Its purpose is to sustain important mission or business outcomes even when prevention fails. That requires understanding which functions matter, what they depend on, how much degradation is tolerable, and how the organization will regain trustworthy operation.
Resilience is designed across systems and operations rather than added as a single control. Measures can include segmentation, diversity, redundancy, reduced privileges, graceful degradation, alternate processes, protected recovery resources, incident response, and exercises. Recovery alone is not enough: organizations should learn from disruption and adapt architecture, priorities, and operating procedures as dependencies and threats change.
Key points
AnticipateIdentify critical functions, dependencies, plausible adverse scenarios, minimum viable service levels and warning indicators.
Withstand and recoverLimit blast radius, preserve essential capabilities, maintain trusted communications, restore in priority order and verify security before normal operation resumes.
AdaptExercise realistic failures, measure outcomes, analyze incidents and near misses, and change designs or operating assumptions when evidence exposes weakness.
Important limitationRedundancy does not guarantee resilience when copies share the same failure mode, credentials, supplier, or attacker access. Claims need scenario-based testing that includes people and third parties, not only component uptime.