Cyber Resilience: Questions for Boards and Audit Committees
Executive Summary: Cyber resilience is an enterprise governance responsibility measured by the ability to continue critical services when systems, identities, data, suppliers, communications, or recovery capabilities are compromised. Boards should require management to identify critical services and dependencies, protect trusted recovery capabilities, maintain crisis communications, exercise severe scenarios, track accountable remediation, and report residual risk and demonstrated recoverability.
From Business Continuity to Enterprise Resilience
Traditional business continuity addresses outages, disasters, technology failures, and personnel loss. Cyberattacks require a broader approach because they can compromise systems, identities, data, suppliers, communications, backups, and recovery environments.
The central governance question is no longer:
“Can the organization recover its systems?”
It is:
“Can the organization continue delivering critical services when technology, data, identities, suppliers, and recovery systems may be compromised?”
Cyber resilience is therefore an enterprise capability, not solely an IT responsibility. Boards should measure it by continued delivery of critical services—not by the existence of recovery plans.
1. Identify Critical Services and Dependencies
Resilience should be assessed through essential business services rather than individual applications. Management should identify the services most important to customers, regulators, markets, and the organization, then define the maximum tolerable disruption for each.
Each service should be mapped to its critical dependencies, including:
● People and specialized skills.
● Business processes and facilities.
● Applications, infrastructure, and networks.
● Data and identity services.
● Cloud platforms and technology providers.
● Suppliers, payment processors, and telecommunications.
● Communications and crisis-management capabilities.
Boards and Audit Committees should ask:
● Which services are most important to the organization and its stakeholders?
● What is the maximum tolerable disruption for each service?
● Which dependencies or common providers could prevent recovery?
● Can services operate through manual or alternate processes?
● What concentration risks exist across suppliers, cloud platforms, or identity providers?
2. Establish Integrated Governance
Cybersecurity, business continuity, disaster recovery, crisis management, and enterprise risk management should operate as one coordinated capability. Management should define ownership, decision rights, escalation protocols, recovery objectives, and accountability across business, technology, legal, risk, communications, and compliance functions.
Question: Who owns cyber resilience, and are responsibilities clear across the organization?
3. Protect Trusted Recovery Capabilities
Identity platforms, privileged access systems, backups, hypervisors, cloud management accounts, storage, and disaster recovery environments are critical infrastructure. Boards should determine whether these assets are protected from production compromise and can be rebuilt from a trusted state.
The relevant question is not whether backups exist, but whether critical services can be restored using intact, available, and trustworthy data. Management should address:
● Protection of backups from production compromise.
● Immutability and logical or physical separation.
● Recovery of identity and privileged access systems.
● Validation of backup integrity and completeness.
● Protection of cloud control planes and recovery environments.
● Ability to rebuild essential infrastructure from trusted components.
4. Distinguish Restoration From Trusted Recovery
Technical restoration is not the same as trusted recovery. Cyber incidents may require investigation, credential resets, malware eradication, backup validation, data integrity checks, and controlled reconnection.
Management should report actual trusted recovery time—not merely infrastructure restoration time—and explain how data integrity will be validated before services return to operation.
5. Address Third-Party and Communications Resilience
Cloud providers, SaaS platforms, payment processors, telecommunications companies, managed security providers, and identity platforms may create significant dependencies. Management should identify alternative providers, manual procedures, supplier recovery capabilities, contractual gaps, and risks arising from common providers.
Cyber incidents may also disable email, collaboration tools, directories, VPNs, and telephony. Organizations need alternative communications and clear authority for system disconnection, failover, restoration, regulatory notification, customer communication, and return to normal operations.
6. Test Severe but Plausible Scenarios
Exercises should involve executives, business leaders, technology teams, suppliers, legal, communications, and risk functions. Scenarios should include:
● Ransomware and destructive malware.
● Identity or privileged-access compromise.
● Cloud control-plane attacks.
● Backup compromise or data corruption.
● Denial-of-service attacks.
● Telecommunications outages.
● Insider sabotage.
● Major supplier or concentration-risk incidents.
Testing should determine whether critical services can continue, whether recovery capabilities are trustworthy, and whether decision-making and communications remain effective. Each exercise should produce accountable actions, deadlines, and follow-up reporting.
7. Use Metrics That Demonstrate Recoverability
Boards should measure demonstrated capability rather than documentation volume. Useful metrics include:
● Percentage of critical services with tested recovery strategies.
● Successful restoration rates.
● Trusted recovery time compared with approved tolerance.
● Percentage of critical services protected by immutable backups.
● Time required to restore identity infrastructure.
● Critical services dependent on single providers.
● Number and effectiveness of tested manual workarounds.
● Unresolved exercise findings and overdue remediation.
● Data integrity validation results following recovery tests.
Management should also report residual risk after planned investments and explain where recovery capabilities remain unproven.
Essential Oversight Questions
Boards and Audit Committees should ask:
1. What are our most critical business services?
2. What dependencies could prevent recovery?
3. Can we operate if identity infrastructure is compromised?
4. Are backups protected from production compromise?
5. Can services be restored to a trusted state?
6. How long would trusted recovery actually take?
7. How will data integrity be validated?
8. What happens if a major supplier is compromised?
9. Can we communicate if corporate systems are unavailable?
10. When was our last realistic cyber recovery exercise?
11. What failed, and what remains overdue?
12. What residual risk remains after planned investments?
Conclusion
Cyber resilience means preventing what can be prevented, detecting what cannot, containing attacks, and recovering critical services before disruption exceeds organizational tolerance.
Boards should seek assurance that the organization can continue its most important operations, recover from a trusted state, and limit harm following a major cyberattack. This requires clear accountability, sustained investment, independent assurance, and demonstrated performance—not merely documented plans.

