There are few walks of life where readiness is proven by paperwork alone. Yet when it comes to cyber security, many organizations still equate compliance filings with capability. This has created a dangerous gap between confidence and capability.
Immersive research recently found that 94% of organizations believe that they’re ready to tackle a serious cyber incident, but just 22% of crisis decisions are correct, and incidents take an average of 29 hours to contain.
It’s an easy trap to fall into. Passing an audit or ticking off a checklist offers a sense of control that is hard to come by in the nebulous world of cyber threats. But this route can quickly end up measuring effort instead of preparedness; and when a real cyber attack hits, that comfort can evaporate in minutes.
The latest wave of regulations is changing how resilience is judged. They require proof, not promises, hard evidence that organizations can withstand and recover from disruption. That shift extends far beyond the IT department. Boards, investors, and insurers now see cyber readiness as a defining measure of organizational strength and the ability to protect value when it matters most.
How regulation is redefining what resilience looks like
Across Europe and the UK, a new generation of regulation is reshaping what it means to be resilient. Under the EU’s Digital Operational Resilience Act (DORA), financial entities must maintain a full ICT risk management framework, carry out business impact analyses, and run regular digital operational resilience testing, including threat-led penetration exercises every three years for critical firms.
The NIS2 Directive extends this principle to a much broader set of essential and important sectors, making senior management directly accountable for demonstrating that their organizations can respond and recover from major incidents.
The UK’s upcoming Cyber Security and Resilience Bill is expected to follow suit, placing continuous improvement and board-level responsibility into law.
Simply keeping policies up to date is not enough in this era. Organizations must be able to provide evidence that the organization can keep operating when disruption hits. Keeping in the good books of both regulatory bodies and the court of public opinion requires senior leadership to be confident that the company did everything it reasonably could to prepare for an incident.
Why Boards struggle to see true cyber resilience
Boards have long struggled to see the real picture of cyber resilience. Security teams tend to report on what’s easy to count – how many employees completed training, how quickly patches were applied, and how many audits were passed. These numbers show effort, but they rarely show performance when the pressure is on.
It’s an understandable gap. Boards want reassurance, and security teams are used to reporting activity that feels measurable. But compliance data doesn’t tell you how people will behave when an incident strikes at 2 a.m., or how quickly a leadership team can make the right call with incomplete information.
Much training focuses on past threat examples, which are often out of date. Again, it looks good on paper, but risks leaving teams unprepared for the latest tactics.
With regulators now creating an external demand for demonstrable capability, this gap has become harder to ignore. Boards need a way to see cyber resilience the same way that they see financial or operational risk – through evidence-based indicators that show how well the organization performs when theory is replaced by reality. Cyber readiness metrics provide Boards with this information.
Turning crisis into evidence
The only way to know how people respond in a crisis is to give them the chance to prove it. Cyber simulations and crisis exercises are one of the most effective ways of achieving this, turning theory into experience and allowing teams to practise under realistic conditions before the stakes are real.
In a genuine crisis, unexpected challenges can emerge, communication can falter, and snap decisions must often be made before all the facts are known.
A simulation exercise can accurately capture these surprises and pressures.
These moments reveal more than any audit ever could – how quickly threats are detected, how clearly information is shared, and how confidently decisions are made when time is short. They expose gaps in escalation paths, coordination, and confidence that no policy document can predict.
As helpful as experiencing a simulated crisis can be, the real value comes after the exercise. A structured debrief transforms experience into improvement, giving teams clear insight into what worked and what didn’t. Each cycle of testing and reflection helps build maturity, strengthening not just technical defences but the leadership and judgement that define resilience in practice.
Data-driven readiness builds board confidence
With simulations generating data, readiness becomes something we can measure. Each exercise produces concrete results – how fast a threat was identified, how long recovery took, and how well communication flowed. Tracking this over time can demonstrate genuine progress and gives leaders a reliable way to evidence improvement.
By aggregating these findings, organizations can calculate what my organization calls a resilience score – a clear, accessible snapshot of how the business performs under pressure. It highlights strengths, pinpoints where investment is needed, and shows how resilience evolves over time. This gives a consistent, evidence-based measure of performance that boards can trust.
When leadership can point to data that shows progress, it replaces uncertainty with confidence. Instead of offering reassurance, we can demonstrate results. That transparency builds trust with shareholders, regulators, and insurers – showing that cyber risk is being managed with the same discipline and accountability as any other area of the business.
True resilience isn’t a milestone; it’s a mindset. It depends on constant testing, learning, and improvement. Regulations set the minimum standard, but genuine readiness comes when these principles become routine. In resilience, confidence doesn’t come from assuming you’re ready, but from proving it, time and again.
The author
Dan Potter is Senior Director, operational resilience at Immersive






