IT staff working in data center showing cyber resilience

Why Prevention Alone Doesn’t Make an Organization Cyber Resilient

Cyber resilience has become the industry’s favorite word, but few of the organizations using it can show they would survive a destructive attack.

Walk the floor of any security conference this year and count the booths promising resilience. Read the annual reports of large enterprises and the word appears again, usually next to firewalls, endpoint detection, phishing training, and a zero trust program. Every one of those investments is worthwhile, but none of them on their own makes an organization resilient.

In many boardrooms, “cyber resilience” now means “a lot of cybersecurity.” That drift is expensive, because it lets organizations claim a capability they have never demonstrated.

What resilience means

Resilience is the ability to keep operating through a disruption and return to normal operations afterward. That definition carries two obligations. You have to absorb the hit, and you have to come back from it. Prevention addresses neither directly. It just lowers the odds of the hit arriving.

The major frameworks draw the same line. NIST’s Cybersecurity Framework 2.0 treats Recover as its own core function, separate from Protect and Detect, because the work is different. Gartner now advises security leaders to define success around resilience rather than prevention, since resilience can be tested and measured. Perfect prevention can’t be proven. A quiet quarter looks identical whether your controls worked or the attackers were busy elsewhere.

A prevention program measures how hard it is to get in. A resilience program has to answer the questions of, if an attacker destroys this environment tonight, how many hours until the business operates again and what evidence supports that number?

Why the confusion persists

Prevention is easy to count. Patch rates, endpoint coverage, mean time to detect, and phishing click rates come straight out of existing tools and fit neatly on a dashboard. Recovery produces no numbers unless someone deliberately tests it, and a full restore exercise disrupts every team it touches, security, infrastructure, application owners, business units, without any one of them owning it. So organizations report what they can measure and call it resilience.

Why recovery decides the outcome

The largest cost driver is downtime, not the incident itself. Ransom, forensics, and legal fees are largely fixed once an incident begins. Interruption losses are the variable, and they climb with every hour the system stays down. Recovery speed is what ultimately decides the final bill.

For privacy leaders, the exposure goes beyond revenue. An organization that cannot restore its systems struggles to confirm which personal data was affected, to meet notification deadlines with confidence, or to show regulators what happened. Those regulators increasingly want the restore, not the plan. New York’s amended DFS cybersecurity regulation requires annual testing of the ability to restore critical systems from backups. The EU’s Digital Operational Resilience Act requires financial entities to test their backup and restoration procedures.

Recovery also runs against an adversary. Traditional disaster recovery assumes an honest failure. A flood doesn’t steal admin credentials, ransomware operators do.  They routinely go after backup systems and directory services first, well before they ever encrypt a file. If the backup console authenticates through the same directory the attacker already controls, the organization owns backups it may be unable to use.

Testing the claim

An organization earns the label resilient when it can show three things. It knows which business services must come back first and what each depends on, including identity systems, network paths, and third parties. Its backups are isolated from the credentials an attacker would seize. And it has restored those services end to end within the past year, against its stated recovery time objectives, with results leadership has reviewed.

Anything short of that is a prevention program with a better name. Prevention reduces how often the worst day arrives. Recovery sets how long that day lasts, what it costs, and how much data and customer trust the organization loses before it ends. Organizations that want to claim resilience should be ready to show the restore path.