How companies can quantify cyber resilience – and why it’s important they do

When developing a cyber resilience plan, board-level discussions should be about value at risk and return on resilience. Image: Getty Images/Cecilie_Arcurs
- Business leaders' confidence in their firms' cyber resilience is falling, but dependence on digital systems is rising.
- Rather than asking whether a company is resilient, boards must ask what measures are in place to be considered “resilient enough”.
- To get the most out of their cyber resilience investments, firms must have board-level discussions about value at risk and the return on resilience.
When the World Economic Forum published its Cyber Resilience Index (CRI) in 2022, it gave business leaders a shared language for a hard question: how ready is your organization to withstand and recover from cyber disruption?
Three years on, the Forum’s Global Cybersecurity Outlook 2025 showed that 35% of small organizations still consider their cyber resilience inadequate – a sevenfold increase since 2022 – while 54% of large organizations cite supply chain complexity as their single biggest barrier to resilience. Additionally, in the age of AI-targeted attacks, a Rubrik Zero Labs study found that 86% of IT and security leaders anticipate the proliferation of AI agents will outpace their company’s security guardrails within the next year.
In this new era, confidence in cyber resilience is falling even as dependence on digital systems deepens.
Indeed, while 92% of executives believe cyber resilience was integrated into their enterprise risk management, according to the CRI, only 19% of cyber leaders were confident their organization was genuinely resilient. This gap between boardroom assurance and operational reality must be closed before organizations can become more cyber resilient.
The most advanced boards have stopped asking whether they are resilient and started asking what measures are in place to be considered “resilient enough”. This equates to figuring out what financial impact the organization can withstand, how cyber resilience investments are balanced across prevention, protection and recovery, and how to measure their return.
Cyber resilience is described, not quantified
Many companies follow a consistent pattern when it comes to cyber resilience. Recovery plans exist and recovery tests are conducted, but not always under the adverse, contested conditions that actually matter during a destructive attack.
Organizations can often quote recovery time and recovery point objectives, yet struggle to show evidence of recovery from a clean, trusted state. Backups are ubiquitous, but immutability and isolated “clean-room” recovery remain inconsistent. Organizations rarely plan for scenarios where backups are targeted and taken down. Crown-jewel systems may not be mapped through an adversarial lens. Accountability can be diffused within the organization, with resilience treated as a technical control owned by IT, not as a strategic capability owned at the top.
The cyber resilience maturity picture is equally uneven. Most organizations invest heavily in preventing and detecting attacks, but comparatively little in the ability to keep operating through one and recover afterwards. These capabilities decide whether a breach becomes a business crisis.
This imbalance has a cost. Where companies used to have 60 days between a breach and damage, now it’s down to as little as 27 seconds, according to Rubrik’s threat research. This leaves organizations virtually no time to react once an attack begins.
And as this window shrinks, the cost of business disruption continues to rise. IBM’s 2025 Cost of a Data Breach report found that lost business remains one of the largest contributors to the $4.44 million global average cost of a data breach. This is why cyber resilience and rapid recovery must become business imperatives.
Measuring the right risk
This reframing depends on measuring the right kind of risk, however. The US National Institute of Standards and Technology's Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management publication gives organizations a disciplined way to express cyber exposure in enterprise terms – likelihood, impact and expected loss – so it can sit alongside every other risk the board governs.
But resilience risk must be measured differently from conventional cyber risk. Traditional programmes concentrate on the likelihood of an event occurring, while resilience objectives use three distinct levers.
First, they aim to reduce the magnitude of impact (constrain, continue, reconstitute). Second, they increase understanding about the likelihood of occurrence (understand, prevent). And third, they help calculate the likelihood that an event turns into harm given existing weaknesses (understand, prepare, constrain, transform, re-architect).
Prevention lowers the odds of being hit, traditional recovery mechanisms lower the cost of regular disruption and resilience lowers the expense of a large-scale compromise. Measuring and presenting only prevention and traditional recovery metrics creates a blindspot for the board because, without resilience, a domino-effect can occur across shared technology services and the critical business processes that depend on them.
Cyber resilience: From impact to value
This is where capability maturity and business value must connect. The cyber community-endorsed Cyber Resilience Capability Maturity Model (CR-CMM) describes resilience across 10 capabilities, including threat-informed defence, crisis management and cyber recovery.
Its worth lies not the score itself but the lineage it creates. Each capability and its maturity can be tied to a concrete value driver that the business already understands. For example, an improvement in recovery maturity that halves time-to-restore could create a multi-million-dollar reduction in expected loss.
Adding such resilience measures creates business value in the following ways:
- cost savings through backup and recovery tool consolidation
- increased visibility into a single, cross-organizational resilience platform
- reduced possibility of and revenue impact from data loss and downtime
- operational efficiency gains from reducing manual effort.
This turns “how much resilience is enough?” into an investment question. Organizations should model the dollar impact the organization cannot absorb, identify the capabilities that reduce it most and direct spending across preventive, protective and recovery controls to the point of greatest return. This is how cyber resilience stops competing for budget on faith and starts competing on quantified risk reduction.
Measuring cyber resilience
None of this holds without ownership. Cyber resilience needs a single accountable executive such as a cyber resilience officer, or a formally chartered group spanning business, continuity, risk, technology and cyber with a mandate to set targets, allocate investment and answer to the board.
And cyber resilience must be run like any other strategic capability. It must be measured against a maturity baseline, exercised under realistic conditions, valued in financial terms and continuously improved.
Every quarter without a consolidated resilience architecture increases remediation complexity and cost. The organizations that invest in cyber resilience today have progressed from a technical debate about controls to a board-level discussion about value at risk and return on resilience. As they move from describing impact to quantifying value, every dollar spent on cyber resilience can be justified by the loss it prevents.
Don't miss any update on this topic
Create a free account and access your personalized content collection with our latest publications and analyses.
License and Republishing
World Economic Forum articles may be republished in accordance with the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International Public License, and in accordance with our Terms of Use.
The views expressed in this article are those of the author alone and not the World Economic Forum.
Stay up to date:
Cybersecurity
Related topics:
Forum Stories newsletter
Bringing you weekly curated insights and analysis on the global issues that matter.
More on CybersecuritySee all
Alex Spokoiny
October 5, 2026



