Rhys Sharp, Solution Director at Six Degrees talks to us about how businesses can build their resilience to ensure they can maintain operations, respond to disruption and adapt to change.

Business resilience has traditionally been treated as a form of technical insurance. In many organisations, the goal has been simple: recover quickly when something breaks and minimise disruption.

That perspective is still deeply embedded. Research from the Six Degrees Business Resilience Index 2026 shows that nearly three-quarters of technology and security leaders define resilience primarily through a security lens. Yet when presented with a broader definition, 91% said they learned something new about what resilience actually involves.

The reason is clear. Modern organisations face a far wider range of risks than cyber threats alone. Operational disruption, third-party dependencies, supply-chain fragility, regulatory change, economic volatility and increasing technology complexity all shape whether a business can continue to operate effectively.

True resilience is therefore not just about protecting systems. It is about ensuring the organisation can maintain operations, respond to disruption and adapt to change.

The resilience perception gap

Despite growing awareness of broader risks, there remains a disconnect between how resilience is discussed at leadership level and how it is delivered operationally.

Almost all respondents in the Business Resilience Index research (97%) agreed that strong leadership and governance would improve resilience. Yet board-level commitment ranked only tenth among the factors organisations associate with actually delivering it.

This gap often leads organisations to overestimate their readiness. Resilience activities may exist within IT or security teams, but they are rarely embedded into strategic decision-making across the business. As a result, organisations can feel prepared until disruption reveals hidden weaknesses.

Understanding resilience maturity

Resilience is not a fixed state but a spectrum. Most organisations sit somewhere along a maturity curve made up of five stages:

  • At risk – highly vulnerable organisations with fragmented processes, limited planning and largely manual recovery capabilities.
  • Reactive – able to respond to incidents but unable to anticipate them, often experiencing repeated disruptions.
  • Stable – controls exist and major failures are less likely, but resilience is still process-driven rather than embedded into operations.
  • Agile – people, processes and platforms align to support rapid response and organisational flexibility.
  • Strategically resilient – resilience is embedded across governance, operations and innovation, supporting both performance and long-term growth.

Research suggests most organisations sit in the middle of this curve. They can manage disruption when it happens but lack the foresight, integration and adaptability required to move beyond reactive measures.

The five pillars of resilient organisations

Progress along the maturity curve depends on how well organisations integrate five core capabilities across their operations: Continuity, Security, Scalability, Efficiency and Innovation.

When these pillars operate in isolation, resilience efforts often remain limited in impact. When aligned across infrastructure, governance and strategy, they reinforce one another and create a more adaptable operating environment.

Among the five pillars, continuity consistently emerges as the most fragile.

The Business Resilience Index research shows that nearly one in three organisations (28%) are classified as At Risk in this area, while fewer than one in ten (9%) reach the Strategically Resilient level.

Operational data reinforces the challenge. Mean uptime across critical services in the past year was just 73%, meaning businesses experienced downtime more than a quarter of the time, whether planned or unplanned.

Mean Time to Recover (MTTR) also varies significantly between sectors. Technology companies report average recovery times of around 9.7 hours compared with an overall average of 6.7 hours, suggesting that their focus on client uptime could be coming at the expense of enhancing their own.

The findings highlight an important point: continuity cannot simply exist as a disaster recovery plan on a shelf. It must be embedded, tested and coordinated across the entire organisation.

Strengths and gaps across the other pillars

While continuity presents the greatest risk, the other pillars show a mixed picture of progress.

Scalability is relatively strong. More than half of organisations fall into the Agile or Strategically Resilient tiers, reflecting growing adoption of flexible infrastructure and cloud-based services.

Efficiency shows significant potential but limited maturity. Only 7% of organisations reach Strategically Resilient status, although 39% are progressing toward greater automation and smarter decision-making.

Innovation is widely present but rarely embedded. Nearly half of organisations operate at an Agile level, but just 2% integrate innovation deeply enough to achieve strategic resilience.

Security, while widely prioritised, still has room for improvement. Only 5% reach the Strategically Resilient tier, even though most organisations cluster at the Agile stage.

Different sectors, different pressures

Resilience challenges also vary significantly between industries.

Financial services organisations often demonstrate stronger resilience profiles due to strict regulatory oversight, structured governance and consistent investment in operational stability.

Manufacturing organisations, by contrast, tend to sit closer to the middle of the maturity curve. Operational intensity and complex supply chains make resilience harder to embed, resulting in higher numbers of organisations classified as At Risk and fewer reaching Agile levels.

Technology companies face another challenge entirely: managing the complexity of large-scale digital environments while maintaining speed and innovation.

These differences highlight that resilience strategies must be tailored to the operational realities of each sector.

The growing role of automation and AI

Technology priorities are also evolving. The Business Resilience Index research shows that automation and AI are now viewed as the most important drivers of resilience, ranking above traditional incident response, recovery and continuity planning.

These technologies allow organisations to detect issues earlier and respond more quickly by reducing reliance on manual processes that can slow recovery. They also enable more continuous, data-driven operations that help anticipate risks before they escalate.

However, infrastructure limitations can still create bottlenecks. Many organisations report that existing resilience strategies cannot scale quickly enough during sudden demand spikes or operational disruptions. Ensuring platforms and services can adapt rapidly is therefore becoming a central focus of resilience strategies.

Turning resilience into a growth platform

The most resilient organisations approach the challenge differently. Rather than treating resilience purely as a defensive safeguard, they see it as an operational capability that supports growth and adaptability.

In practice, this means embedding resilience into everyday operations and decision-making. High-performing organisations design systems that can sense operational signals and emerging demand, allowing them to identify opportunities as well as risks. Continuity is treated as routine operating hygiene, with systems tested regularly and responsibility shared across the organisation rather than confined to IT teams.

They also build scalability directly into system design through elastic infrastructure, self-service capabilities and automation, enabling the business to respond quickly to change without unnecessary friction. At the same time, efficiency is driven by cost transparency rather than simple cost-cutting, helping leaders invest where resilience clearly delivers value. Finally, innovation is actively protected through governance and resource allocation, ensuring experimentation and future-readiness remain part of the organisation’s long-term strategy.

Together, these practices transform resilience from a reactive safeguard into a strategic platform that enables organisations not only to withstand disruption but also to evolve and grow in response to it.

By Rhys Sharp, Solution Director, Six Degrees.

  • Risk & Resilience

Richard Ford, Chief Technology Officer at Integrity360, on why cybersecurity must move beyond control and embrace trust

Cybersecurity has long been focused on building walls, but the biggest threat is already inside. Today, insider risk accounts for nearly half of all data breaches. This isn’t just about malicious actors, it’s about regular employees and trusted contractors who make simple, costly mistakes.

Remote and hybrid working has only intensified the problem. With teams distributed and work happening across cloud platforms and collaboration tools, it’s harder than ever to track what’s happening, let alone why. Although AI tools promise efficiency, they also introduce new vulnerabilities. Employees pasting code into chatbots or bypassing corporate tools to meet deadlines. All seemingly innocent, but highly risky.

Insider Risk

Ransomware gangs know this and are now skipping the technical breach altogether and going straight to the source – a company’s insiders. Whether through bribery or social engineering, attackers are finding that humans can be the weakest link in even the most well-defended environments. Despite this, most security budgets still focus outward.

Traditional tools like data loss prevention (DLP) struggle to keep up with today’s dynamic and unpredictable user behaviour. Meanwhile, simulated phishing tests and punitive training schemes often breed resentment, not resilience. It’s time to rethink the model.

Human Error, Human Fix

We need to stop treating employees as the problem and start making them part of the solution. Enter Human Risk Management (HRM), a behavioural approach to cybersecurity that recognises the complexity of modern work. HRM tools monitor real-world user behaviour, detect anomalies in context, and deliver just-in-time nudges to prevent risky actions before they happen. Instead of punishing mistakes, they help users avoid them in the first place.

Of course, technology alone won’t fix the issue, culture is key. Leadership must champion security as a shared responsibility, not an IT rulebook. Success should be measured by how quickly employees improve, not how often they slip up. Awareness campaigns need to be practical and rooted in real-world behaviour.

Organisations also need to understand how digital transformation has changed the risk landscape. Shadow IT is no longer a fringe issue, it’s how work gets done. Whether it’s a developer using an AI plugin or a marketer sharing files via a personal drive, employees will always find the fastest path to productivity. Security must meet them there, not block the way.

Cybersecurity Built on Trust

The smartest businesses are those that treat identity like infrastructure, and behaviour like a vital data stream. They invest in tools that adapt to people, not the other way around. This means a move away from a surveillance approach and embracing the nuance of human error and design systems that support.

In a world where threats are increasingly internal and AI is both a risk and a tool, cybersecurity can no longer be about control. It must be about trust, and that starts with understanding the humans behind the keyboards.

Learn more at integrity360.com

  • Cybersecurity
  • Cybersecurity in FinTech
  • Digital Strategy
  • Infrastructure & Cloud