Cyber resilience isn’t measured in firewalls. It’s measured in minutes | Daily Reports Online
Cyber resilience isn’t measured in firewalls. It’s measured in minutes.
Time has quietly become the biggest driver of cyber costs. For years, we’ve measured cyber security success by what organizations could stop. How many attacks were blocked? Which vulnerabilities were patched? How much was invested in the latest security tools?
They’re no longer the questions that matter most.
Latest Videos FromTechRadar
It isn’t a groundbreaking observation to say the threat landscape has changed. Attackers are moving faster, AI is accelerating both offensive and defensive capabilities, and businesses are becoming more digitally connected than ever before. If we accept that no organization can eliminate cyber risk entirely, then our definition of resilience has to evolve too.
The organizations that emerge strongest aren’t necessarily the ones that avoid being breached. They’re the ones that detect, respond and recover fastest.
Partner in the Cybersecurity Practice at Grant Thornton UK.
Our latest Grant Thornton Finance Leaders Barometer found the average financial impact of cyber incidents now stands at £488,000 over a two-year period, with 82% of CFOs reporting they’ve experienced a cyber incident with direct financial consequences. Crucially, the cost of an incident is increasingly determined not by the breach itself, but by how quickly leadership teams understand what’s happened, make decisions and restore operations.
Every hour spent identifying the issue, establishing ownership or waiting for decisions and ensuring notifications are made to meet regulations, compounds operational disruption, financial loss and reputational damage. Increasingly, organizations aren’t judged on whether they experience a cyber-attack. They’re judged on the quality and speed of the decisions made in the aftermath.
Every cyber incident eventually becomes a board meeting
In the immediate aftermath of an incident, the conversation shifts away from compromised systems and malicious code towards operational disruption, financial impact and business continuity. Boards aren’t asking which vulnerability was exploited or whether identity controls failed. They’re asking how much it’s going to cost, how long operations will be affected, whether customers, supply chain and regulators need to be informed, and what happens next.
This creates an uncomfortable tension for many organizations. Cybersecurity is fundamentally about risk management, spanning people, processes and technology. While many of the security controls used to mitigate cyber risks are technology-led, they are underpinned by organization-wide processes, policies and decision-making.
Accountability therefore extends well beyond technology teams, with finance leaders and boards increasingly expected to understand and make high-stakes decisions around cyber risk. Yet our research found that 79% of CFOs say ownership of key business risks remains unclear across their organization – a particularly significant gap when speed is critical and decisions can carry financial, operational and reputational consequences.
The organizations that respond best are those that have already decided who owns risk, who makes decisions, how issues escalate and what level of risk the business is prepared to accept. In other words, resilience isn’t just about having the right controls in place – it’s about ensuring the right conversations have happened long before an incident occurs.
Cyber language doesn’t translate to the boardroom
If organizations are going to make better decisions about cyber resilience, they first need to change the conversation. One of the biggest barriers isn’t a lack of investment, it’s a lack of translation. Cyber teams naturally talk about identity management, endpoint detection or upgrading legacy infrastructure. All important priorities, but they’re not the language boards and CFOs use to make investment decisions.
Finance leaders are asking different questions. How does this protect revenue? What operational disruption could it prevent? What’s our potential financial exposure?
How does this reduce regulatory or reputational risk?
The organizations making the most progress are those that can bridge that gap. Rather than presenting cyber as a technology upgrade, they frame it as a resilience investment – protecting business continuity, customer trust and shareholder value. That shift in language changes the conversation from “How much does this cost?” to “What would it cost us if we didn’t do it?”
Ultimately, cyber investment shouldn’t be justified by the sophistication of the controls being deployed. It should be measured by the business outcomes it enables; reducing downtime, improving recovery, protecting critical operations and giving leadership teams confidence they can respond decisively when disruption occurs.
With the cyber landscape evolving rapidly, it can be difficult to predict exactly where investment will be needed one or two years ahead. Organizations therefore need enough flexibility within budget cycles to adapt investment and controls as new threats emerge, rather than being constrained by priorities set at the start of the budgeting period.
AI is shrinking the time frame for good decisions
Artificial intelligence is changing cyber security in two directions at once. Attackers are already using AI to identify vulnerabilities, automate reconnaissance and increase the speed of attacks. At the same time, recent advances in frontier AI models have demonstrated just how quickly AI tools can uncover software vulnerabilities at a scale previously impossible for human teams alone.
The result isn’t simply a more sophisticated threat landscape – it’s a faster one.
Leadership teams have less time to understand what’s happened, assess the commercial impact and make informed decisions. The organizations that respond well won’t necessarily be those with the most advanced AI capabilities. They’ll be the ones that have already agreed who makes decisions, how incidents escalate and what business priorities take precedence before an attack occurs.
The real measure of cyber security
Organizations need to rethink what good looks like. The goal is no longer to create the illusion that cyber risk can be eliminated; it’s to build confidence that the business can make good risk based decisions when disruption inevitably occurs.
That requires more than better technology. It requires clearer ownership, stronger governance and a shared understanding of risk across the organization. In many ways, cyber has become the clearest test of organizational resilience, not because attacks are inevitable, but because they reveal how well leadership teams perform when certainty disappears.
Ultimately, the organizations that come through incidents strongest won’t necessarily be those with the best security tools. They’ll be the ones whose leaders have already had the difficult conversations, made the key decisions and built the confidence to act when it matters most.
We’ve featured the best antivirus software.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here:







