Minimum Viable Company: What’s Actually New Here?

A term with real momentum, four different definitions, and a decade-old cousin nobody mentions.

Ask four different advisers to define “Minimum Viable Company” and you’ll get four different answers, all wearing the same three letters. That’s usually the first sign a term hasn’t earned its place in the vocabulary yet — and it’s worth working through before anyone signs off a budget line for it.

MVC — sometimes MVB, Minimum Viable Business, used interchangeably by at least one major vendor as though the distinction never mattered — has become a fixture of resilience pitch decks since roughly 2023. PwC has built a service line and a podcast series around it. KPMG has published repeatedly on it through 2025 and 2026, including a specific take for family businesses and another for the consumer and retail sector. Cohesity, Veeam, Commvault and Semperis all use it as shorthand for cyber recovery scope. The Business Continuity Institute has run sessions on it. It has, in short, arrived.

The phrase itself is not new, and nobody seems to claim credit for it. It’s an obvious lift from Eric Ries’s “minimum viable product”, repointed at organisational survival instead of product development. The earliest use we could find in a resilience context dates to the summer of 2020: Sungard Availability Services’ John Beattie, talking to Raconteur about how organisations were “thinking about… how can I continue my minimum viable company”, already using it as settled shorthand rather than introducing it. That timing tracks — mid-pandemic was exactly when a lot of BC teams were being asked, in practice rather than in theory, what the smallest version of the business actually looked like. What’s changed since isn’t the idea but the volume around it. The cyber recovery vendors picked it up first, from around 2022 onwards, to describe what needs to come back online after a ransomware attack and in what order. The Big Four followed from about 2024, and the framing shifted again — from “what do we restore first” to something closer to an existential question about the whole organisation.

Four consultancies, four definitions

Put the actual source material side by side and the disagreement isn’t subtle.

  • PwC: “the smallest set of capabilities that must remain operational to keep the organisation viable through severe disruption” — built from critical external offerings, critical internal operations and foundational dependencies. PwC is explicit that this is not a service catalogue, a regulatory submission or a technology recovery plan; it’s pitched as an executive-level view.
  • KPMG: frames MVC around identity rather than capability — “what is the minimum version of our company that must survive for us to still exist as a functioning, legally and economically recognisable business” — broken into Minimum Viable Services, Minimum Viable Processes and Minimum Viable Assets (three more TLAs nested inside the first one), and explicitly contrasted with the “Important Business Services” concept used elsewhere in operational resilience regulation, on the grounds that MVC is “identity-centric, not service-centric.”
  • Cohesity: “the smallest version of an organization that can continue to operate, serve customers, and meet its obligations under extreme conditions” — six domains (people, process, technology, documentation, facilities, third-party dependencies), tiered against 24-hour, 72-hour and one-week recovery windows, with identity and access management as the foundation.
  • Veeam: doesn’t bother distinguishing MVC from MVB at all — both cover “the bare minimum operations, processes, systems, and data an organization must restore to remain functional after a cyberattack”, scoped specifically to cyber incidents rather than disruption in general.

Those aren’t four phrasings of one idea. PwC’s version is a capability inventory. KPMG’s is closer to a philosophical test of corporate identity. Cohesity’s is a technical recovery sequence with a time axis. Veeam’s is narrower still, built for a single incident type. A term that means an executive-level capability list to one adviser and a ransomware runbook to another isn’t a shared standard — it’s four different products sharing a label. That’s a comfortable position to be in if you’re selling something, and a confusing one if you’re buying it.

The bit nobody mentions: this already had a name

Business continuity has had a formally defined answer to “what’s the least we can get away with” since ISO 22301 was first published in 2012, carried through into the 2019 revision unchanged in substance: the Minimum Business Continuity Objective, or MBCO — “a minimum level of services and/or products that is acceptable to the organization to achieve its business objectives during a disruption.” It sits alongside MTPD (how long before disruption becomes unacceptable) and RTO as one of the standard outputs of a properly run BIA. It is, in other words, an ISO-standardised, internationally recognised, already-audited concept that every organisation certified to 22301 has been setting for well over a decade.

Even the friendlier commentary on MVC concedes the overlap. One resilience commentary site, working through the concept without any particular axe to grind, states plainly that “the MVC closely aligns with the concept of the minimum business continuity objective”, and offers as the distinguishing feature that MVC covers “the minimal viable form of the entire organization, including core structures and capabilities, rather than just outputs.” We’d push back on how much daylight that actually leaves. A properly conducted BIA under 22301 doesn’t stop at outputs — the business continuity strategies and solutions work exists specifically to identify the people, technology, premises, information and suppliers needed to deliver those minimum outputs. If your MBCO work stopped at “what” and never got to “with what”, that’s a gap in how the BIA was run, not evidence that a new concept was needed to fill it.

There’s a third complication worth flagging. The phrase has also been used to mean something else entirely. Back in February 2021, CTO Meri Williams — whose background includes Monzo and the Government Digital Service — used “minimum viable business continuity management” in a talk to describe a pragmatic, incrementally built BCM programme, not a description of the organisation’s surviving core. So three different communities have now taken the same three words and pointed them at three different problems: an existing ISO concept, a cyber recovery runbook, and a methodology for building BC programmes lean. That’s not a term maturing. That’s a term still being fought over.

So does it add anything?

Some, to be fair to it. Two things are genuinely useful, and we’d rather say so than pretend this is a clean takedown.

The first is communicative. “Will we still exist” lands with a board in a way that “have we set our Minimum Business Continuity Objectives” never will. Most of what MVC does well is translation — taking work you should already be doing under 22301 and describing it in language an executive committee finds viscerally uncomfortable rather than procedurally dull. That’s not nothing. Getting a board to actually engage with resilience is most of the job.

The second is the cyber recovery vendors’ contribution, which is more substantive than the rest of the field’s. Sequencing recovery by technical dependency — identity and access management first, because everything else depends on it, then core infrastructure, then the rest, against 24-hour, 72-hour and one-week windows — is a genuinely sharper way of thinking about the first days after a cyberattack than classical BC’s activity-and-RTO model was built for. That came out of practical ransomware recovery experience, not a rebrand exercise, and it’s worth taking seriously on its own terms — ideally under a name that doesn’t imply it’s the whole discipline.

What it isn’t is a new methodology for business continuity or operational resilience generally, and we’d treat with real caution any proposal that positions it as one. If an adviser is pitching “Minimum Viable Company” as a discrete new deliverable, sitting alongside — rather than expressed through — your existing BIA, MBCO and Important Business Services work, ask them in writing how it differs from what you’ve already paid to have done, and get the answer before the statement of work is signed. In our experience the honest answer is usually “it’s the same analysis, described differently for the board pack” — which is a perfectly fine thing to buy, just not at the price of a new methodology.

None of this makes MVC worthless. Language that gets a board to sit up and pay attention has genuine value in a discipline that spends a lot of its life being politely ignored until the moment it isn’t. But it’s worth being honest about what you’re buying: a useful piece of translation and, from the cyber recovery specialists, a genuinely sharper technical sequencing model — not a new discipline, and not, whatever the slide deck implies, a replacement for the BIA work most organisations are still doing badly.

Share the Post:
Helen Molyneux, founder of Cambridge Risk Solutions, ISO 22301 and ISO 27001 Lead Auditor

Helen Molyneux is the founder and director of Cambridge Risk Solutions. A certified Lead Auditor for ISO 22301 and ISO 27001, she has spent nearly two decades helping organisations across the public and private sectors build genuine resilience — not just documented compliance. She writes from practice, not theory.

Work with us →