# What is Cyber Resilience?

> Cyber resilience is the ability to anticipate, withstand, recover from, and adapt to adverse conditions, attacks, or compromises involving digital systems and resources.

- Canonical URL: https://yellowcube.eu/glossary/cyber-resilience/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Its purpose is to sustain important mission or business outcomes even when prevention fails. That requires understanding which functions matter, what they depend on, how much degradation is tolerable, and how the organization will regain trustworthy operation.

Resilience is designed across systems and operations rather than added as a single control. Measures can include segmentation, diversity, redundancy, reduced privileges, graceful degradation, alternate processes, protected recovery resources, incident response, and exercises. Recovery alone is not enough: organizations should learn from disruption and adapt architecture, priorities, and operating procedures as dependencies and threats change.

### Key points

- **Anticipate:** Identify critical functions, dependencies, plausible adverse scenarios, minimum viable service levels and warning indicators.
- **Withstand and recover:** Limit blast radius, preserve essential capabilities, maintain trusted communications, restore in priority order and verify security before normal operation resumes.
- **Adapt:** Exercise realistic failures, measure outcomes, analyze incidents and near misses, and change designs or operating assumptions when evidence exposes weakness.
- **Important limitation:** Redundancy does not guarantee resilience when copies share the same failure mode, credentials, supplier, or attacker access. Claims need scenario-based testing that includes people and third parties, not only component uptime.

### Related terms

[Business continuity](<https://yellowcube.eu/glossary/business-continuity/>) · [Disaster recovery](<https://yellowcube.eu/glossary/disaster-recovery/>) · [Cybersecurity](<https://yellowcube.eu/glossary/cybersecurity/>) · [Incident response (IR)](<https://yellowcube.eu/glossary/incident-response/>) · [Crisis management](<https://yellowcube.eu/glossary/crisis-management/>) · [Cyber recovery](<https://yellowcube.eu/glossary/cyber-recovery/>) · [NIST Cybersecurity Framework (CSF)](<https://yellowcube.eu/glossary/nist-cybersecurity-framework/>)

### Sources

[NIST SP 800-160 Vol. 2 Rev. 1](https://csrc.nist.gov/pubs/sp/800/160/v2/r1/final) · [NIST Cybersecurity Framework 2.0](https://www.nist.gov/cyberframework)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

