Boland Lithebe, Cybersecurity lead for Accenture, South Africa
A cyber incident rarely stays in the IT department. When a critical system goes down, a supplier is compromised or data becomes unavailable, the consequences are felt across the business. Customers may be unable to access services, employees may be unable to work and management may have to make difficult decisions with incomplete information.
Yet cyber resilience is still often treated as a technology or security responsibility. That is one of the issues highlighted by the Accenture research, which found that 74% of organisations see cyber resilience as primarily the responsibility of security or IT, while only 43% fully govern it as a shared business outcome.
The distinction matters. Security controls are designed to reduce the likelihood and impact of an attack. Resilience asks a different question: if those controls fail, can the business continue operating and recover its most important services quickly?
That question is becoming harder to answer as organisations rely on increasingly complex technology ecosystems. Cloud services, AI, digital platforms and third-party providers are now closely woven into everyday operations. The research found that 69% of organisations say their operations are becoming more dependent on complex internal and external digital ecosystems, while 61% say their ability to sustain critical operations is influenced by external dependencies.
That has obvious relevance in South Africa, where businesses across sectors are increasingly dependent on digital services and interconnected supply chains. A disruption at a technology or service provider does not have to originate inside an organisation to create a serious operational problem. The responsibility for securing a third-party system may sit with the supplier, but the impact of its failure can still sit with the customer.
This is why the relationship between the CEO and CISO matters. The security team can explain the threat, the controls and the technical recovery options. Business leadership needs to decide what matters most, what level of disruption is acceptable and where recovery effort should be focused first. Those decisions are difficult to make during an incident, which makes it important to agree on them beforehand.
The research points to some uncomfortable assumptions. While 87% of organisations believe regulatory compliance ensures cyber resilience, only 35% regularly test resilience through actual recovery and continuity exercises rather than audits. Compliance remains important, but passing an audit does not tell a leadership team how the business will function when critical systems are unavailable.
The same applies to incident response. Detecting and containing an attack is essential, but it does not necessarily mean the business is ready to recover. Almost all organisations in the research, 98%, regard rapid detection and containment as a sign of operational resilience. Yet only 40% have predefined and tested recovery paths for critical systems.
The gap between response and recovery can become expensive. Leadership teams need to know which operations must be restored first, who has the authority to make recovery decisions and what trade-offs may need to be made while systems are unavailable. These are business decisions as much as technical ones.
Third-party dependencies deserve particular attention. Only 38% of organisations have a clear view of their value chain and its most critical dependencies, despite the importance of external partners to business continuity. Contracts can establish obligations between organisations, but they cannot guarantee that a service will be available when a disruption occurs. Businesses need to understand the dependencies that sit behind their most important services and how those dependencies could affect recovery.
There is also a need to rethink how recovery itself is designed. Organisations should have a recovery environment that can operate under hostile conditions and contain the information and resources needed to rebuild critical systems. Where practical, automation can reduce the time required to restore services. These capabilities should be tested regularly rather than assumed to work when an incident occurs.
The starting point is not another security tool. It is a conversation among business and technology leaders about what the organisation cannot afford to lose. Once those priorities are clear, the business can map the dependencies behind them, agree on recovery decisions and test whether its plans work under realistic conditions.
Cyber resilience is ultimately about protecting the ability to operate. That makes it too important to sit within a single function. The organisations best placed to manage disruption will be those where business leaders and security teams have a shared understanding of what needs to survive, how it will be recovered and who will make the decisions when normal operations are no longer possible.
ENDS






