Cyber security is now subject to more scrutiny, regulation and assurance than almost any other area of enterprise technology. Yet meeting a recognised standard or successfully completing an audit doesn't necessarily demonstrate that an organisation can continue operating through a serious cyber incident. True resilience depends on whether its technology, people and processes perform as expected when disruption actually occurs. Here, our Head of Customer Experience, Nathan Charles, explains why organisations need to move beyond a compliance-led mindset and focus on proving resilience in practice.
Organisations invest significant time and resource into achieving certifications such as ISO 27001 and Cyber Essentials, while regulated firms face additional obligations under frameworks such as the Financial Conduct Authority (FCA) and Prudential Regulation Authority (PRA) operational resilience rules. These frameworks provide valuable structure and demonstrate a credible baseline of security maturity.
Such frameworks establish recognised standards, encourage accountability and provide boards and customers with a useful benchmark for security maturity. The challenge is ensuring that progress doesn't stop once certification has been achieved.
For many organisations, passing an audit becomes the objective in itself, rather than a step towards genuine resilience. Certification and self-assessment exercises capture a snapshot of security controls at a single point in time, under conditions that are largely predictable. What they can't always demonstrate is how effectively those controls will perform when an organisation is dealing with a fast-moving and unpredictable disruption, such as a ransomware attack that spreads faster than the incident response plan anticipated, a misconfigured update that takes core systems offline, or a supplier outage with knock-on effects nobody had mapped.
The gap between documented compliance and operational reality is well evidenced. The UK Government's Cyber Security Breaches Survey 2025/2026 found that 43 per cent of UK businesses reported experiencing a cyber security breach or attack in the past twelve months. This is despite most organisations already having basic technical measures, such as malware protection, firewalls and access controls, in place.
The financial services sector, where operational resilience obligations are most mature, illustrates the same gap. In March 2026, the FCA published its first detailed review of how firms had performed since the transition period for its operational resilience rules ended in March 2025. The review examined whether firms had genuinely embedded resilience into daily operations, or whether their self-assessments amounted to little more than a paperwork exercise. Put simply, having the right documentation doesn't automatically prove that an organisation's most critical services can withstand a severe but plausible disruption.
Encouragingly, this is not a case of compliance frameworks being wrong; it reflects how regulators and standard-setters are actively evolving what they expect organisations to demonstrate. The National Cyber Security Centre (NCSC) has developed its Principles Based Assurance approach specifically to move away from assessment against fixed, compliance-driven control sets, in favour of a risk-based approach.
The FCA has followed a similar trajectory, shifting its supervisory focus from asking firms whether they have identified their important business services, to asking whether they can prove they remain within agreed impact tolerances today, through tested evidence rather than policy documents.
Similar principles underpin the EU's Digital Operational Resilience Act, which requires financial entities to test their resilience through scenario-based exercises rather than rely on point-in-time compliance reviews. Across different sectors and regulatory environments, the direction is increasingly clear: resilience needs to be demonstrated through evidence and testing, rather than assumed from documentation alone.
For organisations that want to close this gap, the starting point is treating resilience as something that is tested and proven, not assumed because a framework has been satisfied. That means running scenario-based exercises that simulate severe but plausible disruption, such as the loss of a critical supplier, a ransomware incident or a major cloud outage, and observing how systems, teams and decision-making actually hold up under pressure.
The value of these exercises lies not simply in confirming what works, but in exposing assumptions, dependencies and weaknesses before a real incident does. Testing gives organisations an opportunity to understand where recovery plans break down, where responsibilities are unclear and where technical resilience doesn't match what is documented on paper.
Compliance and regulatory frameworks will continue to play an important role in helping organisations manage cyber risk, but meeting those requirements should be regarded as a foundation for resilience rather than the finished result. The real test is whether critical services can continue operating when technology fails, suppliers become unavailable or a cyber incident develops in ways that existing plans didn't anticipate.
Building that capability requires organisations to test regularly, challenge their assumptions and make resilience a shared responsibility across technology and the wider business. Those that do so will move beyond demonstrating that controls exist and towards proving that they work when they are needed most. Ultimately, resilience isn't defined by whether an organisation can pass an audit, but by whether it can absorb disruption, recover effectively and keep its most important services running.
To learn how we helps organisations map digital dependencies and strengthen operational resilience, our team is happy to talk it through. Just fill in the form below and we’ll be in touch.