Let’s face it: resilience may have become a buzzword. In security, IT and even personal development, it is popping up everywhere. But how many organisations have really embedded resilience in their way of working? Often it remains a nice strategic document, an incident response plan dusted off once a year, or a one-off crisis exercise. That is not resilience. I call that wishful thinking.
Resilience as a system, not an incident
True resilience means not relying on a handful of experts or procedures that only work if everything goes according to plan. It involves a systems approach: a way of thinking and acting that is woven throughout the organisation. Just as a well-trained athlete prepares not only for the perfect race, but also for injuries, setbacks and changing circumstances.
In cybersecurity, you see the same pattern. We invest heavily in detection and response, but if the basic hygiene is not in order, the mopping up continues. Or worse: the organisation cannot recover quickly enough after an incident because dependencies and vulnerabilities only become visible when it is too late. Creating resilience means actively identifying and structurally reducing these dependencies, so that there are no surprises when the chips are down.
From incident response to cyber resilience
According to Gartner, we are seeing a shift in security and risk management (SRM) from a prevention-oriented approach to a focus on cyber resilience. This means that organisations not only try to prevent incidents, but also accept that disruptions are inevitable. The emphasis is on impact minimisation and strengthening adaptive capacity. This aligns closely with the concept of antifragility – the art of emerging stronger from disruptions.
I like to compare this to training for a marathon or ultra run. You not only build fitness, but also learn to cope with pain, fatigue and unexpected circumstances. In an ultra run, you inevitably come to a point where your body screams to give up. But through training, mental resilience and the right strategy, you learn to persevere and grow stronger from the experience. This is exactly how cyber resilience should work. Not just recovering from an incident, but getting better from it structurally.
In a business context, this means that resilience is not just reactive, but plays an active role in how systems are designed, how employees are trained and how decisions are made. This requires:
- Decentralised decision-making: Ensure that teams can act autonomously in case of disruptions, without waiting for approvals from above.
- Redundancy and flexibility: Build your systems and processes so that they can take a beating and have alternative routes if something fails.
- Continuous learning and experimentation: Simulate scenarios regularly, analyse near misses and proactively adjust your approach.
- Robust communication channels: Ensure that information flows quickly and effectively through the organisation so that everyone knows what is expected of them in stressful situations.
- Strategic integration of AI: Gartner points to the role of generative AI and automated security solutions in strengthening cyber resilience. Smart deployment of AI can improve detection and reduce recovery times.
Resilience as a mindset
Resilience is not only in systems, but especially in people. In how they react to setbacks, how they improvise and how they learn from mistakes. This is perhaps the most difficult factor to ’embed’, as it requires a culture change. An environment where mistakes are negotiable, where learning is more important than blaming, and where continuous improvement is the norm.
According to Gartner, we are seeing increasing attention to the human factor in cybersecurity, with security behaviour and culture programmes (SBCPs) playing a key role. These programmes help organisations strengthen security awareness and create a culture in which employees take ownership of cyber resilience. Resilient teams are not only well prepared for incidents, but can also deal creatively with contingencies without panicking or getting bogged down in viscous processes.
Organisations that truly embed resilience realise that it is an ongoing process. It requires a continuous balance between preparation and improvisation, between standard procedures and adaptability. And it requires leadership that not only steers for stability, but also dares to experiment and learn from setbacks.
Be honest: does your organisation already belong to this?
Also read our blog Cyber resilience – beyond cybersecurity
