Insights

Reflections on cyber resilience in 2025

We seem to be at an inflection point for globalisation. After decades of ever-increasing global interconnection, the narrative around global trust has shifted and governments are speaking candidly about focusing on national capability over international trade and questioning the reliability of allies and institutions. What does this mean for cyber security in 2026 and beyond?

Technological resilience

In 2024, CrowdStrike’s failed patch caused a major outage of global IT – with direct financial losses reportedly topping 5.5 billion USD. In 2025, we saw disruption as AWS in the US-East-1 region caused knock-on impacts across government services, social media, gaming and finance, and issues with Cloudflare (November 2025) further emphasised how much the digital world relies on shared infrastructure.

This concern extends to all categories of infrastructure. Multiple grid blackouts this year forced everyone to acknowledge that almost all infrastructure is part of a complex and growing web of interdependencies. The absence of quick answers when asking why something has happened suggests that no one really understands the intricacies of that web.

Will AI make it worse? 

AI is still touted as the universal accelerator, and there is no reason to think it will not further expedite technological dependencies. A network of AI agents, for example, each learning from similar data sets, acting of their own accord, referencing each other, and pressing for ever-quicker results could provide enormous benefits – as well as new and unpredictable resilience risks. Cast minds back to the High Frequency Trading crash in 2010 when a series of autonomous trading algorithms all pulled back at the same time in response to a market fluctuation as they were in competition for limited resources. They acted faster than humans could intervene. This created a market failure no one could have anticipated, even in a highly regulated and observed industry.

As we think about deploying AI agents in other areas with lower regulation and observation (we’re thinking specifically in operational technology (OT)), we must ask if we are opening ourselves up to accelerated cascading failures. What happens, for example, if an AI security system sees a different AI optimisation system as an attack?

Where does responsibility sit?

What is needed at national level? 

The sheer scale of the cyber resilience challenge can only be addressed at the national level. In the UK, the government is floating the Cyber Security and Resilience Bill; across Europe we’ve seen NIS 2 and DORA try to implement resilience for specific industries; in Australia there is the Security of Critical Infrastructure Amendment Act; and partners of the Indo-Pacific Economic Framework for Prosperity (including India, Indonesia, Thailand, the Philippines, and South Korea) are focusing on supply chain resilience. But will this make a difference or is this just ‘compliance theatre’?

And change cannot be immediate – the UK’s efforts to quickly remove Huawei infrastructure from London mobile networks resulted in a notoriously patchy network. Now, as Europe and the world consider alternatives to US cloud providers, we need to manage expectations. Building resilience on a national scale will take decades, and colossal national funding.

So what should organisations do? 

At the organisational level, cyber resilience is also pressing. Very few companies have the clout to insist on minimum standards for security and resilience from their customers. Although some of the behemothic players may be able to demand enforcement of specific controls, even they will struggle to push requirements downstream to fourth parties (and beyond). The truth is, we rarely see third-party risk management enforced well. Organisational documentation on supply chain risk is largely aspirational and doesn’t reveal the truth of what’s being implemented. Defining the real situation requires time, nuance, and does not lend itself to the scale of real business networks.

The risk can also propagate in your upstream dependencies. The Jaguar Land Rover (JLR) incident earlier this year halted production and left suppliers waiting for payment, eventually necessitating a government-backed guarantee of supplier payment.

If you can’t increase the security of your supply chain, what can you do to increase your own cyber resilience? At a business level, this will broadly mean thinking about redundancies, workarounds, and the amount of money you are willing to spend to reduce the risk of a major crisis. This money may feel like throwing good after bad until and unless you really face such a situation. The financial calculations here should include immediate financial impact, but also reputational impact, customer churn, and the potential operational backlog if you do have to recover or fail over. For most organisations, the decision may be “some redundancy for critical paths, acceptance of risk everywhere else.” So, what are these critical paths – what really matters?

What is the best approach?

Prevention verses cure

Resilience, like cyber security, combines the need for prevention and cure. In both cases, you cannot invest entirely in one option – we all want to live healthy lifestyles to reduce the risk we will need major, expensive, and traumatic care when something does go wrong, but we can’t bet the house on never getting sick.

The CrowdStrike incident is a good example to consider in this regard – organisations that did everything ‘right’ by outsourcing endpoint security to a best-in-class provider were impacted by that provider’s mistake. Could those impacted organisations have foreseen that risk and worked around it Would it have been feasible for organisations to run a separate EDR on backup environments? This would take enormous foresight, cost, and administrative time and expertise. It’s just not practical. Do you really want to double your infrastructure costs just in case something goes wrong?

The goal should perhaps be to increase executive-level understanding of what risks are to be accepted and why. Outsourcing does not eliminate exposure, and tech carries inherent risk. Always.

Equally, organisations must spend time on prevention – those protective controls that decrease the chances that something will go wrong. These are often tedious, unglamorous, and don’t make compelling stories, but are vital, and are almost always less expensive than fixing something once it’s broken.

Everything integrated all at once 

So where will resilience go next? Zero-trust has been the ideal access model for organisations for many years now. Is the next step in resilience a zero-dependency, or even a ‘minimum viable dependency’ model – a spectrum of compromises you take to reduce your dependency on other infrastructure and services? There are some fascinating projects out there that are working to build increasingly complex software and systems that do not rely on libraries, services, or the infrastructure of others. But these still require exceptional people, and there is little proof that they can be scaled for large businesses.

Perhaps we should reset our expectations for the complexity of our software. Outlook doesn’t need to make POST requests on our behalf, and not all software needs constant internet connection to make live updates.

2026 is a chance for organisations of every size and sector to make a strategic choice. Ask yourself this: how do we balance agility with exposure? Do you want your company to be agile but vulnerable to the failure of a single link in a very long chain, or strong on its own, but limited in its capability for growth What’s the middle ground?

Contact us

If you would like to discuss any of the themes raised in this article, or to hear how we are supporting organisations across sectors and geographies to become more resilient, please do not hesitate to reach out:

Kate O’Loghlen, Head of Cyber  

kateologhlen@g3.co