Digital Resilience: How a Company Remains Operational Even in an Incident

Digitalisation brings enormous advantages, but also new risks. What does it mean to be digitally resilient today?

In recent years, we have become accustomed to information, data, and business processes always being available. This is precisely why digital resilience is becoming one of the key competitive advantages of modern companies.

Being digitally resilient today does not mean merely preventing attacks or outages. It means being prepared for the moment an incident occurs and still maintaining business operations. The question is no longer whether a company will experience a disruption at some point, but how quickly it will be able to continue operating afterwards.

The most resilient companies are not those that never encounter problems, but those that know how to respond to them quickly and effectively.

Are attackers primarily targeting large companies?

This is one of the biggest myths.

Today, attackers do not necessarily look for the largest companies. They look for the easiest route to data, financial gain, or business disruption. Automated tools scan millions of systems around the world every day, looking for vulnerabilities. Company size is often not the deciding factor.

Small and medium-sized companies may be even more exposed, as they generally have smaller teams and limited resources for risk management.

Any company that uses information systems, email, customer data, or business applications is a potential target.

How is artificial intelligence changing the field of cybersecurity?

Article Image

Artificial intelligence is changing the rules of the game on both sides – in attack and in defence. On the one hand, it enables attackers to prepare fraudulent messages more quickly, automate attacks, and identify vulnerabilities. On the other hand, it helps organisations detect irregularities faster, analyse large volumes of data, and respond to incidents more effectively.

I believe that in the coming years, artificial intelligence will become an important component of systems for identifying risks and protecting business operations. Nevertheless, people, processes, and responsible company leadership remain crucial.

Technology alone has never solved a problem without a clear strategy.

Does a company need its own cybersecurity specialist?

Not necessarily.

Just as most companies do not build their own data centre, it does not always make sense to build an entire security team in-house.

Many organisations today successfully use external experts and specialised partners for security, monitoring, system recovery, and risk management.

However, it is important to understand one thing: responsibility cannot be outsourced. You can entrust the delivery of certain services to a partner, but responsibility for business risks and organisational resilience always remains with the company’s leadership.

What should a company do when a serious incident occurs?

The biggest mistake is improvisation.

When an incident occurs, a company must know:

This is why Business Continuity Planning (BCP) and Disaster Recovery (DR) plans are now far more important than technology alone.

Companies that have prepared plans and test them regularly generally recover from incidents much faster and with less business damage.

How can a company verify whether it would actually be able to continue operating after a serious incident?

The simplest answer is: test your plans.

Many organisations have backups. Far fewer regularly verify whether they can actually restore their systems within the time required by the business.

I recommend three steps to every company:

Article Image

1. Identify what is truly critical to your business. Not all systems are equally important.

2. Prepare a Business Continuity and Disaster Recovery plan. Not just a document, but an actual implementation plan. It is important to distinguish between a backup and a disaster recovery solution.

3. Conduct regular tests and exercises. A plan that has never been tested is merely an assumption.

What will be the biggest challenge for companies over the next five years?

In the past, we mainly talked about digital transformation, cloud solutions, artificial intelligence, and cybersecurity. In the future, we will talk about digital business resilience.

Alongside growth, innovation, and digitalisation, companies will also need to ensure security, regulatory compliance, and business continuity. NIS2 and DORA requirements are only the beginning of a broader trend in which managing digital risks is becoming an integral part of corporate governance.

Companies that incorporate digital business resilience into their business strategy will be more competitive, more trustworthy, and better prepared for future challenges in the long term.

“Successful companies are not those that never experience an incident. Successful companies are those that know how to continue operating quickly and retain the trust of their customers even in the most demanding circumstances.”

Aleksej Kranjec

CEO, HC Center d.o.o.

Aleksej Kranjec

Connect with me