Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Cyber resilience»Cyber readiness: the new resilience metric that boards will soon be demanding (Page 12)
Cyber resilience

Cyber readiness: the new resilience metric that boards will soon be demanding

Cyber security and resilience metrics often focus on easily quantifiable activity and can create misplaced confidence in organizational capability. Dan Potter examines more evidence-based approaches to measuring true cyber readiness.
February 11, 20265 Mins Read
Digital analytics interface with graphs and charts for data analysis.

There are few walks of life where readiness is proven by paperwork alone. Yet when it comes to cyber security, many organizations still equate compliance filings with capability. This has created a dangerous gap between confidence and capability.

Immersive research recently found that 94% of organizations believe that they’re ready to tackle a serious cyber incident, but just 22% of crisis decisions are correct, and incidents take an average of 29 hours to contain.

It’s an easy trap to fall into. Passing an audit or ticking off a checklist offers a sense of control that is hard to come by in the nebulous world of cyber threats. But this route can quickly end up measuring effort instead of preparedness; and when a real cyber attack hits, that comfort can evaporate in minutes.

The latest wave of regulations is changing how resilience is judged. They require proof, not promises, hard evidence that organizations can withstand and recover from disruption. That shift extends far beyond the IT department. Boards, investors, and insurers now see cyber readiness as a defining measure of organizational strength and the ability to protect value when it matters most.

How regulation is redefining what resilience looks like

Across Europe and the UK, a new generation of regulation is reshaping what it means to be resilient. Under the EU’s Digital Operational Resilience Act (DORA), financial entities must maintain a full ICT risk management framework, carry out business impact analyses, and run regular digital operational resilience testing, including threat-led penetration exercises every three years for critical firms.

The NIS2 Directive extends this principle to a much broader set of essential and important sectors, making senior management directly accountable for demonstrating that their organizations can respond and recover from major incidents.

The UK’s upcoming Cyber Security and Resilience Bill is expected to follow suit, placing continuous improvement and board-level responsibility into law.

Simply keeping policies up to date is not enough in this era. Organizations must be able to provide evidence that the organization can keep operating when disruption hits. Keeping in the good books of both regulatory bodies and the court of public opinion requires senior leadership to be confident that the company did everything it reasonably could to prepare for an incident.

Why Boards struggle to see true cyber resilience

Boards have long struggled to see the real picture of cyber resilience. Security teams tend to report on what’s easy to count – how many employees completed training, how quickly patches were applied, and how many audits were passed. These numbers show effort, but they rarely show performance when the pressure is on.

It’s an understandable gap. Boards want reassurance, and security teams are used to reporting activity that feels measurable. But compliance data doesn’t tell you how people will behave when an incident strikes at 2 a.m., or how quickly a leadership team can make the right call with incomplete information.

Much training focuses on past threat examples, which are often out of date. Again, it looks good on paper, but risks leaving teams unprepared for the latest tactics.

With regulators now creating an external demand for demonstrable capability, this gap has become harder to ignore. Boards need a way to see cyber resilience the same way that they see financial or operational risk – through evidence-based indicators that show how well the organization performs when theory is replaced by reality. Cyber readiness metrics provide Boards with this information.

Turning crisis into evidence

The only way to know how people respond in a crisis is to give them the chance to prove it. Cyber simulations and crisis exercises are one of the most effective ways of achieving this, turning theory into experience and allowing teams to practise under realistic conditions before the stakes are real.

In a genuine crisis, unexpected challenges can emerge, communication can falter, and snap decisions must often be made before all the facts are known.

A simulation exercise can accurately capture these surprises and pressures.

These moments reveal more than any audit ever could – how quickly threats are detected, how clearly information is shared, and how confidently decisions are made when time is short. They expose gaps in escalation paths, coordination, and confidence that no policy document can predict.

As helpful as experiencing a simulated crisis can be, the real value comes after the exercise. A structured debrief transforms experience into improvement, giving teams clear insight into what worked and what didn’t. Each cycle of testing and reflection helps build maturity, strengthening not just technical defences but the leadership and judgement that define resilience in practice.

Data-driven readiness builds board confidence

With simulations generating data, readiness becomes something we can measure. Each exercise produces concrete results – how fast a threat was identified, how long recovery took, and how well communication flowed. Tracking this over time can demonstrate genuine progress and gives leaders a reliable way to evidence improvement.

By aggregating these findings, organizations can calculate what my organization calls a resilience score – a clear, accessible snapshot of how the business performs under pressure. It highlights strengths, pinpoints where investment is needed, and shows how resilience evolves over time. This gives a consistent, evidence-based measure of performance that boards can trust.

When leadership can point to data that shows progress, it replaces uncertainty with confidence. Instead of offering reassurance, we can demonstrate results. That transparency builds trust with shareholders, regulators, and insurers – showing that cyber risk is being managed with the same discipline and accountability as any other area of the business.

True resilience isn’t a milestone; it’s a mindset. It depends on constant testing, learning, and improvement. Regulations set the minimum standard, but genuine readiness comes when these principles become routine. In resilience, confidence doesn’t come from assuming you’re ready, but from proving it, time and again.

The author

Dan Potter is Senior Director, operational resilience at Immersive

Africa Asia Asia Pacific Australasia Europe Middle East North America UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleWhy ‘prove it’ will become the new compliance baseline for AI in 2026
Next Article Failure in human-in-the-loop design is an emerging enterprise risk

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
A batch of Euro notes, some which are showing signs of being burned. Image © De Nederlandsche Bank - used under media permissions.

Identifying scenarios of interest under deep uncertainty

April 21, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?