Cyber resilience: do boards fall short?

Image of empty boardroom

How resilient are organisations in the face of cyber attacks, and can they recover effectively?

The answer could be less well than we think.

A recent survey suggests that, in the UK at least, boards overestimate their organisations’ ability to withstand a breach. And they overstate their ability to recover from an incident, and restore operations even to a minimum viable state.

This is worrying, not least because resilience is increasingly mandated by legislation. And the reputational costs of outages can be extremely high.

But what does overconfidence when it comes to cyber resilience mean for practical security? And does it increase risk?

Pressure, from regulators, law makers, and even shareholders and investors is force boards to take cyber resilience more seriously. But there is a way to go before it is at least on par with conventional business continuity and disaster recovery plans.

Our guests for this episode work at a managed security service provider and a unified communications company respectively, so are well-placed when it comes to the views of CIOs and CISOs. Paul Cragg is CTO at NormCyber, and Richard Beeston is chief operating officer at Digital Space.

They discuss the cyber resilience confidence gap, and how the solution might lie in seeing cybersecurity less as simply a cost, and more as core to business operations.

Featured image by Mariakray from Pixabay