Cyber resilience: The lighthouse in the storm
Cyber incidents happen. They will continue to happen.
Organisations can invest in prevention, strengthen controls and reduce their exposure. They should. But no board, CIO or security leader can credibly promise that their organisation will never experience a serious cyber incident.
The more important question is what happens next.
When systems are compromised, ransomware starts spreading or a critical supplier goes offline, does the organisation know how to respond? Can people make difficult decisions quickly? Do they have the authority to act? Can the business protect its customers, maintain critical operations and start recovering?
That is where cyber resilience becomes commercially important.
The organisations that prepare properly are not simply protecting technology. They are protecting their ability to operate. They are protecting customer confidence, reputation, revenue and margin.
Cyber resilience is the lighthouse in the storm. You hope you never need it. But when the storm arrives, it needs to be there.
Cyber resilience starts before the incident
There is still a tendency to think about cyber security as a technical discipline. Firewalls, endpoint protection, identity management, monitoring and security operations all matter. Getting the basics right matters enormously.
But resilience is bigger than security technology.
It starts with leadership understanding that cyber risk is business risk. The board is accountable for that risk. The CIO and security leadership have responsibility for building and maintaining the capability to manage it. But when a serious incident happens, almost every part of the organisation can become involved.
Operations may need to change. Customer services may need to respond to worried customers. Finance may need to understand the commercial impact. Communications teams may need to manage external messaging. Legal and regulatory obligations may be triggered.
Cyber resilience therefore depends on an organisation knowing what it will do before it needs to do it.
Consider a ransomware attack moving through the network. Does the technology team know whether it has the authority to disconnect infrastructure immediately to prevent further propagation?
That decision could deliberately take critical systems offline. It could stop parts of the business operating. There may be a direct commercial consequence.
Waiting for three levels of approval could have a much bigger one.
The same applies when a Security Operations Centre reports a potentially critical incident. Do people feel confident enough to investigate and escalate? Or is the culture one where nobody wants to raise the alarm until they are absolutely certain?
In a cyber incident, certainty can arrive too late.
People need clear responsibilities, established escalation routes and the authority to act in the interests of the organisation. They also need confidence that making a reasonable decision quickly will be supported by leadership.
That does not happen because someone wrote an incident response document two years ago. It comes from preparation, practice and leadership.
The commercial consequences are already clear
Recent cyber incidents demonstrate why resilience needs to be discussed in commercial terms.
The 2025 cyber incident at M&S disrupted online trading and stock flow and required manual processes to maintain operations. M&S initially estimated an impact of around £300 million on operating profit before mitigation, insurance and trading actions. Its subsequent full-year results recorded £131.3 million of incident-related costs, while adjusted profit before tax fell 23.8%. The business also highlighted the importance of its resilient balance sheet in absorbing the disruption while continuing to invest.
There is an important lesson in that. Resilience is not an abstract measure of cyber maturity. It affects how well a business can continue trading, how quickly operations can recover and how much financial capacity it has to absorb disruption.
The British Library provides a different example.
Its October 2023 cyber attack destroyed multiple capabilities simultaneously and required what the Library describes as a rebuild of its entire technology infrastructure. More than two years later, its own website continues to state that recovery is underway and not everything is back. The Library has been unusually open about the incident, publishing its own review to help other organisations learn from its experience.
The lesson is significant. Recovery from a major cyber incident is not necessarily measured in hours or days. Depending on the damage and the organisation’s preparedness, it can fundamentally change how technology services need to be rebuilt.
Then there is the question of dependencies.
The 2024 Change Healthcare attack disrupted pharmacy services, medical claims and payments across the US healthcare system. As services were restored, UnitedHealth Group reported that Change Healthcare’s payment processing represented approximately 6% of payments across the US healthcare system. The organisation also provided billions of dollars in financial assistance to affected healthcare providers.
The impact did not stop at the boundary of the organisation that was attacked.
That should matter to every executive team.
Most organisations rely on complex networks of technology providers, cloud platforms, software vendors, payment services and operational partners. If a critical supplier is compromised tomorrow, can the organisation identify every service that depends on it? Does it know which business processes will be affected? Is there an alternative?
Resilience means understanding those dependencies before they become an emergency.
Recovery depends on leadership, not just technology
A serious cyber incident creates pressure very quickly.
Information will be incomplete. Decisions will have consequences. Customers, employees, regulators and potentially the media will want answers.
The organisation needs to bring the right people together quickly and securely. That last word matters. The normal collaboration tools, email systems or identity platforms may themselves be compromised or unavailable.
- Who declares the incident?
- Who brings the response team together?
- How will they communicate?
- Who has authority to take systems offline?
- Who makes decisions about customers and operations?
- Who understands the potential revenue and margin impact?
- Who communicates with the board?
- And, critically, have any of those people practised doing it?
This is why table-top exercises and incident simulations matter. They expose assumptions while there is still time to fix them. They show whether the documented response plan actually works and whether everyone understands what they might be asked to do.
They also help leadership teams confront the commercial realities of an incident.
A cyber security team may recommend taking a system offline because that is the safest technical decision. The business may know that doing so stops a critical revenue stream. Both perspectives matter.
The objective is not to choose commercial performance over security, or security over commercial performance. It is to understand the consequences well enough to make the right decision at the right time.
That requires open and honest conversations between the board, executives, technology and security leaders before the incident happens.
The board owns accountability for cyber risk. The CIO and security leadership are responsible for ensuring the organisation has the right capability. But cyber resilience is everyone’s responsibility because recovery is an organisational challenge, not simply a technical one.
Build the lighthouse before the storm
No organisation can eliminate cyber risk completely.
What leaders can control is how prepared the organisation is to respond.
Getting the basics right reduces the likelihood and potential impact of an attack. Strong governance creates clarity around accountability and decision-making. Tested incident response and business continuity plans help people understand what happens next.
Good security leadership connects those things together.
That is the role Relentica plays through its Cyber Security, Risk & Resilience capability.
We help organisations strengthen cyber security, understand technology risk and build resilience across their operations. That includes cyber security strategy and governance, cyber resilience and business continuity, technology risk and security advisory, security architecture and assurance, board training and table-top exercises, regulatory readiness, cyber risk for M&A and vendor assessment.
For organisations that need experienced security leadership without immediately appointing a permanent executive, Relentica also provides Fractional and Interim Chief Information Security Officer – vCISO – support.
A vCISO can work alongside boards, executive teams, CIOs and technology leaders to establish the strategy, governance and practical controls needed to reduce risk and improve resilience. The role can provide strategic guidance for a few days each month or interim leadership during a period of change, helping organisations make confident decisions while building longer-term capability.
The objective is bigger than preventing the next attack.
It is knowing that if something happens, people understand what to do. They have the authority to act. Critical dependencies are understood. Leaders can come together quickly. Decisions consider both the technical risk and the commercial reality.
Because when the storm arrives, that preparation protects more than systems.
It protects customers. It protects reputation. It protects revenue and margin. And it gives the organisation a far better chance of recovering quickly and continuing to move forward.
You cannot build your lighthouse in the middle of the storm.
Build resilience before you need it.
Latest News and Blogs
-
Cyber incidents will happen. The organisations that recover best prepare before the crisis - building the leadership, authority and response capability needed to protect customers, revenue, reputation and business performance when disruption arrives.
-
Technology, data, digital and AI increasingly underpin private equity value creation. The opportunity is to connect technology strategy directly to revenue growth, margin improvement, resilience and the next stage of value creation.
-
Scaling through optimisation is not about reducing cost. It is about creating capacity by simplifying technology, processes and operating models, giving organisations the headroom to grow revenue, improve margins and strengthen resilience.