, SaaS, cloud
  • Instant recovery from backup reduces RTO significantly; immutable repositories prevent backup encryption
  • DORA-aligned reporting: RTO/RPO documentation, ICT third-party risk registers
MVDE role
  • Handles bulk operational recovery for the affected 15–20% — particularly strong for legacy and hybrid estates
  • Provides the regulatory evidence trail required by DORA, NIS2, and SEC disclosures
  • Best fit: complex hybrid estates, organisations with significant legacy OT, DORA-regulated entities

Live threat scenario

AI-powered ransomware: how the stack responds

An autonomous AI attack breaches a perimeter device and attempts lateral movement. Watch how each layer responds.

⚡ Incident timeline
CyberStrikeAI-class attack — autonomous lateral movement campaign
An AI agent gains initial access via a compromised contractor credential. It begins mapping the internal estate to locate crown jewel workloads.
T+0 · Zscaler
Contractor credential authenticated. ZPA grants access to permitted applications only — no network visibility. Posture score flagged as degraded device.
T+2min · Xshield
Anomalous east-west probe detected. AI agent attempts to reach workloads outside permitted communication paths. Xshield blocks and logs. Posture context from ZPA escalates priority.
T+3min · EDR
CrowdStrike detects malicious process behaviour on the compromised endpoint. Telemetry ingested by Xshield AI agent. Automatic quarantine of the originating microsegment initiated.
T+5min · Rubrik
Quarantine event received. Rubrik initiates Turbo Threat Hunt on the affected workload's backup chain. Clean restore point identified. Crown jewel data confirmed unexfiltrated via DSPM scan.
T+8min · Veeam
MVB restore plan activated for affected microsegment. 82% of the digital estate remains fully operational throughout. Board notified: MAMI tolerance not breached. DORA incident log initiated.

Board-level metrics

What the MVDE architecture measures

Four metrics give leadership a clear, auditable picture of cyber resilience posture.

% MVDE unaffected
85%
Proportion of the digital estate that remains operational during an active breach. Target: maintain above 80% under worst-case scenarios.
MAMI — max acceptable material impact
£Xm
Board-defined financial tolerance for cyber disruption. Expressed in currency. Feeds directly into cyber insurance and SEC/DORA disclosure calculations.
Time to quarantine
<5m
Speed from anomaly detection to microsegment isolation. The primary operational metric for measuring containment effectiveness against AI-speed attacks.
RTO vs MVB target
hrs
Recovery Time Objective measured against the pre-defined MVB priority order. Validates that the recovery stack delivers against board-approved continuity commitments.

Integration landscape

What's native, what's architectural, what needs work

Honest assessment of where integrations exist today versus where process design is required.

Vendor pair Integration type What flows between them Status
Zscaler
ColorTokens
Architectural (ZTNA + microseg) User identity, device posture, application access context from ZPA into Xshield segmentation policy Architectural
ColorTokens
CrowdStrike / S1
Native API integration EDR telemetry into Xshield; microsegmentation enforcement via existing Falcon/S1 agent — no additional agent required Native
ColorTokens
Rubrik
Process integration (gap) MVDE workload scope → MVC profile alignment; quarantine event → clean restore trigger. No published native integration as of mid-2026. Process design needed
ColorTokens
Veeam
Process integration (gap) MVDE priority order → MVB restore sequence; affected microsegment signal → recovery activation. No published native integration as of mid-2026. Process design needed
Rubrik
Veeam
Complementary (co-exist) Rubrik for crown jewel / cloud / DSPM; Veeam for hybrid / legacy / OT breadth and DORA documentation. Different workload tiers, not competing. Complementary
Zscaler DSPM
Rubrik DSPM
Overlap / rationalise Both carry DSPM capability. Zscaler focuses on data-in-motion / cloud access; Rubrik on backup data and recovery posture. Recommend rationalising scope to avoid duplication. Rationalise scope

Regulatory alignment

Why regulators care about MVDE

Four major frameworks now require the MVDE architecture's outputs, even if they don't use the term.

DORA (EU)
Mandates ICT resilience for EU financial entities. Requires real-time evidence of operational resilience, automated reporting, and defensible data lineage. Enforcement active 2026. Fines up to 10% of annual turnover.
NIS2 (EU)
Expanded network and information security directive covering essential services across sectors. Requires proactive risk management, incident reporting within 24–72 hours, and supply chain security.
SEC Cyber Rule (US)
Requires US public companies to disclose material cyber incidents within 4 business days and report annually on cybersecurity governance. Drives demand for MAMI calculations and board-level MVDE metrics.
ISO 22301 / NIST CSF
ISO 22301 (BCMS) and NIST CSF 2.0 provide the standards foundations for MVDE methodology: Business Impact Analysis, Minimum Business Continuity Objective (MBCO), and recovery time objectives.