This HotTopics C-suite Food for Thought, in partnership with Veeam, brings together CIOs, CISOs, and senior leaders to explore the difficult decisions shaping modern resilience strategies, and what separates organisations that view resilience as a cost centre from those that treat it as a competitive advantage.
As organisations accelerate AI adoption, expand cloud estates and increase their dependence on data-driven operations, resilience is becoming a strategic differentiator rather than a defensive capability.
Resilience, however, comes with choices. Greater assurance may mean higher cost; stronger controls may reduce agility; more testing may compete with innovation priorities. For technology and security leaders, the challenge has become far more nuanced: resilience matters, but which trade-offs are justified to achieve it.
Which trade-offs are actually worth making for modern business resilience?
Here’s what we learned:
Resilience is no longer an IT issue; it is an operating model issue.
The discussion repeatedly distinguished recovery from resilience. Recovery restores what has failed; resilience is the ability to continue operating through disruption
Executives need to define the minimum viable business.
Most organisations cannot protect everything equally. A more useful question is: which processes, systems, people and data remain available for the organisation to continue delivering on its core purpose? Several participants argued that businesses often misidentify what is genuinely critical.
Legacy assumptions may now be creating risk.
Systems and data are often still classified according to decisions made years ago, even where their business importance has changed. Resilience therefore requires regular reassessment of what the organisation is protecting—and why.
Readiness matters as much as resilience and recovery.
Plans on paper offer limited protection if leadership teams have not rehearsed how they will respond. Decision rights, communications, escalation paths and executive responsibilities need to be tested before an incident occurs.
People are part of the resilience architecture.
Incident response can run for weeks, placing sustained pressure on executives and operational teams. Human capacity, fatigue and decision quality therefore need to be treated as resilience risks in their own right, rather than as secondary considerations.
Your resilience is increasingly dependent on organisations you do not control.
Cloud, SaaS and extended supply chains mean that internal preparedness is only part of the equation. Executives also need visibility into the resilience of critical suppliers and the dependencies beneath them.
Regulation is shifting the emphasis towards demonstrable accountability.
DORA, NIS2 and emerging UK requirements are increasing expectations around ownership, due diligence and third-party oversight. Perfect protection may be unrealistic; the ability to demonstrate responsible preparation is becoming increasingly important.
Traditional organisational silos are poorly suited to resilience.
Security, technology, operations, risk and data have historically made decisions separately. The discussion pointed towards a more integrated model in which those functions jointly evaluate cost, risk, customer impact and operational value.
AI raises the stakes because it depends on the same foundations resilience requires.
Organisations pursuing AI productivity gains need to understand their data, access controls and critical systems. Weaknesses in those foundations simultaneously constrain AI value and increase operational exposure.
The investment case for resilience must be expressed in business terms.
Boards respond more clearly to revenue at risk, inability to serve customers, regulatory exposure, reputational damage and human consequences than to technical measures alone. Resilience becomes easier to prioritise when its value is linked directly to business outcomes.
Has your organisation consciously decided what must continue, what can temporarily fail, and how it will respond when those trade-offs are tested? If not, the business has not considered the modern interpretation of business resilience. It’s past time to do so.
Resilient Leadership
In partnership with Veeam
Created in partnership with Veeam, Resilient Leadership brings technology and business leaders together to protect critical data, recover with confidence and keep business running through disruption.
SUBMIT A COMMENT
RELATED ARTICLES
Why the next innovation in marketing is human | Patricia Mestra, Microsoft
05 Oct 2026
Join the community
To join the HotTopics Community and gain access to our exclusive content, events and networking opportunities simply fill in the form below.
