Decoding the world of cybersecurity

Can boards truly be accountable for cyber resilience if they can’t measure it?

Paul Cragg, CTO at NormCyber, argues that board accountability for cyber resilience depends on continuous, evidence-based measurement rather than fragmented reporting and point-in-time assurance.

Can boards truly be accountable for cyber resilience if they can’t measure it?

Contributed article

Paul Cragg

CTO, NormCyber

Boards are being asked to take greater ownership of cyber resilience, but most still lack a reliable way to measure it. As regulatory scrutiny increases and the UK Cyber Security and Resilience Bill progresses through Parliament, organisations are increasingly expected to show that resilience is being actively measured, managed and improved rather than simply discussed at board level. The recently launched UK Cyber Resilience Pledge reinforces this direction of travel, calling on organisations to make cyber a board-level responsibility and strengthen cyber governance.

For many firms, that creates a challenge. How can a board be held accountable for cyber resilience if it lacks a clear and reliable way to measure it?

Rising expectations with limited visibility

Recent research found that resilience ranks among the top five business priorities for 95 per cent of organisations, meaning leadership is not lacking in intent. However, what they are often missing is the evidence to assess resilience with confidence. Regulators are moving from asking whether a cyber resilience strategy exists to asking whether it works, and whether the organisation can prove it. That shift places greater emphasis on resilience outcomes and the ability to demonstrate them.

Most organisations are not short of cyber security reports. However, much of that reporting provides only a partial view of organisational resilience. Operational data is often spread across dashboards, audits, vulnerability scans, supplier reviews and incident reports, each offering useful information but rarely coming together as a coherent picture. Boards can therefore find themselves governing cyber resilience with significant blind spots, making decisions based on fragments of information rather than a complete understanding of organisational resilience.

When confidence and reality start to diverge

The consequences of those blind spots become clear when organisations are tested in the real world. While 88 per cent of organisations rate their cyber resilience as above average, organisations with experience of incidents often tell a different story. Among those that had suffered a breach or conducted a tabletop exercise, 60 per cent found they were less resilient, or recovered more slowly, than their assessment had suggested.

Part of the challenge stems from how resilience is understood. Security focuses on protecting systems and data from attacks, while resilience focuses on maintaining critical operations and recovering quickly when disruption occurs.

Why point-in-time assurance falls short

Point-in-time assurance remains common across many organisations when examining security. Yet cyber resilience changes continuously as vulnerabilities emerge, suppliers evolve, attack surfaces shift and recovery assumptions drift over time.

Annual audits and periodic assessments may provide valuable insight into compliance and control effectiveness, but they capture only a moment in time. As a result, organisations can struggle to maintain a clear and current view of resilience, making it difficult to understand whether operational resilience is improving or deteriorating as risks change.

What boards can do about it

Closing this gap starts with treating cyber resilience as a continuous performance discipline rather than a reactive, compliance-led exercise. Boards need visibility into which services matter most, which systems and suppliers support them, where disruption would have the greatest operational impact and how quickly critical operations could recover.

Achieving that requires resilience measurement to be grounded in operational evidence rather than assumptions. Recovery testing, vulnerability exposure, supplier assurance, detection and response capability all contribute to a more credible understanding of resilience. Looking at these factors collectively provides a clearer picture of preparedness than any single metric or assessment in isolation.

That evidence then becomes far more valuable when it can be measured consistently over time. Consistent measurement enables organisations to track progress, understand whether investments are delivering improvements and prioritise areas of greatest operational risk. It also helps shift resilience discussions away from technical activities and towards business impact and resilience outcomes.

To support those conversations, organisations need a common executive language between boards, security leaders and operational teams. Discussions should focus on whether critical operations are genuinely resilient, where the organisation’s biggest operational dependencies sit and whether the business could recover within acceptable thresholds if a major incident occurred today.

From governance to competitive advantage

There is clear demand for a continuous measure of cyber resilience, with 92 per cent of UK firms believing it would be very or extremely valuable. The challenge now for organisations is moving away from periodic assessments and adopting a more continuous, evidence-based approach to resilience visibility.

As cyber resilience becomes more closely tied to governance, operational resilience and regulatory accountability, boards must now treat cyber as any other business performance indicator. When resilience can be measured, it can be managed, improved and governed with confidence.

×