Rhys Sharp, Solution Director at Six Degrees talks to us about how businesses can build their resilience to ensure they can maintain operations, respond to disruption and adapt to change.

Business resilience has traditionally been treated as a form of technical insurance. In many organisations, the goal has been simple: recover quickly when something breaks and minimise disruption.

That perspective is still deeply embedded. Research from the Six Degrees Business Resilience Index 2026 shows that nearly three-quarters of technology and security leaders define resilience primarily through a security lens. Yet when presented with a broader definition, 91% said they learned something new about what resilience actually involves.

The reason is clear. Modern organisations face a far wider range of risks than cyber threats alone. Operational disruption, third-party dependencies, supply-chain fragility, regulatory change, economic volatility and increasing technology complexity all shape whether a business can continue to operate effectively.

True resilience is therefore not just about protecting systems. It is about ensuring the organisation can maintain operations, respond to disruption and adapt to change.

The resilience perception gap

Despite growing awareness of broader risks, there remains a disconnect between how resilience is discussed at leadership level and how it is delivered operationally.

Almost all respondents in the Business Resilience Index research (97%) agreed that strong leadership and governance would improve resilience. Yet board-level commitment ranked only tenth among the factors organisations associate with actually delivering it.

This gap often leads organisations to overestimate their readiness. Resilience activities may exist within IT or security teams, but they are rarely embedded into strategic decision-making across the business. As a result, organisations can feel prepared until disruption reveals hidden weaknesses.

Understanding resilience maturity

Resilience is not a fixed state but a spectrum. Most organisations sit somewhere along a maturity curve made up of five stages:

  • At risk – highly vulnerable organisations with fragmented processes, limited planning and largely manual recovery capabilities.
  • Reactive – able to respond to incidents but unable to anticipate them, often experiencing repeated disruptions.
  • Stable – controls exist and major failures are less likely, but resilience is still process-driven rather than embedded into operations.
  • Agile – people, processes and platforms align to support rapid response and organisational flexibility.
  • Strategically resilient – resilience is embedded across governance, operations and innovation, supporting both performance and long-term growth.

Research suggests most organisations sit in the middle of this curve. They can manage disruption when it happens but lack the foresight, integration and adaptability required to move beyond reactive measures.

The five pillars of resilient organisations

Progress along the maturity curve depends on how well organisations integrate five core capabilities across their operations: Continuity, Security, Scalability, Efficiency and Innovation.

When these pillars operate in isolation, resilience efforts often remain limited in impact. When aligned across infrastructure, governance and strategy, they reinforce one another and create a more adaptable operating environment.

Among the five pillars, continuity consistently emerges as the most fragile.

The Business Resilience Index research shows that nearly one in three organisations (28%) are classified as At Risk in this area, while fewer than one in ten (9%) reach the Strategically Resilient level.

Operational data reinforces the challenge. Mean uptime across critical services in the past year was just 73%, meaning businesses experienced downtime more than a quarter of the time, whether planned or unplanned.

Mean Time to Recover (MTTR) also varies significantly between sectors. Technology companies report average recovery times of around 9.7 hours compared with an overall average of 6.7 hours, suggesting that their focus on client uptime could be coming at the expense of enhancing their own.

The findings highlight an important point: continuity cannot simply exist as a disaster recovery plan on a shelf. It must be embedded, tested and coordinated across the entire organisation.

Strengths and gaps across the other pillars

While continuity presents the greatest risk, the other pillars show a mixed picture of progress.

Scalability is relatively strong. More than half of organisations fall into the Agile or Strategically Resilient tiers, reflecting growing adoption of flexible infrastructure and cloud-based services.

Efficiency shows significant potential but limited maturity. Only 7% of organisations reach Strategically Resilient status, although 39% are progressing toward greater automation and smarter decision-making.

Innovation is widely present but rarely embedded. Nearly half of organisations operate at an Agile level, but just 2% integrate innovation deeply enough to achieve strategic resilience.

Security, while widely prioritised, still has room for improvement. Only 5% reach the Strategically Resilient tier, even though most organisations cluster at the Agile stage.

Different sectors, different pressures

Resilience challenges also vary significantly between industries.

Financial services organisations often demonstrate stronger resilience profiles due to strict regulatory oversight, structured governance and consistent investment in operational stability.

Manufacturing organisations, by contrast, tend to sit closer to the middle of the maturity curve. Operational intensity and complex supply chains make resilience harder to embed, resulting in higher numbers of organisations classified as At Risk and fewer reaching Agile levels.

Technology companies face another challenge entirely: managing the complexity of large-scale digital environments while maintaining speed and innovation.

These differences highlight that resilience strategies must be tailored to the operational realities of each sector.

The growing role of automation and AI

Technology priorities are also evolving. The Business Resilience Index research shows that automation and AI are now viewed as the most important drivers of resilience, ranking above traditional incident response, recovery and continuity planning.

These technologies allow organisations to detect issues earlier and respond more quickly by reducing reliance on manual processes that can slow recovery. They also enable more continuous, data-driven operations that help anticipate risks before they escalate.

However, infrastructure limitations can still create bottlenecks. Many organisations report that existing resilience strategies cannot scale quickly enough during sudden demand spikes or operational disruptions. Ensuring platforms and services can adapt rapidly is therefore becoming a central focus of resilience strategies.

Turning resilience into a growth platform

The most resilient organisations approach the challenge differently. Rather than treating resilience purely as a defensive safeguard, they see it as an operational capability that supports growth and adaptability.

In practice, this means embedding resilience into everyday operations and decision-making. High-performing organisations design systems that can sense operational signals and emerging demand, allowing them to identify opportunities as well as risks. Continuity is treated as routine operating hygiene, with systems tested regularly and responsibility shared across the organisation rather than confined to IT teams.

They also build scalability directly into system design through elastic infrastructure, self-service capabilities and automation, enabling the business to respond quickly to change without unnecessary friction. At the same time, efficiency is driven by cost transparency rather than simple cost-cutting, helping leaders invest where resilience clearly delivers value. Finally, innovation is actively protected through governance and resource allocation, ensuring experimentation and future-readiness remain part of the organisation’s long-term strategy.

Together, these practices transform resilience from a reactive safeguard into a strategic platform that enables organisations not only to withstand disruption but also to evolve and grow in response to it.

By Rhys Sharp, Solution Director, Six Degrees.

  • Risk & Resilience

Nick Haan, Field CTO at Claroty, on how resilience will define which organisations stay operational when the next wave of disruptive attacks hits

In October last year, Spain experienced one of the most dramatic infrastructure failures in modern European history. A sudden collapse in grid frequency left more than 50 million people without power, grounded flights, halted trains, and shut down businesses across the Iberian Peninsula. Fortunately, it was down to a technical issue known as an overvoltage event, not a hostile act by threat actors. 

But the incident still delivers an important lesson: when critical infrastructure fails, the consequences will quickly cascade.

Geopolitical tensions are running high and state-sponsored actors increasingly target operational technology environments directly. The conditions for a similarly disruptive incident – this time deliberate – are building. 

Withstanding these disruptive incidents requires building resilience into critical infrastructure at a foundational level. Not bolting it on as an afterthought. But with so many facilities designed and built for a different age, where do operators start? 

The infrastructure threat is no longer theoretical

State-sponsored threat actors are no longer simply probing IT networks for data – they are targeting the operational technology that controls physical processes, including energy generation, water treatment, transport systems, and manufacturing. 

The list of targets is expanding too, as critical infrastructure now encompasses airports, telecoms networks, hospitals, and commercial data centres. All of these areas are under increased cyber threat, and that makes it even more important that operators get on top of it now.

Data centres in particular will be a growing concern. Modern hyperscale facilities consume enormous amounts of power, making them uniquely dangerous nodes on the grid. If you bring a data centre down in one go, the impact on the grid will be immense. 

Taking a centre offline creates a spike in one direction, while bringing it back up creates another. A coordinated cyberattack targeting multiple facilities simultaneously wouldn’t just take those sites offline, but could also destabilise the wider grid they draw from.

The problem with bolting security on

Most infrastructure operators are well aware of the increasing cyber threat, but it competes with many other challenges for resources.

A core difficulty facing most operators is that they are not starting from a blank page. The systems that control physical operations were built for reliability and longevity, not security. Many have been running for decades, and some predate the internet entirely. 

Replacing them wholesale is not a realistic option, and even widespread retrofitting may not be possible where taking a system offline could interrupt critical services.

But that doesn’t mean that nothing can be done. The real opportunity in retrofit scenarios lies not in the operational technology (OT) assets themselves but in the infrastructure that surrounds them. Replacing a complete factory won’t happen – some of those components will remain old. But the switches, the firewalls, the IT-type infrastructure that underpins OT operations: that is what needs replacement. 

Without modernising that network layer, even strong security tooling cannot do its job. If you know you need to do segmentation but haven’t got the switches to enforce it, what are you going to do with the information?

This is where resilience-by-design comes in. Organisations that treat cybersecurity as something to be addressed after the operational priorities are settled will find themselves permanently catching up – technically constrained, financially stretched, and exposed. 

Resilience by design in practice

For organisations building new infrastructure, the opportunity to get this right exists – but only if security is treated as a design requirement from the earliest stages. The architectural choices, the network topology, the equipment specifications: these need to account for cybersecurity years before the first brick is laid, not at commissioning when the options have already narrowed.

But inbuilt resilience is still achievable for existing operators. The starting point is understanding what you actually have. An up-to-date asset inventory is the foundation of everything else, because you cannot protect what you cannot see. 

From there, the question that should drive every security investment decision is simple: which systems would cause the greatest disruption if they stopped working? Security programmes built around that question will always outperform those built around compliance checklists.

Organisational structure matters too. Bringing IT and OT under a single point of security responsibility is essential – one person accountable across both domains, with the authority and tenure to make decisions that outlast their own role. Security decisions made by people who know they are moving on in two years tend to reflect that horizon.

Simplify, don’t accumulate

Most critical infrastructure domains tend to operate at a slow pace, where changes are big but take time to build momentum. This is a poor fit for the fast-paced and increasingly hostile nature of the cyber threat landscape.

However, there are immediate steps that operators can take now, without a major investment programme. Launching a programme to reduce redundancy and overlap is a quick win, especially for remote access systems. 

Over time, most operational environments accumulate technology in layers. Each new vendor relationship, each maintenance contract, each operational requirement brings its own tools and its own access pathways. In one customer environment, we found 80 different remote access solutions in active use. 

Reducing that to say, five or 10, is already a major security improvement – the complexity cost of those 80 solutions, in monitoring burden, policy management, and sheer number of potential entry points, far outweighs any operational convenience they provide.

The principle is straightforward: stop adding more and start strengthening what you already have. Vendors naturally tend to push their own tools and access requirements, but organisations need to push back. Prioritise resilience, simplify the ecosystem, and eliminate the fragility that attackers are counting on. 

Preparing for the next wave of digital risk

The Iberian Blackout may not have been a hostile act, but it demonstrated what happens when critical infrastructure proves more fragile than anyone anticipated. The threat environment is not getting easier, and the interconnected systems that underpin daily life – energy, transport, communications – leave little margin for complacency.

Those that have built security in from the foundation will be better placed to withstand incidents, recover faster, and continue serving the people and industries that depend on them. Those who haven’t will find that bolting it on after the fact is slower, more expensive, and less effective than doing it right from the start. In the year ahead, resilience won’t just protect systems – it will define which organisations stay operational when the next wave of disruptive attacks hits.

Learn more at claroty.com

  • Cybersecurity
  • Digital Strategy