Summary
- Registry continuity must protect integrity and authority as well as availability. A restored service can be fast, internally consistent and dangerously wrong if an intruder altered records, transaction history, credentials or recovery copies before discovery.
- Backups prove that bytes survived; they do not prove which version reflects legitimate resource control. Recovery needs independently witnessed change history, protected time and sequence evidence, external copies, reproducible reconciliation and an explicit last-known-good decision.
- The most useful cyber exercise begins with a plausible, quiet integrity attack: privileged access is stolen, selected holder contacts and transfer evidence are changed, ordinary replication carries the changes outward, and the attacker attempts to make the false state look old and authorized.
- Signed journals and tamper-resistant storage improve detection, but neither should become an unquestioned source of truth. Signing keys can be abused, custodians can collude, clocks can drift and a perfectly preserved malicious transaction remains malicious.
- An alternate operator must be able to restore public registration, reverse DNS, routing registry and carefully bounded RPKI services from independently held material while preserving disputes, rejecting stale credentials and avoiding contradictory authority.
- NRS can strengthen debate about the present RIR model by researching common dependencies, publishing evidence-led comparisons and advocating separation among ordinary service operators, continuity custodians, independent witnesses and incident decision-makers. The responsible RIRs and authorized continuity bodies must implement and test that separation.
- Public assurance should report exercise scope, detection and reconciliation times, disputed-record counts, external-copy health, migration outcomes and residual uncertainty. Vague claims about backups, resilience or security certification are not enough.
- By the end of 2027, every critical registry should have completed an integrity-led migration exercise in which the primary environment and its latest backup are treated as suspect. Passing means proving why the recovered state deserves reliance.
Availability is the easier half of continuity
A registry can be online and still fail in its central purpose. Public queries may return quickly, staff may log in successfully and resource holders may receive confirmation messages, yet the underlying account of authority may have been altered. For an Internet number registry, the damaging event is not limited to downtime. It can be a plausible false statement about who controls an address block, which organization may update it, which contacts are trusted, or which cryptographic actions follow from that state.
Conventional continuity language often begins with recovery time and recovery point objectives. Those measures are useful. They ask how long an important service can remain unavailable and how much recent data may be lost. They do not by themselves answer whether the chosen recovery point predates a compromise, whether the transaction order is authentic, or whether credentials used after restoration still belong to legitimate officers. A quick restoration from poisoned state can accelerate harm.
NIST's Cybersecurity Framework 2.0 makes the missing requirement explicit in its recovery outcomes: the integrity of backups and other restoration assets should be verified before use. NIST's work on recovering from ransomware and other destructive events is even more direct about restoring data that can be trusted as accurate. CISA similarly advises offline, encrypted backups and regular testing of both availability and integrity. These are cross-sector principles, but they fit registry authority unusually well.
Number registry data has a long institutional life. Allocations, assignments, transfers, mergers, contact changes, disputes and legacy records can span decades. A corrupt transaction may remain consequential long after the server that accepted it is replaced. Recovery therefore needs historical reasoning, not just technical restoration. Investigators must determine which changes were legitimate, which were attacker actions, which later changes depended on them and which public outputs carried the resulting claim.
This is where governance and incident response meet. Engineers can identify altered tables, unusual administrative sessions and inconsistent replicas. They cannot alone decide a contested holder identity or infer lawful authority from possession of an old password. Lawyers and board members can interpret governing instruments, but they cannot establish whether a log was rewritten or a backup synchronized after intrusion. A credible recovery body needs both forms of competence and a bounded way to make urgent decisions.
The immediate lesson is skeptical rather than alarmist. Existing RIRs have invested in resilient systems, security controls, audits and continuity planning. RIPE NCC, for example, has publicly described work on a registry business continuity plan, registry-data escrow, ISO 27001 alignment and security assurance. Those are meaningful commitments. They should be tested against an integrity scenario precisely because the institutions matter, not dismissed because no public evidence proves an imminent compromise.
A lawsuit and a cyber intrusion produce different evidence problems
An institutional dispute is visible by comparison. Court filings, board decisions, recognition notices, member communications and public service conditions provide competing records of what happened. Even when authority is contested, observers usually know that a contest exists. Continuity planning can identify triggers, preserve essential functions, appoint temporary decision-makers and maintain an evidentiary boundary while the dispute proceeds.
A capable intruder tries to prevent that visibility. The objective may be selective rather than catastrophic: change a holder contact, insert an apparently historical approval, alter a transfer condition, suppress an audit event, replace a recovery credential or create a route-security action that appears to come from an authorized account. The system may continue to operate normally. Staff may unknowingly approve later transactions that build on the false premise.
This difference makes the latest copy especially dangerous. In an ordinary equipment failure, the newest complete replica is usually preferred because it minimizes lost work. In an integrity incident, every copy created after the earliest possible intrusion may repeat the attacker's state. Synchronous replication can distribute corruption efficiently. Daily backups can preserve many identical versions of the same false record. High availability can increase the number of contaminated locations.
The decision to roll back is also harder. Returning to an older snapshot may remove the malicious change, but it may also discard legitimate allocations, contact updates, transfers and security actions completed in the same period. Replaying all later transactions can reintroduce the attack. Replaying none can harm innocent holders. The recovery task is selective reconstruction with explainable authority, not a simple choice between two database images.
Public outputs complicate reconstruction. RDAP and WHOIS responses, reverse-DNS delegations, routing registry entities, transfer records, member portals and RPKI products may update on different schedules. Caches and third-party archives may preserve observations that the primary institution no longer has. Some outputs carry stronger cryptographic protection than others. A recovered internal record must be compared with what outside users actually saw, because the external effect can reveal both timing and scope.
Legal continuity plans remain necessary. A cyber event can lead to injunctions, disclosure duties, contractual claims or criminal investigation. But a plan designed mainly for corporate incapacity will not answer how to identify a forged approval in an otherwise valid administration. The next generation of continuity rules must treat compromise of institutional knowledge as a first-class event alongside compromise of institutional control.
The most revealing scenario is quiet, selective corruption
A useful exercise should not begin with every screen encrypted and every service visibly unavailable. That scenario tests isolation, communication and restoration under obvious pressure. It does not test whether the registry can recognize a false state that still looks operational. A better institutional stress test begins with a narrow compromise that remains undiscovered long enough to enter ordinary records and copies.
Assume an attacker obtains an administrator's session and enough contextual information to imitate normal conduct. The attacker selects a small number of resource holders whose corporate structures have recently changed. One protected recovery contact is replaced. A supporting document reference is altered. A transaction timestamp is moved into an earlier maintenance period. One transfer restriction is removed. None of these changes causes a global outage or an implausibly large movement.
The attacker then waits. Legitimate staff process unrelated requests. Replication and backup continue. Public directory responses gradually reflect selected changes. Automated notices are redirected to the substituted contact. If a second account is compromised, the attacker uses it to approve one action started by the first, producing superficial separation of duties. The objective is not merely to steal resources; it is to manufacture an apparently normal institutional history.
Discovery may come from outside. A holder notices an unexpected contact, an operator questions a route authorization, an independent archive shows a changed response, or security monitoring identifies a privileged session from an unusual device. At that point, the registry cannot assume that the reported record is the only affected record. It must establish the earliest possible access, every privilege exercised, the systems reached, the copies created and the later transactions that depended on changed data.
The exercise should deny responders one convenient answer: the primary environment and its most recent backup are both suspect. A continuity custodian holds older independent exports and change commitments. External witnesses hold signed checkpoints or authenticated summaries. Public observers retain dated responses. The team must use these materials to identify a defensible state without treating any single copy as conclusive.
Success has several dimensions. Detection succeeds if the anomaly reaches a competent response team. Containment succeeds if affected authority and credentials are bounded without freezing unrelated holders. Reconstruction succeeds if every disputed change has a reasoned disposition and downstream effects are traced. Restoration succeeds if public and dependent services converge on the accepted state. Governance succeeds if urgent decisions are reviewable and residual uncertainty is disclosed.
Backups are evidence, not truth
The phrase "we have backups" compresses several different claims. A backup may be complete, readable, malware-free, recent, isolated from ordinary credentials and restorable within a stated time. Each property matters. None proves that the represented transactions were authorized. A database can be faithfully copied after an attacker used valid credentials. Its checksum can be correct while its institutional meaning is false.
Continuity design should therefore describe backup lineage. For every protected copy, the custodian should know what system produced it, what time range it covers, which account authorized transfer, which cryptographic digest was recorded, what software created it, whether the copy was immutable, and whether restoration has been tested. The record should be held separately enough that compromise of the registry's ordinary administration cannot rewrite the lineage.
Isolation needs more than a different cloud region. If production administrators can delete snapshots, rewrite retention rules or obtain the backup decryption key through the same identity system, geography does not create independence. A useful external copy has separate authorization, protected credentials, retention beyond ordinary operational mistakes and a release rule designed for institutional emergency. The custodian should not also be the sole party that decides when its own copy is trustworthy.
Frequency creates a trade-off. Frequent copies reduce the amount of legitimate work that may need reconstruction, but they also create many contaminated versions after compromise. Long retention improves the chance of reaching a clean point, while increasing cost and the amount of sensitive historical material held. RIRs and lawfully appointed custodians should set retention by transaction risk and investigation need, not by storage convenience alone. NRS can compare their published approaches and advocate stronger safeguards, but it does not set or administer retention.
Restoration exercises should include application behavior, not merely database loading. Can the restored registry generate coherent public directory output, preserve reverse-DNS delegation, enforce disputed-resource restrictions and authenticate current holder officers? Can incident responders query prior versions and transaction relationships without changing them? Can the alternate environment produce a clear difference report against external observations? A backup that loads but cannot support these questions is an incomplete continuity asset.
The same skepticism applies to escrow. Periodic registry deposits and pre-arranged custodians can be highly valuable, as the domain-name registry context demonstrates. ICANN's Emergency Back-End Registry Operator arrangements use data escrow, cached zone material, measured service targets and bounded critical functions to support temporary continuity. Yet escrow does not decide which deposit predates an intrusion or whether the submitting registry had already accepted a forged transaction. Release is the beginning of reconciliation, not the end.
Signed history should make silent rewriting harder
A number registry should maintain an append-evident history of consequential actions. Each event should commit to the prior accepted state or prior event, the affected resource scope, the authenticated actor, the authorization basis, the time evidence and the resulting state. Periodic signed checkpoints should bind a larger interval. Independent witnesses should receive those checkpoints often enough that the institution cannot later replace an entire contested period without detection.
This does not require publishing private member documents or detailed security logs. A public or member-visible commitment can prove that a particular sequence existed without revealing the underlying evidence. Protected reviewers can later compare disclosed records against the commitment. Privacy and integrity are not opposites; careful commitments can preserve the ability to detect rewriting while keeping sensitive content under lawful access controls.
The signing arrangement must be separated from ordinary application administration. If the same compromised account can alter a holder record and direct the history-signing service to endorse an invented sequence, signatures add ceremony without independence. High-impact checkpoints should use keys held in a distinct security boundary, threshold approval or an external witness. Routine events can still be efficient, but privilege escalation into the evidentiary layer should be difficult and visible.
Time also needs independent support. An attacker who can alter clocks or insert old-looking records may make transaction order ambiguous. Checkpoints should incorporate protected monotonic sequence numbers and time evidence from more than one source. External receipt times provide another constraint. Perfect global time is unnecessary; responders need enough independent ordering to show that a claimed event could not have existed before a particular witnessed state.
Signed history has limits. A legitimate signing service can attest to a maliciously authorized transaction. Two corrupt insiders can satisfy a two-person rule. A compromised key can endorse a false checkpoint. A valid signature proves connection to a key, not moral or legal correctness. The design must combine cryptographic evidence with holder notice, organizational authority checks, outside observation and retrospective review.
Nor should immutable history block correction. A false record may need to be reversed, personal data may require protected handling, and a court may lawfully direct a change. The correct pattern is an append-only correction that preserves evidence of the prior state and identifies the authority for change, with access boundaries appropriate to the material. Quiet deletion is the enemy; accountable correction is part of governance.
Independent copies need independent judgment
External custody is useful only when it reduces common failure. Three copies administered through one identity provider, one cloud control plane and one security team are not three independent witnesses. A continuity design should map infrastructure, credentials, staff, software and legal control. Independence is purpose-specific: a storage custodian may be technically separate yet rely on the same officers to validate a disputed release.
At least one protected copy of critical registry state should be held outside the ordinary provider's administrative domain. At least one history witness should receive checkpoints through a channel that production administrators cannot silently suppress or rewrite. At least one incident-review group should be capable of comparing those materials without being subordinate to the executive whose controls failed. These separations create friction, which is the point.
Resource holders should contribute evidence too. High-impact changes can produce notices through multiple pre-established channels, including a protected contact not used for ordinary login. A holder can retain receipts that identify resource scope, transaction order and accepted result. During recovery, those receipts are not automatically decisive, because a holder account may be compromised, but they provide an outside copy of what the institution represented.
Public observations can support reconstruction. Dated RDAP or WHOIS responses, routing registry snapshots, reverse-DNS state and RPKI repository observations may show when a change became externally visible. Their evidentiary weight varies. A search-engine cache is not equivalent to an authenticated registry receipt. The recovery team should rank sources by integrity, collection method, completeness and independence rather than blending every observation into one undifferentiated archive.
Independent judgment means accepting disagreement. One custodian may hold a checkpoint that another missed. A holder receipt may conflict with an internal approval. A public response may reflect a cache rather than current state. The reconciliation method should preserve these differences, state why one interpretation is preferred and mark unresolved records for bounded protection. Forced agreement can destroy exactly the evidence needed to understand compromise.
NRS can make the policy case practical by publishing a evidence-led comparison of continuity custodians against common export, retention, confidentiality and exercise criteria. It should not qualify, accredit or guarantee custodians. Any formal appointment or qualification belongs to the responsible RIR, a lawfully designated authority or an independent process with a defined mandate. NRS can press those bodies to disclose whether a custodian has demonstrated separation, restoration, disclosure controls and cooperation with independent review, so members can see material concentration and advocate additional protection for critical resources.
Recovery requires a declared last-known-good boundary
Every integrity incident eventually confronts a difficult decision: from what point can the institution trust its own history? The answer may differ by system and resource set. A compromised administrator may have reached the membership portal but not the RPKI offline CA. A malicious release may affect public directory output while the underlying allocation ledger remains intact. A stolen signing key may compromise one certificate branch without altering the holder record.
The response team should declare a last-known-good boundary with reasons, scope and confidence. It should identify the earliest possible compromise, the strongest uncompromised checkpoint, the systems covered and the remaining uncertainty. That boundary is provisional and reviewable. New evidence may move it earlier or permit a narrower affected set. Treating it as a reasoned decision is more honest than presenting one restoration timestamp as objective fact.
Transactions after the boundary should be classified. Some can be replayed automatically because their authorization is independently confirmed and they do not depend on disputed state. Some need holder reconfirmation through protected contacts. Some require documentary or legal review. Some must remain suspended because competing claims cannot be resolved safely. The objective is to restore legitimate change while preventing the attack from riding back into the clean environment.
Dependency tracing is essential. If a false contact approved a transfer, and the new account later changed reverse DNS and created a route authorization, reversing only the contact leaves the consequential actions intact. The registry should be able to identify descendant actions and external services affected by each disputed event. This capability should be designed before the incident rather than assembled from ad hoc queries under pressure.
Authority to approve reconstruction must be bounded. Incident responders can recommend technical findings. A designated continuity decision group can accept uncontested replay, impose temporary protection and refer ownership disputes. It should not use emergency status to redistribute resources or settle unrelated claims. Every exceptional decision should expire, receive independent review and preserve affected holders' right to challenge it.
The clean environment must also begin with clean authority. Restoring data while reusing compromised identity accounts, API secrets, signing credentials or administrator devices defeats the exercise. Recovery should establish new privileged credentials, verify current officers, rotate dependent secrets, rebuild monitoring and control access to old evidence. The old environment remains isolated for investigation and should not quietly become production again because it is familiar.
Public directory services can reveal divergence before the ledger does
RDAP and WHOIS are often treated as publication surfaces downstream of the authoritative registry. During an integrity incident, they can become both affected services and external evidence. A changed holder name, role contact, status or remarks field may be the first visible sign of unauthorized state. Queries from multiple locations and retained responses can establish when divergence appeared.
Continuity testing should compare responses across authoritative endpoints, caches and alternate publication services. The test should include an apparently valid but unauthorized contact change, a legitimate change processed during the same interval and a resource under pre-existing dispute. The alternate operator must reproduce the accepted state without flattening these distinctions or exposing protected evidence.
Public availability is not the only criterion. Two responsive RDAP endpoints that identify different controlling organizations can create more harm than one declared outage. The continuity leader should decide which endpoint carries authority, how stale services are marked or withdrawn, and how caches receive correction. Temporary uncertainty should be communicated clearly rather than hidden behind a normal status page.
Registration data also drives operational trust outside formal protocols. Network operators, abuse teams, counterparties and investigators use public contacts to reach responsible organizations. A selective integrity attack can redirect reports, delay incident containment or create a false appearance of abandonment. Recovery priorities should consider these effects instead of measuring only the registry's own transaction service.
The continuity model advocated by the Number Resource Society can reduce dependence on one publication operator, but it can also create contradictory answers if authority is not ordered. The responsible RIR or a lawfully appointed substitute must maintain one coherent accepted state and a signed sequence for provider updates. Authorized providers should be replaceable, yet they should not independently invent current truth. NRS can document divergence and represent affected members under valid powers of attorney; it must not maintain the accepted state. Portability is service choice within a common authority discipline, not competing ledgers.
External monitoring should alert on semantically important differences, not every harmless formatting change. Holder identity, resource scope, status, authoritative contacts, transfer restrictions and delegation state deserve higher priority. Monitors should distinguish expected propagation from unexplained divergence and preserve enough evidence for later comparison. Their alerts should reach both the registry and protected holder contacts where appropriate.
Reverse DNS and routing records widen the blast radius
An Internet number registry is not only a membership database. Its accepted state can affect reverse-DNS delegations, routing registry information, transfer handling and route-security certification. These services have different architectures and refresh behavior. A cyber continuity plan that restores the main account table while ignoring dependent authority may leave the Internet-facing consequences of the attack active.
Reverse-DNS changes can redirect names associated with address space or interrupt operational resolution. The recovery team needs a versioned account of delegation changes, parent-side actions and holder authorization. During uncertainty, preserving a previously stable delegation may be safer than accepting a new request, but the decision should depend on evidence and impact. A blanket freeze can harm legitimate operators who need urgent correction.
Routing registry entities can be created through several institutional paths and are used with varying levels of reliance. Recovery should identify which entities were derived from compromised registry authority, which were maintained elsewhere and which public mirrors still carry stale state. An alternate operator should not claim to correct every external routing database. It should publish authoritative corrections, notify relevant operators and track observable convergence.
RPKI raises stricter questions because signed products and certificate hierarchy carry cryptographic consequences. If ordinary registry records were altered but CA keys remained secure, responders still need to determine whether false state caused authorized signing. If a hosted signing service or CA administration was reached, the incident may require certificate rollover, entity review, revocation and relying-party observation. Database restoration alone cannot withdraw a published signed product.
The separation of RPKI functions can help. Offline or separately administered CA keys, independent repository monitoring and holder-visible route authorizations create evidence outside the compromised registry application. They do not make the system immune. A parent CA can still revoke, delay or reissue, and a compromised hosted service may sign under valid authority. Continuity planning must map actual control rather than assume that cryptography automatically proves legitimacy.
RIRs and lawfully authorized continuity operators should classify dependent services by restoration risk. Public directory publication may resume from a carefully reconciled snapshot. High-impact certificate action may require stronger approval and key review. Reverse-DNS changes may proceed for uncontested holders but pause for affected resources. NRS can publish a research framework for comparing those plans and advocate transparent safeguards, but it does not decide which service resumes. The plan should preserve service where safe while refusing to let pressure for a green status indicator override uncertainty about authority.
Incident responders must be prepared to question the institution
Many incident-response retainers are designed around malware containment, endpoint evidence, credential theft and infrastructure restoration. Registry incidents add a constitutional question: the customer commissioning the response may itself be unable to state which actors or records deserve trust. Responders need a mandate to preserve evidence and report findings beyond the compromised management chain under defined conditions.
That mandate should be agreed in advance. A serious integrity event can authorize direct reporting to an independent board committee, continuity trustee or review panel. The trigger should be specific enough to prevent routine bypass of management, yet broad enough to cover suspected executive credential compromise or suppression of findings. Responders should know which outside custodians they may contact and how protected material can be obtained.
Specialist skills matter. The team needs digital forensics, database history analysis, identity and access expertise, RPKI knowledge, public-service observation and an understanding of registry authority. No single contractor is likely to hold all of them. Exercises should establish how these roles share evidence, avoid contaminating systems and reach decisions without one discipline dominating questions it cannot answer.
Resource holders need representation. An investigation conducted entirely by the institution may overlook external receipts, corporate changes or operational consequences. A protected holder liaison can obtain confirmations and explain temporary restrictions. It should not disclose investigative detail indiscriminately or allow a loud claimant to outrank evidence. Fair participation improves accuracy without turning the incident room into a membership meeting.
Public authorities may have lawful roles, particularly where criminal access, personal data, critical infrastructure or court orders are involved. Their involvement should not transfer routine number-resource policy to a national security body. The registry should preserve applicable reporting and evidence duties while maintaining global operational neutrality. Emergency cooperation must be scoped to the incident, transparent at an appropriate level and reviewable.
The institution should also plan for the possibility that the first forensic conclusion is wrong. Early indicators can misattribute a change to attack when a rare administrative exception explains it, or can miss insider participation. Decisions should record confidence and reversible measures. Protecting a contested resource temporarily is often preferable to making a permanent transfer based on incomplete technical evidence.
Migration exercises must assume the primary operator is evidentially suspect
Most disaster recovery tests ask whether a secondary environment can be started after the primary environment fails. The more demanding test asks whether another lawfully authorized operator can assume bounded service when the primary institution's latest records, credentials and explanations cannot be trusted. NRS should advocate that test and publish evidence about whether the RIR system completes it before 2027 ends; the RIRs and their authorized continuity operators must run it.
The exercise should use synthetic records that reproduce real complexity without touching live holder authority. It should include allocations and assignments, legacy evidence, organizational mergers, delegated contacts, reverse DNS, public directory output, routing registry entries, hosted and delegated RPKI relationships, pending transfers and pre-existing disputes. Some changes are legitimate, some malicious and some ambiguous.
The primary team should not reveal the answer key to the receiving operator. External custodians provide protected exports, checkpoints and holder receipts through the agreed release process. Public monitors provide observed state. Incident responders provide a bounded compromise window. The receiving operator must establish a last-known-good boundary, classify later events, build a clean environment and publish a reasoned reconciliation report.
The test should measure more than elapsed time. It should count corrupted events detected, legitimate events preserved, disputed events protected, descendant actions traced, credentials rejected, public divergences resolved and dependent services restored. It should record how often responders relied on one common system that the scenario assumed compromised. Unexplained correct answers should not count as success if they came from privileged knowledge unavailable in a real event.
Migration should include rollback. If the alternate operator's reconstruction proves wrong or its environment fails, authority must return or move again without reactivating compromised credentials. The test should show who can order that action, how public services identify the current operator and how evidence remains intact. A substitute that cannot itself be replaced creates a new concentration at the worst possible moment.
Independent observers should publish a useful summary. Sensitive attack detail, personal evidence and exact defensive architecture can remain restricted. The public report should identify the scenario class, systems included, assumptions, completion times, major failures, remediation owners and residual risks. Members need evidence that continuity is practiced; attackers do not need a catalogue of every control.
NRS should advocate separation between service choice and continuity authority
The Number Resource Society can contribute as an advocacy and member-representation body, not as an additional registry provider. Its strongest proposal would call for ordinary registry service to be portable while continuity evidence and emergency decisions remain outside any one provider's unilateral control. NRS can research the design, convene affected operators, publish comparisons and present member concerns. It cannot operate the registry, hold accepted state or exercise emergency authority.
Under that proposal, RIRs or other lawfully authorized registry operators maintain holder relationships and process authorized changes. Independently appointed custodians can receive protected exports and history commitments. External monitors can observe public state. A continuity council created under a valid legal and governance mandate can authorize bounded release and substitute service. Independent reviewers decide contested rights, while incident responders investigate without becoming the final tribunal. NRS may support or represent a member in those processes only under valid authority from that member.
These roles should not always be held by different legal entities at any cost. Excessive fragmentation can create delay and ambiguity. The requirement is that no ordinary compromise gives one actor the ability to alter resources, rewrite history, destroy every copy and judge the resulting dispute. Separation should follow decisive powers, supported by tested communication and explicit priority when roles disagree.
NRS should avoid presenting distribution as a guarantee. Multiple authorized operators may share one software supplier, identity service, cloud environment or continuity custodian. A common vulnerability can affect many providers at once. The bodies responsible for appointing or supervising those operators should require dependency disclosure, aggregate concentration reporting and exercises that disable a shared component. NRS can analyze public evidence and advocate disclosure to members, but it is neither the accreditor nor the repository of mandatory operational filings. Visible provider count is a weak measure of resilience.
Member rights remain central. A holder should receive authenticated receipts, maintain protected recovery contacts, obtain its relevant history, challenge exceptional action and move service without losing recognized authority. During a cyber event, those rights may be temporarily constrained to prevent attacker movement, but the constraint should be resource-specific, evidence-based, time-limited and reviewable.
The model is positive because it makes institutional legitimacy testable. NRS does not need to claim that incumbent RIRs are careless or that litigation no longer matters. Through research, public comparison and member advocacy, it can demonstrate why a modern number-resource institution should survive both visible governance failure and quiet corruption. The standard should be available for RIR adoption and independent scrutiny; it is not an NRS-operated service and should not become a vehicle for institutional rivalry.
Assurance reports must expose the integrity question
Security certifications and assurance reports can establish that specified controls were designed or operated during a period. They are valuable evidence, especially when scope, exceptions and testing are clear. They should not be converted into a blanket statement that registry data is correct. Stakeholders need to know which services, identities, backup controls, change histories and recovery exercises were actually examined.
Public assurance should identify the integrity model in plain language. Does the registry maintain protected transaction history? How often do external custodians receive copies or commitments? Can ordinary administrators alter retention? Which dependent services are included? Has a restoration from a suspected-compromise boundary been tested? How are disputed records treated? These questions reveal readiness without demanding sensitive configuration.
Exercise metrics should include detection time, containment time, earliest trustworthy boundary, reconciliation duration, proportion of events automatically replayed, number requiring holder confirmation, number left disputed, public-service divergence and time to converge. It should also report failed external deposits, missing checkpoints, stale protected contacts and untested service dependencies. Distribution matters more than a favorable average.
Near misses deserve protected review and aggregate disclosure. A failed backup, unexplained administrative change or inconsistent public response can reveal weakness before a major incident. Staff and members should have safe reporting channels. Retaliation against a reporter is itself a governance failure because it suppresses the institution's ability to learn about integrity risk.
Claims should carry dates. "Regularly tested" may mean last week or four years ago. "Off-site" may mean a separate building under the same credentials. "Immutable" may mean protected from deletion for thirty days by administrators who can change the policy. Precise descriptions let members and reviewers assess the protection instead of relying on comforting adjectives.
An honest report can acknowledge failure. If an exercise could not reconcile several synthetic records, the institution should preserve the finding, protect the affected design and retest after correction. Concealing a controlled failure sacrifices the purpose of the exercise. Confidence comes from demonstrated learning, not an uninterrupted sequence of claimed success.
A 2027 acceptance test should be difficult to pass
The minimum test begins with governance. The board or equivalent body approves an integrity-threat model, defines protected authority, appoints an independent exercise leader and records who may declare primary state suspect. Contracts with custodians, alternate operators and responders permit the necessary release while preserving confidentiality and review.
The second test is evidentiary. The institution produces a protected sequence of consequential events, independently held copies, verifiable backup lineage, external observations and current authority contacts. Assessors confirm that ordinary production privilege cannot silently rewrite every source. At least one copy and one witness remain usable after the scenario disables the main identity system and most recent backup.
The third test is reconstruction. The receiving team identifies the affected interval, separates legitimate and malicious changes, traces downstream effects and states uncertainty. It does not receive an answer key until decisions are frozen. False confidence counts against the result: incorrectly declaring a malicious event valid is more serious than protecting an ambiguous event for later review.
The fourth test is operational. Clean services return with ordered authority. Public directory responses converge, reverse-DNS state is correct, routing registry corrections are issued and RPKI consequences are handled under a separate high-assurance decision. Compromised credentials do not work. Legitimate holders can reach support and challenge restrictions. Unaffected resources continue safely.
The fifth test is institutional. Emergency powers expire. Independent reviewers examine decisions. Holders receive corrections and explanations appropriate to their role. Public reporting states what was tested and what failed. Remediation has named owners and dates. A second exercise demonstrates that the findings were actually resolved.
Passing should not mean zero interruption or perfect reconstruction. Some uncertainty is realistic, especially with legacy records. Passing means uncertainty is identified, bounded and governed; clean authority is distinguishable from compromised authority; and service can move without transforming the emergency operator into a new owner of resource rights.
Continuity should preserve justified reliance, not just service
Internet number registries derive legitimacy from more than technical operation. Networks and the public rely on their records because the institution is expected to apply recognized rules, preserve history, authenticate change and correct error. A cyber event attacks that basis of reliance even if no router immediately loses reachability.
The period from 2020 to 2027 has made destructive cyber risk, offline backup, tested restoration and data integrity ordinary board concerns across critical services. In number governance, the public debate has also sharpened around institutional continuity and possible substitute operation. These lines should now meet. An emergency operator needs trustworthy state; trustworthy state needs independent evidence before the emergency.
The immediate priority is not to predict which registry will be attacked or when quantum-like catastrophe will arrive. It is to remove a weak assumption: that survival of the latest database equals survival of legitimate authority. Every serious continuity plan should be able to explain why its restored state is trusted, which evidence could disprove it and who has power to decide while facts remain incomplete.
NRS can advocate a constructive benchmark by researching signed history, external custody, holder receipts, dependency mapping and integrity-led migration exercises, then publishing evidence-led comparisons of adoption. Existing RIRs and authorized continuity operators must implement and test the protections; independent reviewers should assess contested outcomes. Safety should not depend on institutional branding. Common acceptance tests can improve the whole number-resource system.
The next registry failure may still begin in a courtroom, a bank account or a boardroom. It may instead begin with one stolen session and a change too plausible to trigger alarm. Preparedness for the second case will also strengthen the first: better history, independent copies, bounded emergency authority and tested migration make any continuity decision more defensible.
The governing principle is simple but demanding. Availability answers whether a service can speak. Integrity answers whether anyone should believe it. A registry that can restore only the first has not preserved its public function. The continuity promise is complete only when the institution can show, with independent evidence and practiced correction, why the recovered account of number-resource authority deserves reliance.
Evidence and further reading
- NIST, Cybersecurity Framework 2.0 - establishes governance, protection, detection, response and recovery outcomes, including verification of restoration assets before use.
- NIST, Data Integrity: Recovering from Ransomware and Other Destructive Events - addresses recovery from data-corruption events with emphasis on confidence in the accuracy of restored information.
- NIST, Data Integrity: Detecting and Responding to Ransomware and Other Destructive Events - provides a companion basis for detecting and responding to destructive integrity attacks.
- CISA, StopRansomware Guide - recommends offline encrypted backups and regular testing of backup availability and integrity in disaster recovery.
- RIPE NCC, 188th Executive Board Meeting Minutes - records work on a registry business continuity plan, registry-data escrow, identified gaps and ISO 27001 implementation.
- RIPE NCC, Information Security, Risk and Compliance Quarterly Planning - gives current public detail on audit, risk resilience, application security, monitoring and incident-response work.
- RIPE NCC, 2025 Annual Report - reports RPKI assurance activity, continuing ISO 27001 work, continuity readiness and data-governance development.
- RIPE NCC, Trust Portal announcement - describes public assurance about confidentiality, integrity, availability, vulnerability management and incident response.
- ICANN, Emergency Back-End Registry Operator program - provides a comparative model for pre-arranged temporary operation of bounded critical registry functions.
- ICANN, Registry Transition Processes - sets out emergency thresholds, cached data, escrow release and measured activation targets for substitute service.
- RFC 6480, An Infrastructure to Support Secure Internet Routing - defines the core RPKI architecture whose certificate and repository consequences must be handled separately during registry recovery.
- RFC 8897, Requirements for RPKI Relying Parties - explains validation, retrieval and local processing duties relevant to observing the effect of restored or disputed RPKI state.

