Cybersecurity • 4 hours ago • Neha Jamwal

For years, the dominant question in enterprise cybersecurity was straightforward: How do we stop the attack? Security teams invested in firewalls, endpoint protection, identity controls, threat detection and incident response with the expectation that stronger prevention and faster detection would keep the business protected.
That question is no longer sufficient.
As enterprises become more dependent on cloud platforms, digital applications, third-party providers, connected infrastructure and always-on services, even a well-defended organization has to assume that some attacks will get through. The more important question is increasingly becoming: Can the business continue operating when they do?
That shift is pushing cyber resilience beyond the security function and into business continuity, operations, finance and executive decision-making. A recent World Economic Forum analysis argues that organizations need to move beyond simply asking whether they are resilient and instead determine how resilient they need to be, including the value at risk and the return generated by resilience investments. The distinction is important because an organization can successfully contain an intrusion and still experience a major business failure.
A security incident can become a business crisis within hours
Consider a ransomware attack against a large enterprise. The obvious security problem is encrypted or stolen data. But the operational consequences can spread much further. Employees may lose access to core applications. Customer transactions can stop. Manufacturing or logistics operations may be interrupted. Contact centers may struggle to serve customers. Suppliers may be unable to exchange information. Finance teams may not be able to process payments. Even internal communication can become difficult if collaboration systems are affected.
At that point, the organization is no longer dealing with a cybersecurity incident in isolation. It is dealing with a business continuity crisis that happens to have started with a cyberattack.
Recent research reinforces this disconnect between technical recovery and business recovery. Veeam’s 2026 Data Trust and Resilience Report found that while 90% of organizations said they were confident they could meet defined recovery time objectives, only 69% said those objectives fully aligned with their business continuity goals. Among organizations affected by cyber incidents involving downtime, data loss or disruption, customer and financial impacts were also significant. That gap should concern executives. Meeting an IT recovery target does not necessarily mean the business has recovered.
Recovery time is not the same as business resilience
Recovery Time Objectives have traditionally been treated as an important measure of preparedness. They remain useful, but they can create a false sense of security when viewed without business context.
Restoring a database within four hours sounds impressive until the organization realizes that its payment system, customer identity platform or logistics application depends on another service that cannot be restored for twelve hours.
The same applies to backups. Having multiple copies of data is essential, but backups alone do not guarantee operational continuity. Enterprises also need to know whether those backups are trustworthy, whether recovery credentials remain available, whether applications can be rebuilt in the correct order and whether dependencies outside the organization’s direct control will also be available. This is why resilience needs to be measured from the perspective of business services, rather than individual technology assets.
The question should not simply be whether a server can be restored. It should be whether the organization can continue processing orders, serving customers, paying employees, shipping products or meeting regulatory obligations while recovery is underway.
The rise of the “minimum viable business”
This is leading to a useful change in thinking: enterprises should identify the smallest set of capabilities required to keep the business functioning during a major disruption. A company may not need every internal application to remain available during a cyber incident. It may, however, need customer communications, payment processing, core operational systems, identity services and a limited set of data-access capabilities.
That concept changes how resilience is designed.
Instead of attempting to restore everything simultaneously, organizations can establish a hierarchy of critical business services and determine how each one should operate under degraded conditions. Employees might temporarily use alternative communication channels. Certain non-essential applications could remain offline. Customer-facing services could operate with reduced functionality rather than shutting down completely.
The objective is not perfect continuity. It is controlled continuity. That distinction can significantly reduce the pressure placed on incident-response teams because the organization has already decided what matters most before a crisis occurs.
Cyber resilience needs to leave the CISO’s silo
One of the biggest obstacles is organizational. Cybersecurity teams often own detection, containment and incident response. Business continuity teams may own disaster recovery. IT teams own infrastructure. Application teams own critical services. Operations teams understand customer and supply-chain dependencies. Communications teams handle external messaging.
During a serious cyber incident, however, all of these responsibilities collide. The result can be decision paralysis precisely when decisions need to be made quickly.
PwC’s latest Global Digital Trust Insights survey shows why this remains a significant challenge. Only 39% of surveyed organizations have fully formalized operational continuity plans that specifically address cyber threats, while 84% expect their cyber budgets to increase and AI remains a major investment priority.
The message for executives is clear: spending more on cybersecurity does not automatically produce resilience. The organization also needs the governance structure, processes and cross-functional exercises required to turn that investment into operational readiness.
Third-party dependencies make resilience harder
Modern enterprises rarely operate entirely within their own infrastructure. Cloud providers, payment platforms, identity providers, SaaS applications, telecommunications providers, logistics partners and software vendors all form part of the operational ecosystem. A company may maintain excellent internal recovery capabilities and still be unable to operate because a critical external dependency is unavailable.
This is becoming particularly important as organizations consolidate technology services around fewer major platforms. A third-party outage or cyber incident can therefore have consequences across multiple business functions simultaneously. The resilience question becomes broader: What happens if a critical provider is compromised at exactly the moment your organization is experiencing its own cyber incident?
Enterprises need to map these dependencies before an incident, identify alternatives where practical and establish clear priorities for restoring interconnected services. This also means third-party risk management should not end with vendor questionnaires and annual assessments. Organizations need to understand how external dependencies affect their ability to maintain critical business services during disruption.
Testing matters more than having a plan
Most enterprises already have some combination of incident-response plans, disaster-recovery documentation and business-continuity procedures. The problem is that documents do not prove resilience.
A plan that has never been exercised may contain assumptions that collapse under real-world pressure. Credentials may no longer work. Contact information may be outdated. A supposedly independent backup environment may share the same identity infrastructure as production. A critical vendor may have changed its recovery process. Business leaders may disagree about which services should be restored first. Testing exposes those weaknesses before attackers do.
The strongest resilience programs increasingly combine technical recovery exercises with executive simulations. Security teams should practice containment and recovery, while business leaders should practice making decisions with incomplete information. Operations teams should test degraded-service scenarios, and communications teams should rehearse customer and employee messaging.
NIST’s updated ransomware guidance similarly emphasizes preparedness, response and recovery as interconnected elements of managing ransomware risk rather than treating prevention as the sole objective.
The value of these exercises is not simply proving that systems can be restored. It is discovering where the organization’s assumptions about continuity are wrong.
AI is raising the stakes
The shift toward resilience is becoming even more important as AI changes both the threat environment and the enterprise technology landscape. AI can accelerate attacks, automate reconnaissance and increase the scale of malicious activity. At the same time, organizations are embedding AI into customer service, software development, analytics, operations and decision-making. That creates new dependencies that may become business-critical surprisingly quickly.
PwC’s latest research identifies attacks targeting AI systems as the cyber threat organizations feel least prepared to address. This creates an uncomfortable possibility: organizations may become dependent on AI-enabled services before they have developed mature continuity strategies for those systems. The resilience conversation therefore needs to include questions such as what happens when an AI service becomes unavailable, how organizations operate when an AI-assisted workflow has to be disabled and how critical AI outputs are validated during a security incident.
Resilience should become a board-level performance metric
Cybersecurity has traditionally been measured through technical indicators such as vulnerabilities patched, alerts investigated, incidents detected and mean time to respond. Those metrics remain valuable, but executives increasingly need business-oriented measures as well.
How long can a critical business service operate in degraded mode? How quickly can customer-facing operations resume? Which third-party dependencies represent single points of failure? How many critical services have been tested under cyberattack conditions? How much revenue is exposed to an hour of downtime? These questions connect cybersecurity investment to business outcomes.
The World Economic Forum’s recent work on quantifying cyber resilience makes a similar argument: boards need to think about resilience in terms of value at risk and the return on resilience investments rather than relying on a vague sense that the organization is “prepared.” That is a more useful conversation than asking whether the organization has enough security tools.
The competitive advantage may be the ability to keep operating
Cybersecurity will always involve prevention. Enterprises should continue investing in controls that reduce the probability and impact of attacks. But prevention cannot be the entire strategy.
The organizations that distinguish themselves over the next few years may be those that can absorb disruption without allowing a security incident to become a prolonged business shutdown. They will know which services matter most, understand their dependencies, maintain trusted recovery environments and regularly test whether their plans work under realistic conditions. That changes the definition of cyber readiness.
The strongest organization is not necessarily the one that can claim it will never be breached. It is the one that knows what it will do when it is breached — and has already practiced doing it.
Conclusion
Cyber resilience is becoming a business capability rather than a cybersecurity subcategory. As digital dependencies multiply, the boundary between a cyber incident and a business continuity event is disappearing.
Enterprises therefore need to stop treating recovery as the final stage of incident response. Resilience begins much earlier, with decisions about critical services, dependencies, identity, data, recovery architecture and the minimum capabilities the organization needs to keep operating.
The ultimate measure of cybersecurity may not be whether an enterprise can prevent every attack. It may be whether the organization can keep serving customers, generating revenue and making decisions while an attack is still unfolding. That is the point at which cybersecurity becomes business resilience.
Key Takeaways
- Cybersecurity and business continuity are converging. A cyberattack can quickly become an operational crisis affecting customers, revenue, employees and supply chains.
- Recovery does not equal resilience. Restoring infrastructure within an RTO does not guarantee that critical business services are functioning.
- Enterprises need a minimum viable business strategy. Organizations should identify the essential services that must continue during a major cyber disruption.
- Third-party dependencies are part of the resilience equation. Cloud, SaaS, identity, payment and other external providers can determine whether the business can continue operating.
- Plans need to be tested, not simply documented. Technical recovery exercises and executive simulations expose weaknesses that written plans often hide.
- AI is creating new continuity requirements. Organizations need contingency plans for critical AI-enabled services and workflows, not just security controls around them.
- Cyber resilience needs board-level metrics. Downtime exposure, recovery capability, critical-service availability and dependency risk provide a more meaningful view of readiness than security-tool counts alone.
- The goal is controlled continuity, not perfect continuity. A resilient enterprise knows which functions must remain operational and how to maintain them under degraded conditions.
