The 2025 attacks on major UK firms including M&S, the Co-op, and Jaguar Land Rover have demonstrated the importance of having a resilient business. A year later, boosting cyber resilience is mandated by multiple regulations as the cost of cyber-attacks impacts national economies.
How can CISOs assess what is needed to be resilient and apply this to their own business?
Resilience Drive
The move towards cyber-resilience comes at a time when cyber-attacks are accepted as matter of fact. Resilience is being driven by the realisation that perfect security is “impossible,” says Quentyn Taylor, senior director of information security at Canon Europe, Middle East and Africa.
He believes being able to react and respond to incidents “is now a far more sensible approach than trying to prevent them from happening at all.”
“History has shown that no matter how much money you put into your information security team or defence layers, someone will always find a way around,” Taylor says. “If you accept this as fact, the way forward becomes clear.”
Resilience allows businesses to “bounce back to steady operations more quickly,” he says.
The shift towards resilience is an acknowledgment of something practitioners have known for a long time: Not every incident can be stopped, agrees Mandy Andress CISO at Elastic. She says the question now is “what happens when something gets through.”
Ransomware has been one of the biggest drivers of the shift towards resilience, adds Stewart Parkin, global CTO, Assured Data Protection. “Organisations can put strong cybersecurity measures in place, but attackers are still breaching defences. With businesses increasingly dependent on digital systems, an attack can quickly become a wider business issue, affecting operations, revenue and customers.”
AI is making this shift even more pressing, Parkin adds. “Attackers can use it to move faster and operate at greater scale, but the risks don’t only come from outside the organisation. As businesses deploy AI agents with access to data, applications and critical processes, there is also greater potential for mistakes or unintended actions to cause significant disruption.”
Prevention and Resilience
Theo Nell, consulting security officer at Security Everywhere believes prevention and resilience go hand in hand. “Prevention aims to reduce the likelihood of a successful attack, while resilience recognises that no preventative controls can guarantee that an attack, outage or other disruption will never occur. Organisations therefore need to be able to continue operating, respond effectively and recover when preventative measures fail.”
The pressure is very real for business and security leaders, with latest figures from the UK National Cyber Security Centre (NCSC) recording 204 nationally significant cyber incidents in a year, up from 89 the year before.
In response, more regulations are being introduced, and experts say the Digital Operational Resilience Act, Network and Information Systems Directive 2 (NIS2), the EU Cyber Resilience Act and the UK Cyber Security and Resilience Bill should all be on the CISOs’ radars.
Regulations such as the UK Cyber Security and Resilience Bill and NIS2 have “changed the game,” says Taylor. “It used to be that not all industries were regulated, but times have changed. For example, if you are a CISO in the financial services industry or if you simply supply products or services into the financial services industry now, you need to be aware of DORA.”
Their scope and timelines differ, so security leaders need to understand which requirements apply to their organisation and suppliers alike, says Dan Wood, CISO at Cyberfort. “The real work is translating those obligations into operational readiness, tested response plans and the ability to recover critical services in a timely manner. Compliance should provide the necessary evidence that the business can cope with disruption.”
The CISO’s Role
Amid this complex environment, the CISO’s role is to “make disruption tangible,” says Wood: “This includes which services matter most, what systems and suppliers they depend on, and how long recovery would actually take.”
Working with business and technology leaders, the CISO should support those answers with evidence and test whether recovery plans can deliver, Wood says.
The board’s role is to agree how much disruption the business can tolerate and approve recovery objectives that reflect those limits. “It must ensure recovery capability is proportionate to the business’ needs and sufficient to meet its accepted recovery objectives, fund that capability, and hold leaders accountable for addressing gaps exposed by testing,” Wood explains.
Any decision to accept a shortfall must be explicit and informed by the business consequences. “Resilience is a shared responsibility, with the board retaining accountability for the risk the business accepts,” according to Wood.
Proactive Steps CISOs
Boosting resilience is certainly challenging, but there are some solid steps CISOs can take now.
CISOs must start with visibility, proceed to risk assessment, think about controls that reduce risk and then “evaluate resilience continuously,” says Daniel dos Santos, VP of research at Forescout.
“First, identify business processes that are critical to revenue, safety, customer trust and other indicators relevant to your industry,” he advises. Then, map these processes to technology assets such as applications and devices where they run.
Organisations should maintain continuous visibility into those assets and use this information to “understand how changes in the environment affect risk,” says dos Santos.
“You only know what you know; it’s the not knowing that can cause the biggest headaches,” says Wood. This makes identification key, he says.
Wood believes firms should conduct a discovery exercise to fully understand the landscape. “Perform a business impact assessment to establish what critical services are truly essential to the business. Then test test test."
“Perform scenario testing on critical asset outages, service interruptions and the effectiveness of the business response to getting back to ’normal’. This will support the business two-fold by identifying areas for improvement in recovery and making the recovery process ‘muscle memory’ should a live event occur.”
Nell recommends “maintaining a comprehensive risk register,” ensuring identified risks result in “appropriate corrective-action plans,” rather than simply being recorded.
At the same time, align resilience controls and security measures with regulatory requirements and the organisation's actual risk exposure, Nell adds. He says Cyber Essentials is “a particularly useful starting point” for many UK organisations because it “provides a relatively low-cost route to establishing fundamental technical controls against common attacks”.
Written by
Kate O'Flaherty
Cybersecurity and privacy journalist