Skip to main content

Article

From cybersecurity to cyber resilience: Four steps to move from numbers to action

What does cyber resilience mean and how is it different from cybersecurity?

A security-centric organisation focuses on prevention — deploying firewalls, limiting access, and training employees, among other cybersecurity processes and controls. A cyber-resilient organisation anticipates the possible failure of those security measures and knows how it will act.

True cyber resilience is achieved when an organisation has the capacity to not only anticipate and prevent attacks, but also to respond and recover from one. A cyber-resilient organisation can minimise losses from a cyberattack and quickly resume operations.

How Can My Organisation Build or Improve Cyber Resilience?

In today’s cyber environment, organisations must be prepared to battle through adversity and restore operations quickly. The case for cyber resilience has never been stronger. Organisations should take these four steps to help build cyber resilience into their operations and embed it within their culture.      

1.    Anticipate risk: Prepare, prepare, prepare! Preparation is the cornerstone of your cyber resilience plan. You can:

  • Determine the degree of contingent business interruption risk that exists within your organisation.
  • Use financial stress testing to learn how much stress your organisation can bear during and after a cyberattack.
  • Develop early warning metrics to enable more effective decision-making during an attack.
  • Consider your vendors and partners and create metrics that measure the potential security risks your supply chain partners pose.

2.    Align cyber risks with organisational strategy: Consider integrating your cyber risk management program with your organisation’s strategy. The Marsh Risk Resilience Report found that 25% of companies do not align risk and resilience planning and insurance buying with their long-term growth strategies. Key stakeholder alignment on cyber risk can help, but is often missing.

3.      Look for gaps: Assess how prepared your organisation actually is to withstand a cyberattack, and map that against the potential impact of an attack. There is often a misalignment between how an organisation views a risk and how prepared it is to manage that risk. While more than 90% of organisations consider cyber/technology risks important or highly important, only 18% of them feel highly prepared to manage cyber risk.

4.    Measure your cyber risk exposure: Take a holistic look at cyber risk across your organisation. Identify potential issues, and quantify your exposure in terms of their operational, financial, and reputational impacts.

While most organisations rank cyber as an important or highly important risk, less than one-third of organisations use scenario-based financial metrics to model cyber risk. And more than a quarter of organisations do not model cyber risk at all.

To learn how leading global organisations perceive risk and define resilience, as well as the actions they are taking to increase their resilience.