Cyber resilience vs cybersecurity: keeping the business running after a breach

Most security budgets go on keeping attackers out. That matters, but no defense is perfect. Cyber resilience is about what happens next: whether payments, services and operations keep running when an attack gets through.

NIST (the US National Institute of Standards and Technology) describes cyber resilience as the ability to anticipate, withstand, recover from and adapt to attacks and disruptions. Cybersecurity aims mainly to prevent a breach. Cyber resilience aims to keep the organization working if one happens.

Cyber resilience cycle: anticipate, withstand, recover, adapt

You need both. Security locks the doors. Resilience makes sure the business carries on when one door is forced.

Plan as if someone will get in

Security teams call this mindset “assume breach”. You plan on the basis that an attacker will eventually get inside, and you ask how quickly you would notice and respond.

A strong firewall tells you how good your walls are. Resilient organizations also track two other measures. Mean time to detect (MTTD) is how long an intruder goes unnoticed. Mean time to respond (MTTR) is how long it takes to contain them.

Why boards are paying more attention

Downtime is expensive. Every hour a critical system is down brings failed transactions, missed service levels, contract penalties and damage to customer trust that takes a long time to repair.

Attacks have also become more capable. Many are automated, some use AI, and more of them arrive through suppliers and partners connected to your systems.

Regulators expect more, too. Indonesia’s Personal Data Protection Law (UU PDP) requires breach notification within 72 hours and allows administrative fines of up to 2% of annual revenue. The financial regulators, OJK and Bank Indonesia, expect institutions to show evidence that they can withstand and recover from incidents.

The framework we use below comes from NIST CSWP 29: The NIST Cybersecurity Framework (CSF) 2.0.

Six functions from NIST CSF 2.0

NIST CSF 2.0 groups security and resilience work into six functions. Each one answers a plain question.

# Function Key question Example controls
1 Govern Who is responsible? RACI structure (Responsible, Accountable, Consulted, Informed), security policies, board oversight
2 Identify What do we have, and what matters most? Asset discovery, vulnerability scanning, penetration testing, critical asset classification
3 Protect Are the doors locked? Multi-factor authentication (MFA), access management (IAM), firewalls, disk encryption, hardening, least privilege
4 Detect Would we know if someone broke in? Central log monitoring (SIEM), endpoint detection (EDR/XDR), intrusion detection (IDS/IPS), tracking MTTD
5 Respond Once we know, what do we do? Automated response (SOAR), incident playbooks, forensics, measuring MTTR
6 Recover How do we get back to normal? Tested backups, disaster recovery plan, crisis communications

In our experience, many organizations invest most in Protect and much less in Govern, Detect and Recover. Those three largely decide whether the business keeps running during an incident.

Where Snipeyes can help

  • Govern and Identify: security assessments, penetration testing, and risk mapping against ISO/IEC 27001:2022 and the regulations that apply to you.
  • Protect: architecture review, hardening, and secure code review before applications go live.
  • Detect and Respond: a 24/7 security operations center (SOC), plus red teaming (a realistic simulated attack) to check whether the SOC catches real attacks.
  • Recover: hands-on testing of backups and disaster recovery, so you know the plan works when you need it.

A practical first step

You cannot protect assets you do not know you have. A free 90-minute scoping session maps your critical assets, your largest gaps and the first step likely to give the best return. Schedule scoping. We reply within 24 hours and can sign an NDA before we start.