Understand cyber resilience

Understanding cyber resilience

A plain-language guide for manufacturing SMEs — no specialist cybersecurity knowledge required.

What is information infrastructure?

The digital systems, technologies and platforms used in daily operations to manage information: computers, accounting systems, inventory systems, email, internet, cloud storage and other digital tools that support your work processes.

Cyber resilience goes beyond preventing attacks. It is the ability to anticipate disruptions, withstand them, recover quickly and adapt afterwards.

The four stages

  1. Stage 1 of 4

    Anticipate

    Your organisation is building basic preparedness and awareness of cyber risks to its information infrastructure.

    Focus on building awareness, identifying your critical systems and putting basic protective controls in place.

  2. Stage 2 of 4

    Withstand

    Your organisation demonstrates stronger controls and the ability to respond to cyber disruptions as they happen.

    Focus on strengthening technical controls, incident response procedures and third-party governance.

  3. Stage 3 of 4

    Recover

    Your organisation has established recovery capabilities and restores critical services after cyber incidents.

    Focus on recovery-time targets, tested backups and coordinated restoration of critical systems.

  4. Stage 4 of 4

    Adapt

    Your organisation learns from incidents, absorbs new knowledge and continuously improves its resilience.

    Focus on sustaining organisational learning, absorbing emerging practice and continuous improvement.

The six capability areas

CTA

Cybersecurity Training & Awareness

The capability to develop employees' cybersecurity knowledge, risk awareness and role-based competencies through structured and continuous training.

CCIR

Cyber Control & Incident Response

The capability to implement integrated cybersecurity controls and structured incident response processes to detect, analyse, contain and mitigate cyber threats.

RC

Recovery Capability

The capability to restore critical information infrastructure services within defined recovery-time targets and at acceptable cost after a cyber incident.

AC

Absorptive Capacity

The capability to recognise, assimilate, integrate and apply new cybersecurity knowledge and technologies.

LC

Learning Capability

The capability to review incidents openly, identify root causes, document lessons and apply them to improve practice.

CR

Cyber Resilience

The organisation's overall ability to anticipate, withstand, recover from and adapt to cyber disruptions affecting its information infrastructure.