We spend a lot of time talking about how to stop cyber attacks.
Passwords. Patching. Phishing. Firewalls. Access controls. Vulnerabilities.
All incredibly important.
But a conversation I had recently made me think about the problem slightly differently.
What happens when an attack gets through anyway?
Because however good an organisation’s defences are, there probably isn’t a credible cyber security strategy that starts with the assumption that nothing will ever go wrong.
And that’s where cyber security becomes a much bigger business conversation.
What happens when the screens go blank?
Dr Richard Horne, CEO of the UK’s National Cyber Security Centre (NCSC), has described the challenge in four words:
Endure. Respond. Rebuild. Survive.
I like that because it takes something that can become incredibly technical and makes it pretty easy to understand.
Imagine your organisation’s technology stopped working tomorrow.
Could people still do their jobs?
Could you pay employees?
Could customers still access critical services?
Could your suppliers continue operating?
And if the answer to any of those is no what happens next?
That is what cyber resilience is.
Jaguar Land Rover showed why this matters
The 2025 cyber attack on Jaguar Land Rover is a useful example of how quickly a cyber incident can become something much bigger than an IT problem.
Production was disrupted and the effects reached into JLR’s wider supply chain. The UK Government subsequently backed a £1.5 billion loan guarantee intended to provide certainty to that supply chain.
Suddenly we’re not really talking about just computers anymore.
We’re talking about factories, suppliers, employees, customers and whether a business can continue operating.
That’s why the conversation can’t only be about keeping attackers out.
It also has to be about what happens when they get in.
So where does something like CAF come into this?
This is something I’ve only really started to appreciate properly while working in this space.
The NCSC Cyber Assessment Framework (CAF) can look pretty intimidating when you first encounter it.
Objectives. Principles. Outcomes. Indicators. Evidence.
But strip away the terminology and the logic is actually quite sensible.
CAF asks organisations to think about four big things:
How are we managing security risk?
How are we protecting ourselves against cyber attack?
How would we detect something going wrong?
How would we minimise the impact and recover?
CAF isn’t a magic shield that stops an organisation being attacked.
It helps organisations understand whether the right protections, processes and plans are actually in place before they’re desperately needed.
Do we have an incident response plan?
A business continuity plan?
A disaster recovery plan?
Do we understand which services are critical?
Are backups actually tested?
Who makes decisions during an incident?
Have we practised any of this?
And importantly:
What evidence gives us confidence that it would actually work?
Having the document isn’t the same as being prepared
This is the bit I’m finding particularly interesting.
An organisation might already have much of this.
A cyber security policy in SharePoint. A risk register in Excel. An incident response plan somewhere else. Vulnerability reports from the security team. Penetration-test findings. Supplier assessments. Audit reports. Business continuity plans.
Individually, they’re documents and reports.
Collectively, they’re evidence of how prepared the organisation actually is.
And I think that’s one of the easiest ways to understand what cyber assurance is trying to achieve.
It’s not just:
“Do we have a policy?”
It’s:
“Can we demonstrate that what we say we’re doing is actually happening?”
That’s a much more useful question.
Cyber doesn’t need to be impossible to understand
The more I learn about cyber resilience, the more I realise that underneath a lot of the terminology are some fairly straightforward questions.
If something goes wrong tomorrow:
Can you spot it?
Can you respond to it?
Can the business keep operating?
Can you recover?
And perhaps most importantly:
What evidence gives you confidence that any of those things will actually happen?
That’s helped me understand frameworks like CAF differently.
They’re not there because somebody decided organisations needed another compliance exercise. They’re there to help organisations understand whether the right protections, processes and plans are actually in place before they’re desperately needed.
So perhaps the simplest way of looking at cyber resilience is this:
Try to stop the attack.
Know when something has gone wrong.
Know what you’re going to do about it.
Know how you’re going to recover.
And have the evidence to show you’re genuinely prepared.
Because you can’t guarantee that an attack will never get through.
You can make sure you’re far better prepared for what happens if one does.
SIFTR INSIGHT
SIFTR is exploring how organisations can turn dispersed cyber evidence into clearer, traceable assurance findings – helping teams understand what their evidence supports, where potential gaps exist and where human review is required.
Professional judgement remains at the centre of the assurance process.
Leave a comment