What this risk is, and why it matters
Resilience assumes that prevention will eventually fail, and measures how quickly and completely the business recovers when it does. It reframes cyber from a technical problem into a continuity one: the question is not only whether an attack can be stopped, but whether the organisation can keep operating, meet its obligations and restore trust afterwards. Regulators, insurers and customers increasingly judge firms on recovery capability, not just defensive controls, because downtime is where the real damage accrues.
Legal and regulatory framework
Operational-resilience rules now mandate what was once good practice. The EU's DORA sets resilience, testing and recovery requirements for financial entities and their ICT providers; UK operational-resilience rules require firms to set impact tolerances for important business services; and NIS2 obliges essential entities to maintain business-continuity and crisis-management capability. Regulators expect evidence of tested recovery, not paper plans, and increasingly scrutinise concentration on shared providers as a systemic resilience risk.
Typical scenarios and impact
The loss data shows that recovery time, more than the initial compromise, determines total cost: firms that restore in hours absorb an incident, while those taking weeks suffer contract losses, breach of service obligations, and lasting reputational harm. Documented cases include organisations reverting to manual operations for extended periods and others unable to restore because backups were unavailable or themselves encrypted. Poor resilience turns a contained event into an existential one.
Mitigation framework and when to engage an expert
Resilience rests on immutable, offline, regularly-tested backups; a rehearsed and role-assigned incident-response and crisis-management plan; defined recovery-time objectives for critical services; and manual fallback for a loss of key systems. Test through realistic tabletop and technical exercises, including scenarios where the primary provider is unavailable. Engage incident-response and business-continuity specialists to validate the plan, and ensure the board has set and understands the tolerance for downtime on each important service.