Definition

Cyber resilience is an organisation's ability to withstand a cyberattack, continue operating during the incident and recover quickly afterwards. It broadens conventional cybersecurity. The goal is not only to prevent an attack, but also to survive one that succeeds.

Cybersecurity and cyber resilience: the difference

Cybersecurity focuses on prevention and detection: stopping intrusions and identifying attacks. Cyber resilience starts from the fact that defences can be bypassed, then organises continuity and recovery. The two complement each other. Resilience extends security; it does not replace it.

Why resilience is the decisive control

Prevention and detection are essential, but they do not replace a recovery plan. If production is compromised, the organisation must be able to restore systems from dependable restore points that are disconnected from the production network and protected from tampering.

What practical cyber resilience requires

  • Tamper-protected backups: an append-only write path and software air gap prevent compromised credentials from overwriting or deleting restore points.
  • Fast recovery: instant cross-hypervisor recovery (R2V) restores systems within minutes.
  • Tested recovery: automated restore tests verify that backups are usable.
  • Hosting: with Full Cloud, data is distributed across two geo-redundant datacentres in France without transfer outside the European Union. An HDS option is available through an HDS-certified hosting partner.

Evidence from a real incident illustrates the result. An Oxibox backup and a legacy backup were running on the same network during the Dharma attack. The legacy backups were encrypted and rendered unusable, while the entire information system protected by Oxibox was restarted in under two hours. That is cyber resilience when it is put to the test.