Cyber-security

How Resilient Am I to a Major Cyber Disruption?

USD 49 single Risk Briefing|Delivered within 4 hours|Reference material, not advice
Configure your report

What this risk is, and why it matters

Resilience assumes that prevention will eventually fail, and measures how quickly and completely the business recovers when it does. It reframes cyber from a technical problem into a continuity one: the question is not only whether an attack can be stopped, but whether the organisation can keep operating, meet its obligations and restore trust afterwards. Regulators, insurers and customers increasingly judge firms on recovery capability, not just defensive controls, because downtime is where the real damage accrues.

Legal and regulatory framework

Operational-resilience rules now mandate what was once good practice. The EU's DORA sets resilience, testing and recovery requirements for financial entities and their ICT providers; UK operational-resilience rules require firms to set impact tolerances for important business services; and NIS2 obliges essential entities to maintain business-continuity and crisis-management capability. Regulators expect evidence of tested recovery, not paper plans, and increasingly scrutinise concentration on shared providers as a systemic resilience risk.

Typical scenarios and impact

The loss data shows that recovery time, more than the initial compromise, determines total cost: firms that restore in hours absorb an incident, while those taking weeks suffer contract losses, breach of service obligations, and lasting reputational harm. Documented cases include organisations reverting to manual operations for extended periods and others unable to restore because backups were unavailable or themselves encrypted. Poor resilience turns a contained event into an existential one.

Mitigation framework and when to engage an expert

Resilience rests on immutable, offline, regularly-tested backups; a rehearsed and role-assigned incident-response and crisis-management plan; defined recovery-time objectives for critical services; and manual fallback for a loss of key systems. Test through realistic tabletop and technical exercises, including scenarios where the primary provider is unavailable. Engage incident-response and business-continuity specialists to validate the plan, and ensure the board has set and understands the tolerance for downtime on each important service.

Read the report. Talk to an expert.

This research is a starting point, not a verdict.

A Risk Briefing in the Cyber-security Domain tells you what the risk looks like, what the law says, and what indicators to watch. It does not replace a senior adviser who knows your jurisdiction, your industry, and your specific exposure. Senior advisors who have published on this exact question for your country appear at the bottom of this page once you have configured for a country. Download a Report for free; contact details live inside each PDF.

Configure for your country and industry

Pick a jurisdiction and an industry. Receive the report within 4 hours.

Country, optional state or region, and optional industry. Single Risk Briefing USD 49. Or buy the entire Domain Bundle (12 Risk Briefings) for USD 412 Save USD 176 (30%).

For Expert-Partners

Publish on this exact question

Buyers researching this risk in their country see your Report on this page. A Single Seat is USD 495 a year, up to five firms per page, and a Pro Seat is USD 1,485 for the larger card at the top. All 12 Cyber questions in one country cost USD 4,158/yr (save usd 1,782 (30%)). Registration is free and shows which of them are open before you choose.

Reference material for informed readers, not professional advice. Reports are produced against current, verifiable sources; material claims are referenced. Always consult a qualified adviser before acting on the contents of a report. Browse all Intelligence Reports.