By Harpreet Sidhu, Giovanni Cozzolino and Yusof Seedat
Cyberattacks can no longer be prevented entirely, making resilience, not protection, the defining leadership challenge. This article argues that CEOs must shift from protection to resilience by identifying the essential operating core and rethinking compliance, recovery, governance, value-chain risk and the true economics of cyber disruption today.
Europe’s cyber threat landscape has changed dramatically since 2022. What began as cyber operations linked to the Russia–Ukraine conflict has evolved into a persistent campaign targeting critical infrastructure, including hospitals, energy networks, transportation systems and financial institutions. The European Union Agency for Cybersecurity, ENISA, reports that both the volume and consequences of attacks increased during 2023 and 2024.[1] Its 2025 threat assessment documented nearly 4,900 incidents across the region.[2]
In an era of escalating attacks and digital interdependence, complete prevention is no longer achievable. Leaders are aware of this fact. In our February–March 2026 survey of 329 senior executives across the UK, Germany, France, Italy and Spain, almost 70% said preventing all cyber disruption is no longer realistic given today’s complex technology ecosystem.
Europe’s exposure to cyber threats is amplified by its deeply integrated cross-border supply chains, with manufacturers, logistics providers, financial institutions and critical service operators bound together across multiple jurisdictions. An attack on one central provider impacts every organization across its network.
Rapid AI adoption is accelerating this vulnerability. AI increases the speed, scale and interconnectedness of digital operations, creating new pathways for disruption while making recovery more complex and accelerating the path from compromise to business impact.
Yet many European companies continue preparing for a world in which attacks can largely be prevented or quickly contained. In our research 82% of executives expect critical downtime after a ransomware attack to last no more than ten days. But based on Accenture’s observations across multiple cyber recovery engagements and publicly reported incidents, many organizations require months, not days, to fully recover from major cyber disruption.
Drawing on our client work, original survey and analysis of European cyber incidents, we suggest that European CEOs make a fundamental strategic shift: from protecting against cyberattacks to building organizations that can withstand them. That means rethinking how resilience is designed, governed and funded. We outline six moves that make this possible: defining the essential operating core, treating compliance as the starting point rather than the goal, engineering recovery instead of relying on rapid response, making resilience an enterprise-wide responsibility, extending it across the value chain and understanding the full economic cost of disruption.
From cybersecurity to cyber resilience
Cybersecurity seeks to prevent attacks. Cyber resilience accepts that some attacks will succeed and focuses on ensuring the business can continue operating, adapt under pressure and recover when disruption occurs.
But many executives still rely on the dangerous assumption that if they are protected, they will recover. In our research, 86% of executives believe their cybersecurity controls are sufficient to sustain critical operations during a major cyber disruption. Compounding the challenge, business and security leaders are not aligned on what resilience requires. European CEOs are 52% more likely than Chief Information Security Officers (CISOs) to believe that strong protection controls alone ensure business continuity following an attack.
Businesses now run on a mix of cloud systems, AI-driven processes and third-party services, all of which are constantly changing. Legacy systems, unpatched, outdated software and hardware and other forms of tech debt further expand the attack surface, making it increasingly difficult to predict where attacks will originate or to contain them with perimeter-focused security strategies alone.
For instance, in 2024, a UK transport-technology provider suffered a cyberattack despite the company’s heavy investments in security testing, employee awareness, external certifications and secure system design.[3] Although services were restored relatively quickly, recovery continued for approximately 12 weeks.[4] Service credits, restoration expenses and customer compensation cost the company more than 5% of annual revenue and over two-thirds of annual operating profit. Protecting systems and data does not automatically preserve critical operations.[5]
Despite this new reality, only 11% of our survey respondents fully acknowledge that traditional cybersecurity approaches are outdated. An effective cyber strategy does much more than protect against attacks. It prepares companies to operate under stress when attacks succeed. That’s why companies must move their defences from protection-centric to cyber resilience (Figure 1).
Figure 1: From protection to resilience
Effective cyber strategies are anchored in resilience

Shift 1: Identify the essential operating core that must remain available during disruption
Resilience must be demonstrated, not assumed. In fact, most companies in our research never test whether they can swiftly restore operations after a major disruption.
Building resilience begins with deciding what the business must be able to preserve when disruption inevitably occurs. Business leaders must define the organization’s essential operating core: the smallest set of business outcomes, customer services, decisions, processes, applications, data and third-party services that must remain available or be restored first when the wider technology environment becomes unavailable or cannot be trusted.
They should establish visibility across critical assets, dependencies and exposures, including legacy environments. They must then determine, before a crisis occurs, which customer services cannot stop, which regulatory and safety obligations the enterprise still needs to meet, which processes can operate manually and which activities can be paused without causing irreversible harm. Those choices should then determine where to engineer resilience into core platforms, which clean recovery environments are required and where to invest.
In Europe, this is increasingly becoming a regulatory requirement as well as a business imperative. Under NIS2, organizations that provide services critical to the economy and society must demonstrate asset management, risk assessment and business continuity capabilities.[6] Organizations that cannot identify and protect their essential operating core risk falling short not only of operational resilience, but also of regulatory expectations.
When disruption occurs, the most important question is rarely, “How quickly can we restore every system?” Instead, it is, “What must continue operating while recovery takes place?”
Shift 2: Treat compliance as the starting point, not the goal
Another common mistake is to treat compliance and resilience as the same thing. Nearly 70% of executives believe regulatory compliance provides sufficient assurance of cyber resilience, and CEOs are 73% more likely than CISOs to equate compliance with resilience.
Europe’s regulatory landscape is becoming increasingly demanding. NIS2 became enforceable in October 2024, and the Digital Operational Resilience Act (DORA) for financial services followed in January 2025, together representing the most significant expansion of cybersecurity regulation in European history.[7] These regulations are raising the baseline of cyber preparedness across the region, but they establish minimum expectations, not resilience itself.
Cyber threats evolve continuously, while regulations take time to catch up. Compliance frameworks often reflect what organizations should do based on lessons from past incidents. Resilience, however, is defined by an organization’s ability to withstand the next disruption, not the last one.
The gap becomes clear when recovery is tested. Only 34% of surveyed companies use recovery and continuity exercises to assess resilience. Most rely on audits, which prove controls exist, not that operations can continue when controls fail.
Leaders must instead mandate live recovery exercises. The digital core deserves particular scrutiny. It should be tested under realistic disruption scenarios, not simply signed off by an auditor. NIS2 mandates incident response testing and business continuity measures, but the regulation sets a floor, not the ceiling.[8]
Shift 3: Think beyond fast response; engineer recovery pathways
A vast majority of executives from our research also equate rapid detection and containment with resilience. But a swift response does not necessarily result in swift recovery as the experience of a national public health service provider in Western Europe demonstrates. Following a ransomware attack in May 2021, the organization responded immediately, shutting down ICT systems and disconnecting access to the national healthcare network on the same day to contain the spread of the attack. Government agencies, cybersecurity authorities and external incident-response specialists mobilized quickly to support the response.[9] A decryptor became available within days.
But rapid containment did not translate into rapid operational recovery. The attack disrupted multiple healthcare services, including radiology, pathology, maternity care and primary care. Staff reverted to paper records and manual workarounds, resulting in delayed admissions, patient handovers and clinical records. It took more four months for 99% of affected applications to be restored.[10]
True resilience is engineered before disruption strikes. It requires organizations to define recovery pathways, establish alternative operating models and design containment mechanisms that prevent disruption from cascading across the enterprise. Yet fewer than half of surveyed organizations have taken these steps. Only 40% have containment and isolation strategies to limit the blast radius of an attack and the same proportion predefine and test recovery pathways for critical systems.
Leaders must insist on tested recovery pathways for every critical service, but they should not assume that every service must be restored simultaneously. Recovery should be sequenced around the essential operating core. That means defining in advance what recovers first, what can operate in a degraded or manual mode and what can temporarily stop. The pathways must be rehearsed before a crisis, never improvised during one.
Shift 4: Treat cyber resilience as an enterprise-wide, not just an IT, priority
A 2023 ransomware attack on a major UK logistics group demonstrates why cyber resilience cannot be treated as an IT issue alone. The attack affected core systems, business processes and financial information. Truck-management networks, booking platforms and payment-processing systems became unavailable, disrupting deliveries and critical financial operations.[11]
This further weakened the group’s already stressed financial position. In particular, the loss of access to reliable financial information limited the company’s ability to provide the assurances required to secure additional investment and credit. What began as a cyber incident quickly became a liquidity challenge, a workforce challenge and, ultimately, a business survival challenge. Three months later, the company entered insolvency proceedings, made 730 employees redundant and sold part of its business to preserve 170 jobs. [12]
Cyberattacks rarely remain confined to IT systems. Their effects cascade across operations, finance, treasury, workforce management, customer relationships and ultimately the viability of the enterprise itself.
Yet our research shows that 71% of European executives regard cyber resilience as an IT issue. This isolates cyber resilience within specialist teams and leaves critical business functions unprepared to operate through disruption.
But defining and protecting the essential operating core should be an enterprise-wide exercise. Determining which customer commitments must be maintained, which revenue streams must be preserved, which regulatory obligations cannot be compromised and which business activities can temporarily pause are all enterprise decisions.
Technology leaders can explain system dependencies, but they cannot determine which business trade-offs to make during disruption. Those decisions require alignment between the CEO, COO, CFO, CIO, CISO, risk leaders and business-unit executives before a crisis begins. Yet only 41% of organizations in our research hold cross-functional leaders accountable for sustaining operations during cyber disruption. This results in a gap between resilience planning and operational reality. When disruption occurs, responsibilities are often unclear, decisions are delayed and functions outside IT are left unprepared to operate under degraded conditions.
Organizations must also test more than technology recovery. They need enterprise-wide simulations that prove they can continue serving customers, maintain liquidity and operate effectively when core systems fail.
Shift 5: Have a clear view of the entire value chain, not just the enterprise
Many organizations assume that responsibility for cyber resilience ends at the boundaries of the enterprise. They expect vendors, suppliers and cloud providers to manage their own risks. Our research reveals a significant visibility gap: 54% of executives say their organization’s ability to sustain critical operations depends on external partners, but only 34% have a clear view of their entire value chain.
However, when a critical partner fails, the consequences ripple through the value chain regardless of where the failure originated. As organizations become increasingly dependent on technology providers, logistics networks, financial institutions, data processors and outsourced service providers, cyber resilience is determined by both internal controls and the broader ecosystem’s resilience.
The consequences can be severe. In August 2025, a ransomware attack on a Swedish HR software provider disrupted services used by approximately 80% of Sweden’s municipalities. Human resources, sick-leave and incident-reporting systems across roughly 200 municipalities and regional authorities were affected.[13] An attack on a single supplier quickly became a disruption affecting hundreds of organizations. The incident later resulted in the exposure of personal data relating to 1.5 million individuals and triggered regulatory investigations into both the supplier and several public-sector customers.[14]
Organizations can outsource services, but they cannot outsource accountability for resilience. As organizations become more interconnected, the attack surface includes systems they do not directly own or control.
Leaders must demand visibility across the entire value chain. This requires organizations to identify and monitor critical third-party dependencies and incorporate them into resilience planning. They must identify viable alternatives where a single provider carries disproportionate operational importance. Recovery exercises should test not only internal systems but also the failure of critical suppliers and ecosystem partners.
Shift 6: Plan for the true cost of disruption, not just insured losses
It’s tempting to assume that cyber insurance can offset the cost of major disruptions, reducing the need to invest in resilience. Nearly two thirds (62%) of companies in our research said they rely on insurance as a substitute for investing in resilience.
Insurance may cover certain direct costs after a successful attack, but it does not guarantee critical operations continue during disruption. In fact, the full cost of disruption, after accounting for downtime, lost revenue and reputational damage, often exceed insurance payouts tenfold.[15] Nor can insurance shield executives from regulatory scrutiny, customer attrition or shareholder backlash.
Besides, many cyber insurance policies have “act of war” exclusions that allow insurers to deny coverage if an attack is attributed to a government. The 2017 NotPetya attack, responsible for over $10 billion in global damage, demonstrated the limits of cyber insurance when insurers argued that a state-sponsored attack fell under “act of war” exclusions, resulting in years of litigation over coverage.[16]
A policy might help fund forensic investigation, specialist support and other direct response costs, but it cannot restore critical data, preserve access to liquidity or keep the business operating while its systems recover. Consider the logistics group we discussed above. It had bought £1 million of cyber insurance a month before the attack, and its insurer quickly mobilised external incident-response support. However, the attackers had destroyed a backup of the company’s financial-management databases. So, it was unable provide the financial information its bank required for additional lending, complicating efforts to sell the business.[17]
Leaders must calculate the true cost of disruption, not just insured losses. This honest accounting has to capture downtime, lost revenue, regulatory exposure and reputational damage. For European companies, GDPR compounds the risk: A major breach that triggers both operational disruption and a regulatory investigation carries financial exposure well beyond what any policy covers. Resilience remains the only reliable protection against the full economic impact of cyber disruption.
Prioritize cyber resilience
The organizations described throughout this article followed a protection-centric cyber strategy. They had controls in place and detected attacks quickly. Where they went wrong was the misplaced belief that protection, compliance and fast response were enough, that third parties would manage their own risks and insurance would cover the damage. Core operations still broke down and recovery took far longer than expected.
Companies that will survive the next major disruption will be the ones that understand how exposed their entire value chain is, define the essential operating core they must preserve when normal operations fail and build their operating model around sustaining it.
That is what cyber resilience means in Europe today: not restoring everything at once, but knowing what must keep running, what must recover first and who has the authority to make those choices. And it starts at the top.
About the Authors
Harpreet Sidhu is the Global Cybersecurity Lead at Accenture
Giovanni Cozzolino is the EMEA Cybersecurity lead at Accenture
Yusof Seedat is the Global Cybersecurity Research and Though Leadership Lead at Accenture







