[Blog](/blog)

Show links

Resources

[Blog](/blog)

[Breaches](/breaches)

[eBooks, reports, & more](/resources)

[Events](/events)

[News](/news)

[Attack Surface Management](/category/attack-surface-management)

Show links

Categories

[Attack Surface Management](/category/attack-surface-management)

[Company News](/category/company-news)

[Compliance and Regulations](/category/compliance-and-regulations)

[Cybersecurity](/category/cybersecurity)

[Data Breaches](/category/data-breaches)

[DevOps](/category/devops)

[Human Cyber Risk](/category/human-cyber-risk)

[Risks and Vulnerabilities](/category/risks-and-vulnerabilities)

[Third-Party Risk Management](/category/third-party-risk-management)

[Vendor Risk Management](/category/vendor-risk-management)

[What is Cyber Resilience?](/blog/cyber-resilience)

Publish date

July 4, 2025

{x} minute read

# What is Cyber Resilience?

[Get a demo](/contact-sales)

[Free trial](/demo)

[Download the PDF guide](/resources/the-itil-guide-to-cyber-resilience)

[Free trial](/demo)

Written by

[Abi Tyas Tunggal](/team/abi-tyas-tunggal)

Writer and Senior Product Manager at UpGuard.

Abi's work has influenced leaders across cybersecurity, technology, and financial services.

Reviewed by

[Kaushik Sen](/team/kaushik-sen)

Chief Marketing Officer

Kaushik has a background in software engineering, enterprise solution architecture, and data analytics. He brings a unique, data-driven perspective to cybersecurity education.

Table of contents

eBook

The ITIL Guide to Cyber Resilience

Free resource

### The ITIL Guide to Cyber Resilience

[Download now](/resources/the-itil-guide-to-cyber-resilience)

Cyber resilience is your ability to prepare for, respond to, and recover from [cyberattacks](https://www.upguard.com/blog/cyber-attack) and [data breaches](https://www.upguard.com/blog/data-breach) while continuing to operate effectively. 

An organization is cyber resilient when they can defend against [cyber threats](https://www.upguard.com/blog/cyber-threat), have adequate [cybersecurity risk management](https://www.upguard.com/blog/cybersecurity-risk-management), and can guarantee [business continuity](https://www.upguard.com/blog/business-continuity-plan) during and after cyber incidents.  

Cyber resilience, alongside [attack surface management](https://www.upguard.com/blog/attack-surface-management), has emerged over the past few years because traditional security controls such as [penetration testing](https://www.upguard.com/blog/penetration-testing) and security questionnaires are no longer enough to minimize [cyber risk](https://www.upguard.com/blog/cybersecurity-risk).

The objective of cyber resilience is to maintain your ability to deliver goods and services at all times. This can include the ability to restore regular mechanisms, as well as the ability to continuously change or modify mechanisms on an as-needed basis even after regular mechanisms have failed, such as during a crisis or after a security breach.

## Why is Cyber Resilience Important?

[Cyber resilience is important](https://www.upguard.com/blog/what-is-the-digital-operational-resilience-act) because traditional security measures are no longer enough to ensure adequate [information security](https://www.upguard.com/blog/information-security), [data security](https://www.upguard.com/blog/data-security), and [network security](https://www.upguard.com/blog/network-security). In fact, many CISOs and IT security teams now assume that attackers will eventually gain unauthorized access to their organization. 

The truth is adverse cyber events negatively impact the [confidentiality, integrity, and availability](https://www.upguard.com/blog/cia-triad) of organizations every day. These events may be intentional or unintentional (e.g. failed software update) and caused by humans, nature, or a combination thereof.

Today, it's as important to be able to respond to and recover from security breaches as it is to be able to prevent them.

The need for cyber resiliency was well summed up by Lt. Gen. Ted F. Bowlds, former Commander, Electronic Systems Center, USAF:

*“You are going to be attacked; your computers are going to be attacked, and the question is, how do you fight through the attack? How do you maintain your operations?”*

## What are the Four Elements of a Successful Cyber Resilience Strategy?

The four elements of a successful cyber resilience strategy are:

1. **Manage and protect:&#xA0;**&#x54;his involves developing the ability to identify, assess, and manage cyber risks associated with network and information systems, including those across your [third-party and fourth-party vendors](https://www.upguard.com/blog/third-party-vendor).
2. **Identify and detect:&#xA0;**&#x54;his involves the use of [continuous security monitoring](https://www.upguard.com/blog/continuous-security-monitoring) and [attack surface management](https://www.upguard.com/blog/attack-surface-management) to detect anomalies and potential [data breaches](https://www.upguard.com/blog/data-breach) and [data leaks](https://www.upguard.com/blog/data-leak) before any significant damage.
3. **Respond and recover:&#xA0;**&#x54;his involves implementing adequate [incident response planning](https://www.upguard.com/blog/incident-response-plan) to ensure business continuity even if you are the victim of a cyberattack.  
4. **Govern and assure:&#xA0;**&#x54;he final element is to ensure that your cyber resilience program is overseen from the top of your organization and part of business as usual. 

## How Does Cyber Resilience Work?

Any cyber resilience strategy, when put in practice, needs to be considered a preventive measure to counteract human error, [vulnerabilities in software and hardware](https://www.upguard.com/blog/vulnerability), and misconfiguration. Therefore, the goal of cyber resilience is to protect the organization, while understanding that there will likely be insecure parts, no matter how robust security controls are. 

The components of any cyber resilience strategy include:

* **Threat protection:** Cybercriminals advance in lockstep with security controls. What were once state of the art controls are now the bare minimum required to protect an organization. A [third-party risk management and attack surface management software](https://www.upguard.com/) bundle, like [UpGuard Vendor Risk](https://www.upguard.com/product/vendorrisk) and [UpGuard Breach Risk](https://www.upguard.com/product/breach-risk), is one of the best options you can choose to improve your organization's cyber resiliency. Together, they can help you minimize first, third, and [fourth-party risks](https://www.upguard.com/blog/what-is-fourth-party-risk) caused by misconfiguration, [data leaks](/blog/data-leak), and [data breaches](/blog/data-breach). They'll also help you understand where your most at risk through always up-to-date [security ratings](https://www.upguard.com/blog/what-are-security-ratings). 
* **Recoverability:&#xA0;**&#x41;fter a security incident, your organization must be able to return to regular operations quickly. This generally means you have infrastructure redundancies and data backups across different regions in case a natural disaster or cyberattacks impacts a specific part of the world. It's also recommended that you run tabletop exercises to ensure that everyone knows what their role is in the event of a cyberattack. [Read our guide on incident response planning for more information](https://www.upguard.com/blog/incident-response-plan).
* **Adaptability:&#xA0;**&#x57;hile planning is important, adaptability is paramount. Your organization must be able to evolve and adapt to new tactics that cyber criminals come up with. We recommend investing in continuous security monitoring so your security team can recognize security issues in real-time and immediately take action.  
* **Durability:&#xA0;**&#x59;our organization's durability is its capability to effectively operate after a security breach. With system improvements, [configuration management](https://www.upguard.com/blog/5-configuration-management-boss), [vulnerability management](https://www.upguard.com/blog/vulnerability-management), and [attack surface management](https://www.upguard.com/blog/attack-surface-management), your organization's cyber resilience will improve. 

## What are the Benefits of Cyber Resilience?

Cyber resilience strategies provide a range of benefits before, during, and after cyberattacks:

* **Enhanced systems security:&#xA0;**&#x43;yber resilience doesn't only help with responding to and surviving an attack. It can also help your organization develop strategies to improve IT governance, boost safety and security across critical assets, improve data protection efforts, avoid the impacts of natural disasters, and reduce human error. 
* **Reduced financial loss:&#xA0;**&#x52;egardless of how good your security is, the fact is no one is immune to cyberattacks or misconfiguration. The [average cost of a data breach](https://www.upguard.com/blog/cost-of-data-breach) is now $3.92 million globally, enough to kill many small to medium size businesses. In addition to financial costs, the reputational impact of data breaches is increasing due to the introduction of general data protection laws and stringent data breach notification requirements. 
* **Regulatory and legal compliance:&#xA0;**&#x46;or many industries, cyber resilience is a requirement. For example, [FISMA](https://www.upguard.com/blog/fisma) defines a framework for managing information security that must be followed by all information systems used or operated by a U.S. federal government agency in the executive or legislative branches and by [third-party vendors](/blog/third-party-vendor) who work on behalf of a federal agency in those branches. The framework is further defined by the National Institute of Standards and Technology (NIST) who has published standards and guidelines such as [FIPS 199 Standards for Security Categorization of Federal Information and Information Systems](https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.199.pdf), [FIPS 200 Minimum Security Requirements for Federal Information and Information Systems](https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.200.pdf) and the [NIST 800 series](https://csrc.nist.gov/publications/sp800). 
* **Improved work culture and internal processes:&#xA0;**&#x43;yber resilience is a team sport. Every employee has a role to play in [protecting your organization's sensitive data](/blog/sensitive-data) and ensuring adequate incident response. When people are empowered to take security seriously, sensitive data and physical assets are at far less risk. 
* **Reputation protection:&#xA0;**&#x50;oor cyber resilience can irreversibly damage your organization's reputation. This is driven by governments establishing general data protection laws, following the leadership of the European Union's GDPR. For example, while the United States does not have a nation-wide equivalent to GDPR, California has [CCPA](https://www.upguard.com/blog/what-is-the-ccpa), Florida has [FIPA](https://www.upguard.com/blog/fipa), and New York has [the SHIELD Act](https://www.upguard.com/blog/shield-act). All are designed to protect the [personally identifiable information](https://www.upguard.com/blog/personally-identifiable-information-pii) of their constituents. Outside of the United States, Brazil has introduced a very similar law to GDPR called [LGPD](https://www.upguard.com/blog/lgpd). 
* **More trust across customer and vendor ecosystem:&#xA0;**&#x41; lot of emphasis has been placed on [vendor risk management](/blog/vendor-risk-management) and [third-party risk management frameworks](/blog/third-party-risk-management-framework) over the last decade, and rightly so. However, trust is a two-way street. It's essential that your organization has cyber resiliency strategies in place before asking your vendors to. If your organization has an ineffective cyber resiliency, it can damage the reputation of your customers and vendors. 
* **A better IT team:&#xA0;**&#x4F;ne of the underemphasized benefits of cyber resilience is that it improves the daily operations of your IT department. An organization with a hands-on IT team not only improves the ability to respond to threats, but it also helps to ensure day-to-day operations are running smoothly. 

## How is Cybersecurity Different From Cyber Resilience?

The difference between cybersecurity and cyber resilience comes down to their intended outcomes:

* **Cybersecurity:&#xA0;**&#x43;ybersecurity consists of information technologies, processes, and measures designed to protect systems, networks, and sensitive data from cybercrimes. Effective cybersecurity reduces the risk of cyberattacks and protects entities from the deliberate exploitation of systems, networks, and technologies. [Read our full post on cybersecurity for more information.](/blog/cyber-security)
* **Cyber resilience:&#xA0;**&#x43;yber resilience has a broader scope, encompassing [cybersecurity](https://www.upguard.com/blog/cyber-security) and business resilience. Cyber resilience helps businesses recognize that attackers may have the advantage of innovative tools, [zero-days](/blog/zero-day), and the element of surprise. This concept helps businesses prepare, prevent, respond, and successfully recover to their pre-attack business processes and business operations. In short, cyber resilience requires the business to think differently and be more agile when handling attacks.

### Is Cyber Resiliency a Replacement for Cybersecurity?

No, cyber resiliency works with cybersecurity. Most cyber resiliency techniques assume, leverage, or enhance cybersecurity measures. Cybersecurity and cyber resiliency work best together. 

Cyber resiliency has become more popular because it reflects the fact that modern systems are large and complex entities that will always have flaws and weaknesses that may be exploitable. Given resource limitations, achieving an acceptable level of cyber risk requires making trade-offs among cybersecurity measures.  

## What are the Common Cyber Resiliency Threats?

There are four common cyber resiliency threats that a robust cyber resilience strategy will address:

1. **Cybercrime:&#xA0;**&#x4F;ffences that are committed against individuals or groups to intentionally harm the reputation of the victim, cause physical or mental harm, or cause loss to the victim directly or indirectly, using the Internet. Cybercrimes typically threaten a person's, organization's, or nation's security and financial health. Common cyber crimes include [malware infections](/blog/malware), [phishing](https://www.upguard.com/blog/phishing), [spear phishing](https://www.upguard.com/blog/spear-phishing), [whaling attacks](https://www.upguard.com/blog/whaling-attack), other [forms of social engineering](https://www.upguard.com/blog/social-engineering).  
2. **Hacktivism:&#xA0;**&#x48;acktivism is the use of computer-based techniques such as hacking as a form of civil disobedience to promote a political agenda or social change. Common hacktivism cybersecurity incidents include denial of service attacks on critical infrastructure and information systems, doxing, website detachments, wormable ransomware, [typosquatting](https://www.upguard.com/blog/typosquatting), [man-in-the-middle attacks](https://www.upguard.com/blog/man-in-the-middle-attack), and [information leakage](https://www.upguard.com/blog/data-leak). 
3. **Cyber espionage:&#xA0;**&#x43;yberspying is the practice of obtaining secrets and information without the permission or knowledge of its owner. Cyber spying can be a form of [industrial espionage](https://www.upguard.com/blog/corporate-espionage) or be concerned with national secrets. Poor [operational security](https://www.upguard.com/blog/opsec) and a lack of cybersecurity awareness training around what information can and can't be shared on social media are common causes for successful cyber espionage attacks. Common targets for cyber espionage include trade secrets, supply chain information, [personally identifiable information (PII)](https://www.upguard.com/blog/personally-identifiable-information-pii), [protected health information (PHI)](https://www.upguard.com/blog/protected-health-information-phi), and other [sensitive information](https://www.upguard.com/blog/sensitive-data). 
4. **Business continuity management:&#xA0;**&#x42;usiness continuity planning is the process of creating systems of prevention and recovery to deal with potential threats to a company. In addition to prevention, the goal is to enable ongoing operations before and during the execution of disaster recovery.

## How to Improve Cyber Resiliency

[The National Institute of Standards and Technology's Special Publication 800-160 Vol. 2](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-160v2.pdf) offers a framework for engineering secure and reliable systems by treating adverse cyber events as resiliency and security issues. In particular, it outlines fourteen techniques that can be used to improve resiliency:

1. **Adaptive response:** Optimize your ability to respond in a timely and appropriate manner.
2. **Analytic monitoring:** Monitor and detect adverse actions and conditions in a timely and actionable manner. See our post on [indicators of compromise](https://www.upguard.com/blog/indicators-of-compromise) for more information. 
3. **Coordinated protection:** Implement a [defense-in-depth strategy](https://www.upguard.com/blog/defense-in-depth), so adversaries have to overcome multiple obstacles. 
4. **Deception:** Mislead, confuse, hide critical assets from, or expose covertly tainted assets to, the adversary.
5. **Diversity:** Use heterogeneity to minimize common mode failures, particularly attacks exploiting common vulnerabilities (like those listed on [CVE](https://www.upguard.com/blog/cve))
6. **Dynamic positioning:&#xA0;**&#x49;ncrease your ability to rapidly recover from a non-adversarial incident (e.g. natural disasters) by distributing and diversifying your network.
7. **Dynamic representation:&#xA0;**&#x4B;eep representation of your network current. Enhance your understanding of dependencies among cyber and non-cyber resources. Reveal patterns or trends in adversary behavior. 
8. **Non-persistence:&#xA0;**&#x47;enerate and retain resources as needed or for a limited time. This reduces exposure to corruption, modification, or compromise. 
9. **Privilege restriction:&#xA0;**&#x52;estrict privileges based on attributes of users and system elements as well as on environmental factors. See our posts on [access control](https://www.upguard.com/blog/access-control) and [RBAC](https://www.upguard.com/blog/rbac) for more information. 
10. **Realignment:&#xA0;**&#x4D;inimize the connections between mission-critical and noncritical services to reduce the likelihood that a failure of noncritical services will impact mission-critical services.
11. **Redundancy:&#xA0;**&#x50;rovide multiple protected instances of critical resources.
12. **Segmentation:&#xA0;**&#x44;efine and separate elements based on criticality and trustworthiness. 
13. **Substantiated integrity:&#xA0;**&#x41;scertain whether critical system elements have been corrupted.
14. **Unpredictability:&#xA0;**&#x4D;ake changes randomly and unexpectedly. This increases an adversary's uncertainty regarding the system protections which they may encounter, thus making it harder for them to understand how to circumvent them. 

For more ways to improve your cyber resiliency, look at the Cyber Resilience Review (CRR) a framework for the assessment of your resiliency created by the Department of Homeland Security (DHS).

## How UpGuard Can Improve Your Organization's Cyber Resilience

[UpGuard Breach Risk](https://www.upguard.com/product/breach-risk) can monitor your organization for 70+ security controls providing a simple, easy-to-understand [cyber security rating](https://www.upguard.com/blog/what-are-security-ratings) and automatically detect leaked credentials and data exposures in S3 buckets, Rsync servers, GitHub repos, and more.

Our expertise has been featured in the likes of [The New York Times](https://www.nytimes.com/2018/07/20/business/suppliers-data-leak-automakers.html), [The Wall Street Journal](https://www.wsj.com/articles/computer-security-firm-says-voter-data-set-left-unprotected-online-1497877200), [Bloomberg](https://www.bloomberg.com/news/articles/2019-06-27/ford-td-bank-files-found-online-in-cloud-data-exposure), [The Washington Post](https://www.washingtonpost.com/news/the-switch/wp/2017/12/22/you-may-not-know-much-about-the-companies-exposing-your-personal-information-but-they-know-a-lot-about-you), [Forbes](https://www.forbes.com/sites/lconstantin/2017/07/17/cloud-storage-error-exposes-over-two-million-dow-jones-customer-records), [Reuters](https://www.reuters.com/article/facebook-privacy/millions-of-facebook-records-found-on-amazon-cloud-servers-upguard-idUSL3N21L3R4), and [TechCrunch.](https://techcrunch.com/2019/09/18/russia-sorm-nokia-surveillance/) You can also read more about what our customers are saying on [Gartner reviews](https://www.gartner.com/reviews/market/it-vendor-risk-management/vendor/upguard).

eBook

The ITIL Guide to Cyber Resilience

Free resource

### The ITIL Guide to Cyber Resilience

[Download now](/resources/the-itil-guide-to-cyber-resilience)

## Related posts

Learn more about the latest issues in cybersecurity.

Data Breaches

#### [Your First Dark Web Scan Report, Explained](/blog/your-first-dark-web-scan-report-explained)

You scanned your domain. What do the results mean?

[](/team/lance-turner)

[Lance Turner](#)

September 21, 2026

Data Breaches

#### [Good Security Rating? Your Dark Web Exposure Says Otherwise](/blog/good-security-rating-your-dark-web-exposure-says-otherwise)

Scan your domain to see just how exposed you are on the Dark Web.

[](/team/lance-turner)

[Lance Turner](#)

September 20, 2026

Cybersecurity

#### [Left Unsupervised: 10 Times Access Outlived Its Authorization](/blog/10-times-access-outlived-authorization)

Access granted once shouldn’t mean access forever. Read more on how unmonitored access caused 10 of these real-life breaches and what they taught us.

[](/team/revashni-moodley)

[Revashni Moodley](#)

August 25, 2026

Cybersecurity

#### [Surviving a LockBit Ransomware Attack: The ROI of Visibility](/blog/surviving-a-lockbit-ransomware-attack)

Read how veteran CISO Nick Gicinto saved his alma mater from a LockBit ransomware attack by discarding the standard playbook.

[](/team/nicholas-sollitto)

[Nicholas Sollitto](#)

June 1, 2026

Attack Surface Management

#### [Shadow MCP Servers: The AI Infrastructure You Can't See](/blog/shadow-mcp-servers)

In 2012, it was Dropbox. In 2026, it’s Shadow MCP. Discover why unvetted AI agents are an invisible threat and how to regain total visibility.

[](/team/shane-moosa)

[Shane Moosa](#)

August 25, 2026

Attack Surface Management

#### [Six MCP Security Incidents Every Security Leader Should Know](/blog/mcp-security-incidents)

From registry poisoning to filesystem wipes: discover the 6 MCP security incidents every leader must know to secure their AI agent workflows in 2026.

[](/team/shane-moosa)

[Shane Moosa](#)

July 1, 2026

[All posts](/blog)

Experience superior visibility and a simpler approach to cyber risk management

[Get a demo](/contact-sales)

[Free trial](/demo)
