Cyber resilience is the capacity of an organisation or system to anticipate, withstand, recover from, and adapt to adverse cyber events while continuing to deliver its intended outcomes. It extends conventional cybersecurity from breach prevention towards graceful degradation, rapid restoration, and continuous learning under sustained attack. Cyber resilience integrates technical controls, business continuity planning, and governance so that critical functions persist even when individual defences fail.
Overview
- Cyber resilience reframes security around the assumption of compromise: defences will eventually be breached, so systems must limit blast radius and recover essential services quickly.
- It couples preventive controls with detective and recovery capabilities, measured by metrics such as mean time to detect and mean time to recover.
- Resilience spans people, process, and technology, embedding security into governance and continuity planning rather than treating it as a perimeter problem.
Key aspects
- Anticipation through threat intelligence and proactive risk assessment.
- Withstanding via defence-in-depth, segmentation, and zero-trust controls that contain intrusions.
- Recovery through tested backups, disaster recovery runbooks, and incident response playbooks.
- Adaptation by post-incident learning that hardens the system against recurrence.
Applications
- Critical national infrastructure protection where downtime is unacceptable.
- Financial services and healthcare systems subject to strict continuity and regulatory requirements.
- Cloud and distributed platforms that must survive ransomware, supply-chain compromise, and DDoS while maintaining service.