AI News Feed
Market watch
Cybersecurity

Cyber Resilience Should Be Measured in Minutes, Not Firewalls, TechRadar Pro Opinion Says

TechRadar Pro opinion: cyber resilience is measured in response minutes, not firewalls, citing Grant Thornton UK research.

The piece, written by a partner in Grant Thornton UK's cybersecurity practice, says time has become the biggest driver of cyber costs. For years, organizations measured security success by attacks blocked, vulnerabilities patched and tools deployed. The author argues those questions no longer matter most as attackers move faster, AI accelerates offensive and defensive capabilities, and businesses become more digitally connected. If no organization can eliminate cyber risk entirely, the article says, the definition of resilience must evolve.

The organizations that emerge strongest are not necessarily those that avoid a breach, according to the article, but those that detect, respond and recover fastest. Every hour spent identifying an issue, establishing ownership, waiting for decisions or making regulatory notifications compounds operational disruption, financial loss and reputational damage. Increasingly, the article says, organizations are judged not on whether they suffer an attack but on the quality and speed of decisions made afterward.

The article describes how every cyber incident eventually becomes a board meeting. In the immediate aftermath, the conversation shifts from compromised systems and malicious code to operational disruption, financial impact and business continuity. Boards ask how much an incident will cost, how long operations will be affected, whether customers, supply chain and regulators need to be informed, and what happens next. This creates tension because cybersecurity is risk management spanning people, processes and technology, even though many controls are technology-led.

Accountability extends beyond technology teams, the article says, with finance leaders and boards expected to understand and make high-stakes decisions about cyber risk. It cites Grant Thornton's research finding that 79% of CFOs say ownership of key business risks remains unclear across their organization. That gap is significant when speed is critical and decisions carry financial, operational and reputational consequences. The best responders have already decided who owns risk, who makes decisions, how issues escalate and what level of risk the business accepts.

The article also points to a language barrier. Cyber teams talk about identity management, endpoint detection and legacy infrastructure upgrades, but boards and CFOs ask different questions: How does this protect revenue? What operational disruption could it prevent? What is our potential financial exposure? How does this reduce regulatory or reputational risk? Organizations making the most progress bridge that gap by presenting cyber as a resilience investment that protects business continuity, customer trust and shareholder value. That changes the question from 'How much does this cost?' to 'What would it cost us if we didn't do it?'

Ultimately, the author argues, cyber investment should not be justified by the sophistication of controls but measured by business outcomes: reducing downtime, improving recovery, protecting critical operations and giving leadership teams confidence to respond decisively when disruption occurs. With the cyber landscape evolving rapidly, the article says the priority is to ensure the right conversations happen before an incident, not after.