KONCYBER

Cyber Resilience

Cyber Resilience: Preparing the Business to Withstand the Inevitable

August 26, 2026

After 35-plus years across technology, business, and law enforcement - including years investigating cybercrime with the Toronto Police Service - I have learned that the organizations best positioned to survive a cyberattack are not necessarily those with the most technology. They are the ones that have prepared to make sound decisions under pressure.

For years, cybersecurity was primarily framed as a prevention problem. Organizations invested in firewalls, antivirus software, email filtering and other controls intended to keep attackers out. These safeguards remain essential, but they cannot eliminate risk. Threats evolve, people make mistakes, technology fails and trusted third parties can be compromised.

The question for business leaders is therefore no longer simply, "How do we prevent an attack?" It is also, "How will we continue operating when an attack succeeds?"

That is the foundation of cyber resilience.

What an investigation reveals

When investigating a cyber incident, the initial point of compromise is only one part of the story. The greater business impact is often determined by what happens next.

I have seen organizations lose valuable time because nobody knew who had the authority to make critical decisions. Technical teams worked to contain the incident while executives, legal counsel, communications professionals and operational leaders struggled to establish a common understanding of the situation. Contact information was inaccessible, third-party responsibilities were unclear, and backups that existed on paper could not be restored within the expected timeframe.

These are not exclusively technical failures. They are failures of preparation, coordination and leadership.

By contrast, prepared organizations respond differently. They activate a documented plan, assemble the right decision-makers and establish clear priorities. They preserve evidence while containing the threat. They communicate with employees, customers, regulators and other stakeholders in a deliberate manner. Most importantly, they understand which business services must be restored first.

Preparation does not make an incident painless, but it can prevent the incident from becoming an organizational crisis.

Recovery must be defined before the attack

Two of the most important concepts in resilience planning are the Recovery Time Objective and the Recovery Point Objective.

The Recovery Time Objective, or RTO, defines how quickly a system or business service must be restored following disruption. The Recovery Point Objective, or RPO, identifies how much data loss the organization can tolerate, measured in time.

These may sound like technical measures, but they are business decisions. If a payment platform must be restored within two hours, the organization must invest in the technology, people and processes required to achieve that outcome. If losing a full day of transaction data would be unacceptable, the backup strategy must reflect a much shorter RPO.

Too often, recovery expectations are assumed rather than tested. A backup may complete successfully, but that does not prove the organization can restore a complex operational environment. Dependencies may be undocumented. Credentials may be unavailable. A critical application may rely on a vendor that has its own recovery limitations.

A backup is only valuable when it can be restored. A recovery plan is only credible when it has been exercised.

Resilience is a leadership responsibility

Cyber resilience cannot be delegated entirely to the information technology department. During a serious incident, leaders may need to decide whether to shut down systems, interrupt production, notify customers, involve law enforcement or engage an insurer. They may have to make those decisions with incomplete information and under intense time pressure.

Source: IANS Research & Artico Search, 2026 State of the CISO Benchmark Report.

That shift is already showing up in how companies are structured. It is why tabletop exercises are so valuable. A well-designed exercise gives executives and operational teams an opportunity to practise their responsibilities before the consequences are real. It exposes gaps in authority, communication, vendor coordination and recovery planning that may otherwise remain hidden until a breach occurs.

The objective is not to predict every possible attack. It is to build a repeatable decision-making capability that can be applied when the unexpected happens.

Organizations should know who will lead the response, how key people will communicate if normal systems are unavailable, which external experts must be contacted and how critical services will continue. They should also understand what evidence must be preserved so the incident can be properly investigated.

Managing the risk that remains

No organization can achieve perfect security. Every organization carries a level of inherent risk simply by operating - connected systems, employees who can be targeted, vendors with their own vulnerabilities, and data worth stealing. A strong cybersecurity program exists to reduce that inherent risk as far as it reasonably can: identity controls, endpoint protection, tested backups, trained employees, and the preparation described above. But no program, however mature, reduces that risk to zero. What remains after every reasonable control is in place is residual risk, and every organization operates with some amount of it.

Cyber insurance is the tool built specifically for what remains. It cannot prevent an incident, but it can address the financial dimension of the exposure a strong program can't eliminate - access to incident response specialists, legal counsel, forensic services, notification support, business interruption coverage, and other resources. For small and mid-sized businesses in particular, who often can't absorb a six- or seven-figure incident the way a large enterprise can, and who are frequently underserved by insurance products built for bigger companies, the right policy can be the difference between a bad year and the end of the business. RB Cyber Assurance Inc. (www.rb-cyber.com) is one option I'd point SMBs toward specifically for that reason - coverage built with a smaller organization's actual exposure in mind, not a scaled-down version of an enterprise product.

Insurance should complement, not replace, effective cybersecurity and recovery planning. The most resilient organizations combine preventive controls, prepared people, tested recovery capabilities, and appropriate risk transfer for what those controls can't cover. They recognize that cybersecurity is not only about stopping an attacker. It is about protecting the organization's ability to deliver products and services, preserve trust and recover with purpose.

My experience in investigations has reinforced one lesson repeatedly: the attack may begin with the criminal, but the outcome is shaped by the organization's preparation. Cyber resilience is the discipline of preparing for that outcome before the crisis begins.

Get the next issue