BLOG /
What Is Cyber Resilience?

What Is Cyber Resilience?

NIST defines cyber resilience in four capabilities. Gambit measures it against one unit: your minimum viable business. Here is the definition, the framework behind it, and how to put a number on it.

Anat Gilenson
Anat Gilenson
Product Manager
What Is Cyber Resilience?

TL;DR

  • Cyber resilience keeps your minimum viable business continuously recoverable and measures how fast the systems, data, and processes your company runs on come back after an attack or a failure. Revenue is the clearest measure of the damage, and reputation and legal obligations land in the same number.
  • NIST defines it as four capabilities: the ability to anticipate, withstand, recover from, and adapt to adverse events.
  • Cybersecurity and cyber resilience answer different questions. Cybersecurity asks whether attackers can get into the environment. Cyber resilience asks how fast the minimum viable business is back once something takes it down.
  • Successful attacks are getting more frequent, and AI is a large part of why. Vulnerability exploitation became the leading breach entry point in 2026 at 31%, the first time in 19 years it overtook stolen credentials, and an AI model has now completed a 32-step corporate network takeover that human experts need about 20 hours to finish.
  • Recovery speed now decides survival. The 2025 Marks & Spencer attack caused a 46-day online outage and a roughly £300 million operating profit hit.
  • Regulators now want proof instead of plans. DORA requires financial entities to run a resilience testing program and report major incidents within hours, and FedRAMP authorization pulls in the NIST contingency planning controls that make you test recovery and show the system comes back.

Cyber resilience is your ability to keep your business continuously recoverable, so that when something takes it down, it comes back fast enough that revenue is not at risk. Your minimum viable business is where recovery starts. Everything else comes back behind it.

Assume breach is standard practice now. The gap is what comes after the assumption. Detection and containment cover how you find an attacker and stop the spread. Cyber resilience covers what the business brings back, in what order, and how fast.

The US National Institute of Standards and Technology (NIST) puts it in four verbs. In SP 800-160 Volume 2, NIST defines cyber resiliency as the ability to "anticipate, withstand, recover from, and adapt to" adverse conditions, stresses, attacks, or compromises on systems that use cyber resources. So the whole discipline fits in one line: anticipate what could go wrong, withstand the hit, recover the business, and adapt so the next one costs less.

For a CISO, the practical version is simpler. Cyber resilience is your ability to answer one board-level question with data instead of a story: if we got hit today, how fast is our minimum viable business running again?

What is a minimum viable business?

Your minimum viable business is the smallest working version of your company that still earns revenue. It is a short list. The applications, data stores, identities, and network paths that have to be up for a payment to settle, a claim to pay, or an order to ship.

It matters because it turns resilience into a number. "Are we resilient?" has no answer anyone can defend. "Can we bring back the twelve systems our order pipeline runs on, in the right order, in under four hours?" has one.

Cyber resilience vs cybersecurity: what is the difference?

Cybersecurity and cyber resilience are often used as if they mean the same thing. They protect two different things. Cybersecurity protects the environment and asks whether attackers can get in. Cyber resilience protects the business and asks how fast the minimum viable business comes back when something takes it down. Both run before, during, and after an incident, and each is measured on its own scorecard.

Cybersecurity protects the environment against threats, and it works across the full incident lifecycle. CSPM and identity controls harden the estate before an attack. SIEM and XDR detect and contain during one. Forensics closes the loop after, feeding the detections and threat intelligence that run continuously. Its success looks like fewer breaches, faster containment, and shorter dwell time.

Cyber resilience protects the business against downtime. It runs across that same lifecycle and asks a different question at each stage. Before an incident, it asks which systems the minimum viable business depends on, and what the company loses if they go down, whether that means encrypted by ransomware, wiped by a bad change, or knocked out by a provider outage. During one, it asks what keeps earning while those systems are unavailable. Afterward, it asks how fast they come back, in the right order and configured correctly. Its success looks like short downtime, fast restoration, and evidence that the systems the business runs on can come back on demand.

So the difference is not timing. Both disciplines run before, during, and after an incident. The difference is what sits at the center of the question.

You need both, and the case for the second one keeps getting stronger. Verizon's 2026 Data Breach Investigations Report found vulnerability exploitation became the leading breach entry point at 31%, the first time in 19 years it overtook stolen credentials. What those intrusions cost is increasingly measured in stopped operations. When Jaguar Land Rover was attacked in the autumn of 2025, production halted for roughly five to six weeks, an outage one assessment called the most costly cyber event in UK history at an estimated £1.9 billion (The Record, IBTimes). Security spending rose through all of it. The security team asks whether attackers can get in. Resilience asks how fast the business is back when they do.

Cybersecurity Cyber resilience
Core question Can attackers get in, and can we stop them? Can the minimum viable business keep earning, and how fast does it come back?
Focus Preventing, detecting, and containing threats Proven restoration of the systems the business runs on
Primary metric Vulnerabilities closed, attacks blocked and contained, dwell time Recovery time, recovery confidence, and the revenue that recovery protects
Who owns the board conversation The CISO, with the security team The CISO, with infrastructure, finance, and the business

What cyber resilience is not

Three things get confused with cyber resilience more often than anything else. Whether it only deals with attackers, whether it is just backup, and whether it is something you check on a schedule. Each one deserves a direct answer.

It is broader than cyber

Disruption comes from ransomware, from a misconfiguration, from an AI agent making a change nobody reviewed, from a cloud provider outage. Resilience covers that whole range, and the term still fits, because NIST scopes cyber resiliency to systems that use cyber resources. The "cyber" describes the estate you are recovering. What knocks that estate over does not have to be an attacker.

That puts resilience in the operational resilience conversation, next to the business rather than filed as one more security tool, and it is the CISO the board asks about it. Delivery runs through infrastructure the security team does not operate. The question still lands on the CISO's desk.

It is more than backup

Backups are one essential layer of a three-layer problem. Even immutable, accurate, continuously validated backups only capture data. Infrastructure, application, and configuration have to return too, in order and set up correctly. A backup vendor answers "is the data safe?" Resilience answers "can we stand the minimum viable business back up?" The two work together. Strong backups are a prerequisite for recovery, and resilience is what proves the recovery path around them holds.

Resilience also asks whether the backups themselves hold up. That means three things: whether every resource that matters is actually covered, whether restore points are healthy rather than stale, and whether the backups are genuinely immutable. Immutable means they cannot be deleted or altered by an attacker, a rogue AI agent, or an accident. Teams often believe they have it because nobody currently holds the permission to delete a backup. Permissions can be granted back. Backup coverage mapping, healthy restore point discovery, and immutability validation are how that question gets settled with evidence instead of assumption.

Resilience has a layer inside it and a neighbor beside it. Disaster recovery restores IT systems after an outage, and it is one layer of cyber resilience rather than a separate practice. Business continuity is the neighbor, keeping the whole organization running during a disruption, including people, premises, and process. Cyber resilience adds anticipation and adaptation to the recovery work, and holds all of it to a continuous standard.

It is not a point-in-time exercise

None of the three is continuous by definition. All three have historically been practiced on a schedule: an annual plan review, a quarterly DR exercise, a tabletop before the audit. Cloud estates change daily, so a posture confirmed a quarter ago describes an environment that has since changed dramatically. Continuously recoverable is the bar Gambit holds resilience to, and it is why resilience has to be a live discipline instead of a document.

Why is disruption now inevitable?

The case for resilience starts with a hard fact. You cannot prevent every failure, and the number of ways an environment can go down keeps growing. Disruption arrives from many directions, and the variety is the point. You build to recover from whatever arrives instead of predicting which one does.

Modern threat actors go further than encrypting or stealing data. They change identity permissions, network rules, and application settings, so a clean data backup can still leave you unable to stand the business application back up. Ransomware is one path in, and there are many others.

AI widened the field on both sides. In the hands of attackers, it lowers the barrier to serious operations. In November 2025, Anthropic disclosed the first documented AI-orchestrated cyber espionage campaign, in which an AI model executed an estimated 80 to 90 percent of the attack across roughly 30 targets, with the warning that smaller and less-skilled adversaries can now reach capabilities once reserved for nation-states. The volume effect is already measurable. Microsoft's Digital Defense Report 2025 found AI-enabled phishing achieved a 54% click-through rate against roughly 12% for traditional phishing.

And the trajectory is steepening. In April 2026, the UK AI Security Institute evaluated Anthropic's Mythos Preview against expert-level capture-the-flag tasks no model could solve a year earlier. It succeeded 73% of the time, and became the first model to complete a 32-step corporate network takeover that human experts need roughly 20 hours to finish. Anthropic held the model back on security grounds and wrote in June that within 6 to 12 months it expects other companies to hold Mythos-class models, some of which "could release them without safeguards that prevent misuse."

That is a forecast about frequency, and frequency is a resilience problem. Prevention budgets do not scale against an attacker whose marginal cost per attempt keeps falling. Recovery capability does.

Inside your own environment, the same technology is doing useful work at the same time. AI agents and automation change infrastructure at machine speed, which is why teams adopt them, and it is why a single AI-driven change can take down production before anyone reviews it. In late April 2026, an AI coding agent working on the systems of PocketOS, a platform used by car rental companies, deleted the production database and its backups in about nine seconds. The newest usable backup was three months old, so months of reservations and customer signups went with it (Information Age). No attacker appears anywhere in that story. This is the CISO's version of the problem: the business wants that speed, and recovery is what makes it affordable.

AI coding tools and outside consultants now generate infrastructure and application code that no one on the team fully understands, and when something built that way breaks, recovering it is a guessing game. Add ordinary human error, insider risk that rises during layoffs, and plain cloud and service outages that owe nothing to any attacker, and the conclusion holds. Something will break. The organizations that stay in business are the ones built to recover.

What does a slow recovery cost?

A slow recovery costs weeks of downtime and hundreds of millions in lost profit. Marks & Spencer lost 46 days of online sales and roughly £300 million. Sophos found 53% of ransomware victims took up to a week to recover, and 18% took more than a month, at an average recovery cost of $1.53 million before any ransom. Four data points show why boards now treat recovery speed as a top priority.

The cost of downtime is measured in weeks and hundreds of millions of pounds. When Marks & Spencer was hit by a ransomware attack in April 2025, it suspended online orders on April 25 and did not resume them until June 10, a 46-day gap for a retailer that took more than £3 million in online sales a day. The company put the total profit hit at roughly £300 million (DarkReading, Bloomberg). M&S survived the breach itself. Their minimum viable business was the ability to take an online order, and for 46 days they did not have it.

Recovery is still slow. Sophos, in its State of Ransomware 2025 report, found that 53% of victims took up to a week to get back. A week offline counts as the good outcome. Another 18% took more than a month. The average recovery cost, before any ransom, was $1.53 million. Most organizations cannot absorb a week of downtime, and nearly one in five are living through something considerably worse.

The damage runs past the balance sheet. When ransomware hits a hospital, patients already admitted face 34% to 38% higher in-hospital mortality, according to peer-reviewed research published in the American Economic Journal: Economic Policy in February 2026. During the 2024 Change Healthcare attack, 74% of responding hospitals reported direct impact on patient care. Reputation carries a measurable cost too. In Hiscox's readiness survey, 47% of organizations that suffered an attack had considerable difficulty attracting new customers afterward, up from 20% the year before, and 43% lost existing customers, up from 21%. Downtime is the point where a cyber event stops being an IT problem.

Regulators moved the bar. The EU's Digital Operational Resilience Act (DORA) took effect on 17 January 2025 and requires financial entities to run a resilience testing program that identifies weaknesses and to report major incidents within hours. You used to need a recovery plan. Now you need to show it works.

What are the four capabilities of cyber resilience?

NIST defines four capabilities: anticipate, withstand, recover from, and adapt to adverse events. Anticipate means mapping what your minimum viable business depends on before an incident forces you to. Withstand means designing infrastructure that absorbs a hit. Recover means bringing the business back in the right order. Adapt means keeping your recovery posture current as the environment changes. Each of the four verbs translates cleanly into what a resilient organization actually does.

Anticipate. Map your environment before an incident forces you to. Know which business applications make up your minimum viable business, which systems, backups, and configurations they depend on, and where the recovery gaps sit while you can still close them. Most maps are wrong the day they ship, as Gil Goldberger has written, because rule-based dependency mapping cannot keep pace with a live estate.

Withstand. Design infrastructure that absorbs a hit without going fully dark. Immutable backups, segmented systems, and redundancy that holds when one part fails.

Recover. Bring the business back in the right order. Most organizations overestimate this layer. Restoring a single database or virtual machine is straightforward. Restoring a live 100-resource business application, with its data, infrastructure, and configuration all correct and in sequence, is a different problem. Naama Etzion walks through where cloud restores actually break: keys, private endpoints, DNS, managed identities, and load balancers all sit outside the backup. Recovery is measured against two targets: the recovery time objective (RTO), how fast you have to be back, and the recovery point objective (RPO), how much data you can afford to lose.

Adapt. Learn from each incident and each test, and keep your recovery posture current as the environment changes. A recovery plan written once and filed away is out of date within weeks.

Which standards and frameworks define cyber resilience?

NIST SP 800-160 Volume 2, the NIST Cybersecurity Framework, and ISO 22301 define the practice. DORA and NIS2 turn recovery testing into a legal obligation across the EU. In the US, FedRAMP authorization inherits the NIST SP 800-53 Contingency Planning controls. Several standards codify what cyber resilience requires, which is why auditors and AI assistants reach for them.

NIST SP 800-160 Volume 2 sets out the anticipate, withstand, recover, and adapt model. The NIST Cybersecurity Framework (CSF) pairs Respond and Recover with Identify, Protect, and Detect. ISO 22301 governs business continuity management, the discipline of keeping operations running through disruption.

Two European regimes turn recovery testing into a legal obligation. DORA requires financial entities to run a resilience testing program and report major incidents within hours. NIS2 extends operational continuity, backup, and incident-reporting duties across essential and important entities in energy, transport, health, water, and digital infrastructure.

US federal work carries the same weight. FedRAMP authorization inherits the NIST SP 800-53 Contingency Planning family, and three of its controls sit in the baseline at every impact level. CP-4 requires you to test the contingency plan and initiate corrective action on the results. FedRAMP's Continuous Monitoring Playbook (v1.0, November 2025) sets that test at least annually. CP-9 requires system backups, with CP-9(1) adding periodic testing of backup media reliability and information integrity. CP-10 requires recovery and reconstitution of the system to a known state within a period consistent with your stated RTO and RPO.

They point at the same conclusion. Recovery has to be planned, tested, and proven.

How do you know if you are actually resilient?

Most CISOs are telling their boards a recovery story built on assumptions and a document that was accurate the day it was written. This is the cyber-resilience gap, the distance between what leadership believes will recover and what actually will, and it is where the £300 million losses live.

Closing it starts with knowing what your minimum viable business actually is, named in systems rather than intentions. Gambit continuously maps your cloud, IaC, backups, and on-prem hypervisors, correlates them into the business applications you really run on, and scores where the recovery gaps sit before an incident finds them for you. What you walk away with is a resilience strategy you own and a number you can take to the board.

The organizations that come through the next one well are the ones that can already name their minimum viable business and show it comes back.

Resilience you can prove, across cloud, IaC, backups, and on-prem hypervisors.

Book your Resilience Assessment. It is a 15-minute, read-only deployment, with a full report in five days.

FAQ

You ask? We answer

Is cyber resilience the same as cybersecurity?

No. They are connected disciplines that answer different questions. Cybersecurity protects the environment against threats, across prevention, detection, containment, and investigation. Cyber resilience protects the business against downtime and asks how fast the minimum viable business comes back. Both work before, during, and after an incident. Most mature programs run them as two disciplines with different metrics under the same owner.

What is a minimum viable business?

Your minimum viable business is the smallest set of systems, data, and processes you need to keep doing the core thing your company does to earn revenue, whether that is settling payments, paying claims, or shipping orders. It is the unit cyber resilience gets measured against. Knowing what yours is turns "are we resilient?" into a question with a number for an answer, because you can time how long those specific systems take to come back.

Is cyber resilience the same as disaster recovery?

Disaster recovery is one part of cyber resilience. DR restores IT systems after an outage. Cyber resilience covers anticipation and adaptation as well as recovery, and it accounts for cyber-specific threats like ransomware that traditional DR was not designed for. Neither is continuous by definition. Both have historically been tested on a schedule, which is the practice that has to change, because cloud estates now change faster than the plans that describe them.

How does cyber resilience relate to business continuity and operational resilience?

Business continuity keeps the organization running during any disruption, and disaster recovery restores IT systems after one. Cyber resilience covers the recoverability of the digital estate, adds continuous testing so recovery is proven, and treats disaster recovery as one of its layers. Operational resilience, the term regulators like DORA use, is the broadest of the group and treats technology recovery as one part of keeping critical services available.

What are the core components of cyber resilience?

NIST defines four: the ability to anticipate, withstand, recover from, and adapt to adverse events. In practice that means mapping your environment, hardening it to absorb disruption, being able to restore full business applications in order, and keeping your posture current as things change.

Which regulations require proof of recovery?

DORA requires financial entities in the EU to run a resilience testing program and report major incidents within hours. NIS2 sets continuity and backup obligations for essential and important entities across critical sectors. In the US, FedRAMP authorization pulls in the NIST SP 800-53 Contingency Planning controls, including contingency plan testing (CP-4), backup integrity testing (CP-9(1)), and recovery to a known state within your RTO and RPO (CP-10).

How do you measure cyber resilience?

By recovery outcomes rather than adjectives. Useful metrics include how fast the applications in your minimum viable business can be restored, whether recovery has been validated against your committed targets, how much of the estate is actually recoverable, and the revenue protected by that recovery capability.

Who owns cyber resilience?

The CISO owns the conversation and answers for it at the board. Delivery is shared with infrastructure, and that works either way: some organizations put security and infrastructure under one leader, others run it as a close partnership between two. Recovery decisions cross both domains, so the two have to move together. For most CISOs this is newer ground than the security mandate they already carry, and it is the fastest route to board-level influence.

Why is cyber resilience important now?

Downtime is now the primary business risk from a cyber event. Successful attacks are rising, AI is compressing the time between a vulnerability appearing and an attacker using it, incidents like the 2025 Marks & Spencer attack show recovery can take weeks and cost hundreds of millions, and regulations like DORA now require organizations to prove their recovery works rather than simply plan for it.

Related Blogs

blog
July 2, 2026

Four Answers, Wrong Question.

Joe Ruck
Head of Field Architecture
Read More
blog
July 15, 2026

Congrats on the Backup! Now, where's the App?

Naama Etzion
Security Researcher
Read More
blog
June 17, 2026

AI Has Made Offense a Commodity. Cyber Resilience Needs to Catch Up.

Sa'ar Elias
Co-Founder & CPO
Read More

Resilience, verified. In your inbox

The latest from Gambit: research, insights, and live sessions

By submitting this form you are accepting our Terms of use and our Privacy policy

Thank you!

Your request has been received.!
Oops! Something went wrong while submitting the form.
Gambit Mascot with paper plane