COO's Guide to Cyber Resilience : Introduction
What is Cyber Resilience? This is the organisations ability to keep delivering its essential services through a cyber attack or technical failure and to recovery and adapt afterwards.
In this coming series of briefings we reflect on the COO and the changing face of Cyber Resilience.
Many organisations still treat cyber security as an IT problem that operations inherits when something goes wrong. But cyber is a specialist discipline that belongs inside the resilience governance which every business already needs, and the COO is usually the executive best placed to run it.

When Marks & Spencer suspended online service for around six weeks, distribution fell back on manual processes and food shelves emptied. The retailer estimated a hit of around £300m to operating profit, and half year profit fell 55% even after a £100m insurance recovery.
Jaguar Land Rover had to stop building cars. The Cyber Monitoring Centre put the cost to the UK economy at £1.9bn across more than 5,000 organisations. That same month, check in at Heathrow, Brussels and Berlin went back to manual processes after an attack on a check in supplier the airports shared. None of the airports had been breached themselves.
This week Denmark is investigting a data berach affecting 8.8 million people after security failed on its national population register, as intruders used a thord party to gain legitimate access to the Central Person Register (CPR) which compromises names, addresses and personal data.
In each case the technical incident was only the start. Within hours it had become a continuity, supply chain and crisis management problem, and that is where most of the cost landed. It is the strongest argument I know for governing cyber as part of resilience rather than leaving it in a technical silo.
Governance has Already Moved
The UK Cyber Security and Resilience (Network & Information Systems) Bill, currently in the House of Lords, extends regulation to managed service providers and introduces the concept of a 24 hour initial reporting clock. Financial services firms are further along: DORA and the UK operational resilience regime already handle technology risk, third party risk and incident management within a single framework.
This is built ontop of existing good practice and the UK Cyber Governance Code of Practice, published by DSIT and the NCSC in April 2025, idefining five board level principles: risk management, strategy, people, incident planning and assurance. Anyone who has built a resilience programme will recognise those headings.
I should be careful not to overstate this. Cyber is not just another continuity risk. Attackers adapt, the technology moves quickly and the specialist knowledge runs deep, so a business that treats cyber purely as a recovery problem will end up under investing in prevention. What I am arguing for is for this specialist discipline, with its own expertise and resource, to be governed through the resilience framework.
Why the COO
The COO already owns most of what a cyber attack actually breaks, from the services customers rely on to the suppliers who deliver them and the plans for keeping them running.
Nobody can promise to stop every attack, and I would be wary of anyone who did. A more useful ambition is that no single attack can stop the business. Framed that way the subject becomes far less intimidating, and the COO has something that can be measured. How long would each critical service take to recover, and how long could the business tolerate it being down?
More and more of the threat now arrives through suppliers. Third Party Risk Management (TPRM) is the fastest growing part of resilience maturity, and cyber has its layered responsibilities here.
The 2026 Verizon Data Breach Investigations Report found third parties were involved in 48% of breaches, a 60% rise on the previous year. A security questionnaire filled in once at onboarding was never designed for that. Managing it means linking cyber properly with third party risk, continuity and crisis management.
What this Series Covers
This piece introduces a three part guide written specifically for COOs and the boards they report to.
• Part 1: Why Cyber belongs inside Resilience. What is the difference between Cyber Resilience & Cyber Security. What recent attacks tell us, where regulation is heading, and how cyber fits alongside third party risk, continuity, crisis management and enterprise risk.
• Part 2: What are the Three R’s of Cyber Resilience. How to protect, contain and recover. The five disciplines that matter most, how to structure and measure the function, and twelve questions to put to your team, along with the answers that should worry you.
• Part 3: Risks, Rewards, AI and Next Steps. Where investment pays back, what AI changes for defenders and attackers look like, and a practical plan for the first 30, 90 and 180 days and what this is built on.
Three questions to ask your teams this week
1. Which services would hurt us most if they stopped for a week, and how long can each be down before the harm is intolerable?
2. When did we last restore critical systems from backup, end to end, and how long did it take?
3. Which of our suppliers could stop those services, and would they tell us within 24 hours if they were breached?
If you can answer all three with evidence, you are in better shape than many organisations. If the honest answer is that someone has assured you it is fine, the rest of the series is written specifically with you in mind.
Chris Oliver FBCI is Principal Director of Armstrong Resilience, a Channel Islands advisory and software business specialising in resilience, business continuity, risk managemen, cyber securityt and third party risk management. He is an industry speaker, co author of industry good practice guidelines, operational resilience frameworks and ISO contributor.




Comments