Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Cyber resilience»Calm before the cyberstorm? Evolving threats show that complacency is the real resilience risk (Page 4)
Cyber resilience

Calm before the cyberstorm? Evolving threats show that complacency is the real resilience risk

Magnus Jelen examines the forces driving complacency in cyber resilience and offers a practical checklist for shifting from compliance to genuine capability.
January 30, 20267 Mins Read
Cyberstorm matrix: a hackers face emerges from a digital matrix.

No one enters the cybersecurity sector expecting serenity. The pace is relentless, and the stakes are high. According to the World Economic Forum, the weekly number of cyberattacks has more than doubled over the past four years, now hovering just below 2,000. That figure might seem exaggerated until you consider how many high-profile breaches have made headlines recently – and those are just the ones we know about.

What’s more concerning is the speed at which attacks are evolving. AI, once a theoretical threat, is now a practical weapon. Phishing techniques have become disturbingly sophisticated and attackers are even weaponising chatbots to develop malicious code as they innovate at pace.

Thankfully, many governments have responded with commendable urgency. New regulations are emerging across the globe and law enforcement has successfully dismantled several major threat groups. But these victories can be misleading. They create a sense of calm that’s not only temporary but dangerous. Cyber threats are not vanishing – instead, attackers are adapting.

No getting off this ride

The one constant in cybersecurity is change. Recently, it seemed like the industry was on a big high, with major cyberthreat groups like LockBit, Black Cat, and Black Basta either being shut down, disappearing, or simply ceasing operations. Across Europe, we have seen two major cybersecurity regulations in the form of NIS2 and DORA, seeking to improve resilience for organizations in general and for the particularly hard-hit financial sector. Some countries even took steps towards more decisive measures. In the UK, consultation was carried out on a potential ransomware payments ban for critical national infrastructure and public sector organizations. Taken alone, you could almost forgive organizations for thinking they could take their foot off the gas a little.

But there have been plenty of lows too. In recent months, we’ve seen a spree of successful attacks across Europe, most notably targeting the retail sector. While ransomware payments might have dropped again, it doesn’t mean that attackers are going away. The takedown of established groups opened up room for smaller groups and even individual ‘lone wolves’. With these new attackers comes a whole new set of motives. Money might still be a driver, but many of these newcomers are more focused on targets that can cause the most disruption, rather than who might pay the biggest ransom. Today, you can split the market largely in two. Those high-cost, targeted attacks are still very much present, aiming at larger enterprises with deeper pockets. But on the other side, you’ve got volume-driven Ransomware-as-a-Service attacks, driven by smaller groups and lone wolves, aiming to create as much chaos as possible.

So, while on the surface it might seem like an improved landscape, the same threats are still very much present, and new ones are already here.

Making the right choices

Luckily, regulation hasn’t just sat still in the face of this. As already mentioned, in the EU alone, we’ve had two major regulations, NIS2 and DORA, both targeting data resilience. NIS2 has been particularly impactful, enshrining resilience squarely as a responsibility for the C-suite. No longer can organizations push resilience into the corner; now senior leadership must actively manage cybersecurity risks, making it as much of a business priority as profit and strategy. NIS2 has also introduced new standards for organizational risk management and mitigation and incident reporting in particular, an essential element with attacks on the rise. While DORA is restricted to the financial services sector, it addresses some of the most pressing issues, like third-party risk, in an attempt to bolster one of the most targeted sectors.

Despite the measures required being essential for developing mature data resilience that can withstand the current pressures from threat actors, compliance is easier said than done. When so much work is needed to reach compliance, the response is often to stop when the compliance threshold is reached. But it’s vital to remember that being compliant does not equal being secure.

Keeping moving

Right now, organizations are sitting in the middle of a perfect storm. Big-name takedowns are lulling leaders into a false sense of security, while new attackers emerge from the wings using new and improved tools. And the focus on regulatory compliance creates the risk of obscuring the true scope of improvements that could be made to data resilience.

In times like this, organizations need to turn their attention inwards. Rather than scrambling to react to attacks with one hand, while also trying to meet compliance deadlines and keep day-to-day operations running smoothly with the other, they should try a different approach.

Using data resilience maturity models, organizations can not only better understand their current data resilience level but also create a path to improve it. Instead of looking at every aspect of data resilience separately, these models bring them together, focusing efforts and creating a tide that lifts all boats, rather than the more typical patchwork approach to resilience.

With attacks more frequent than ever and with attackers arguably as unpredictable as they’ve ever been, special attention also needs to be paid to recovery. While having mature data resilience should always be ‘Plan A’, your recovery ‘Plan B’ needs to be just as developed, if not more so. Data resilience is a journey that can’t be completed overnight and attackers won’t wait until you get yours up to scratch before they strike.

Ask yourself – right now – how long would it take your organization to recover from an attack? Take a long, hard look at the answer and if you wouldn’t be able to wait that long without a severe business impact, perhaps you need to take a look at your recovery plan before the storm hits.

Where to start: a cyber resilience checklist

Unsure where to begin? Well, there are a few places to start:

  • Make data resilience a board-owned priority: ensure that the board oversees a clearly defined data-protection mandate, reflecting the strategic importance of safeguarding business-critical information.
  • Demand verifiable backup immutability and rapid recoverability: prioritise immutable backups, tiered recovery strategies, and automated verification to guarantee clean, recoverable data after an attack.
  • Ensure ransomware-ready architecture across all environments: establish consistent resilience standards across all workloads.
  • Validate that recovery speed meets business-risk tolerance: implement recovery time and recovery point objectives that align with operational and financial risk thresholds – and regularly test and validate these.
  • Strengthen identity controls to protect the backup layer: mandate multifactor authentication, role-based access, and separation of duties across backup and recovery tools to bolster the last line of defence.
  • Test, test, and test again: schedule regular resilience exercises such as ransomware simulations and executive tabletop sessions to validate the real-world ability to recover quickly and cleanly. Board and leadership teams should be involved in these to build confidence navigating the response to a cyber incident, especially under pressure.
  • Maintain visibility across the full data ecosystem: ensure comprehensive oversight of data flows, storage, and third parties to build a full picture across the ecosystem.
  • Link cyber resilience directly to operational continuity: align security, IT operations, and business continuity teams under a unified plan for fast recovery.
  • Track metrics that reflect real recoverability: introduce key performance indicators tied directly to backup success rates, recovery verification, dwell time before detection, and total time-to-restore.
  • Promote a resilience-first culture: lead from the front to embed awareness, accountability, and preparedness as a shared responsibility, not just an IT concern.

While the above is by no means a comprehensive guide, these points should help to identify and address any key gaps in your data resilience.

The author

Magnus Jelen is Lead Director of Incident Response UK & EMEA, Coveware by Veeam

Africa Asia Asia Pacific Australasia Europe Middle East North America UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleIs WhatsApp’s new Strict Account Settings option a turning point for crisis communications?
Next Article Forescout’s 2025 Threat Roundup shows that attack infrastructure and tactics have evolved quickly

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
A woman with blonde hair and a ponytail looking at colourful sticky notes on a wall.

The stories behind the organization: how cultural narratives shape resilience

August 7, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?