Cybersecurity

Why cyber resilience depends on trust

Cyber resilience requires ecosystem partners to work together when trust in shared platforms is challenged.

Cyber resilience must evolve beyond recovery to verification, and maintaining trust is key. Image: Getty Images/iStockphoto

Mark Orsi
Chief Executive Officer, Global Resilience Federation
Keri Pearlson
Principal Research Scientist, MIT - Sloan School of Management
Luna Rohland
Specialist, Cyber Resilience, World Economic Forum
This article is part of: Centre for Cybersecurity
  • The next cyber crisis may be a crisis of trust, not downtime, as compromised data can disrupt critical decisions even when systems remain online.
  • Cyber resilience must evolve beyond recovery to verification, and businesses must be able to operate safely when trust in shared platforms is challenged.
  • Collective resilience will be vital, with collaboration between organizations and their ecosystem partners essential to keeping critical services running.

Information is at the heart of every organization. Business is conducted digitally because we trust systems and the shared information on which they are based to be accurate and reflect real-world activity.

Cyber incidents interfere with this data flow by compromising or manipulating information and disrupting decisions that depend upon it – be the disruption internal or from external parties including customers, suppliers and partners.

In such situations, the consequences come not only from downtime while systems are repaired, but also from the erosion of trust underpinning business relationships and shared digital ecosystems.

Trust in shared dependencies

Cyber resilience has long focused primarily on availability, recovery and restoration efforts when systems stop working. Those capabilities remain essential, but attacks that undermine the integrity and authenticity of information can be equally disruptive.

In such scenarios, organizations may continue making decisions using data that is inaccurate, manipulated or unverified and, in an interconnected digital economy, the consequences can cascade across companies and sectors.

Modern economies and the critical infrastructure on which they run depend on trust in digital information and the transactions built upon it. Organizations rely on software platforms to process transactions, cloud providers to store information, suppliers to provide accurate operational data and digital networks to coordinate complex supply chains. These systems function not only because the technology works, but because the information flowing through them is trusted.

Loading...

When that confidence is disrupted, the consequences extend well beyond a technical outage. A system may remain online while managers can no longer determine whether the information guiding critical decisions is accurate, complete or safe to act upon. In these situations, restoring confidence in information becomes just as important as restoring the technology itself.

Recent incidents show how quickly trouble in a shared dependency can spread. In July 2024, a faulty CrowdStrike software update by a trusted supplier affected 8.5 million Windows devices worldwide, grounding flights, halting banking services and disrupting healthcare and highlighting the risks of concentration and systemic dependency.

Recovery required more than technical remediation. Within an hour, members of the Global Resilience Federation's cross-sector Business Resilience Council were collaborating over a secure channel, building on the trusted relationships built over time by the community. Soon after, CrowdStrike’s CEO briefed more than 1,000 organizations in another trusted forum, providing a response that depended on, and built on, relationships, pre-established playbooks and trusted channels.

When systems work but information cannot be trusted

An even more difficult crisis occurs when systems continue operating but the information moving through them can no longer be trusted.

A recent cyber resilience exercise at the World Economic Forum's Annual Meeting on Cybersecurity 2026 centred on a long-established business-to-business platform routing digital orders, shipments and invoices across a large ecosystem of trading partners. During the exercise, the widely trusted platform began behaving unreliably, creating uncertainty about whether the information it carried could still be believed.

Have you read?

Participants had to determine whether transaction data remained reliable, whether customer commitments should be honoured, what assurance was needed before reconnecting, and how much uncertainty could be tolerated before action became necessary.

These issues sat at the intersection of cybersecurity, operations, legal, risk, communications and executive decision-making. Leaders had to act before certainty was available and reassess the trust they could place in a partner or platform previously considered reliable.

AI makes the trust problem more consequential

As artificial intelligence (AI) becomes increasingly embedded across business processes, it only intensifies the cyber challenge faced by organizations.

Unlike a conventional outage, an impaired AI service may continue responding while producing inconsistent recommendations, misleading summaries, unexpected actions or subtly corrupted outputs. Surrounding applications can appear to function normally even as confidence in the decisions they support deteriorates.

The Business Resilience Council’s multi-sector exercise AI Interrupted, developed with Google and Anthropic, involved a simulation of an impaired AI application programming interface (API) gateway causing unusual behaviour across an enterprise's internal systems and external software-as-a-service (SaaS) platforms.

Participants had to decide whether to reduce AI usage, disconnect capabilities or continue operating while the cause and scope remained uncertain, as well as determine which outputs remained trustworthy, which processes could operate safely without AI, who could constrain or disable AI capabilities, and what evidence was required before reconnecting.

The exercise exposed significant readiness gaps:

  • Only 3% of respondents had defined minimum viable service levels for AI degradation or failure
  • 80% did not know the minimum AI capability required for their tools to be deemed usable again
  • Just 6% had complete data-flow diagrams showing how generative AI was used within critical business services

The emerging principles are clear: Organizations must verify an AI service’s outputs and downstream impacts, not just restore it, and that technical availability is meaningless without operational trust.

From collective defence to collective resilience

The World Economic Forum's Global Cybersecurity Outlook 2026 reports that 65% of large organizations cite third-party and supply-chain vulnerabilities as their greatest cyber resilience challenge.

The report also highlights the dangers of concentration risk, where incidents impacting major cloud, internet or shared-service providers can have widespread downstream effects, including uncertainty about the information flowing through those systems. A platform can be technically restored without being operationally trusted.

Loading...

Collective defence practices, such as sharing threat intelligence, vulnerabilities and mitigation strategies across trusted communities remain essential. But the next step is collective resilience: enabling organizations to continue delivering critical services together when a shared dependency fails, degrades or can no longer be trusted.

This depends on pre-established relationships, secure communications channels, agreed escalation paths, shared expectations with critical vendors and exercises that test degraded operations across the ecosystem.

Indeed, organizations rated as highly resilient were nearly three times more likely to conduct cyber exercises with ecosystem partners than organizations with insufficient resilience, according to the Global Cybersecurity Outlook 2026.

Six ways organizations can boost cyber resilience now

Trust is essential for business recovery and organizations should establish the relationships, decision processes and verification mechanisms they will need before a crisis occurs:

  • Assign executive ownership: Designate a leader responsible for strengthening trust, transparency and resilience across critical partner relationships.
  • Map shared dependencies: Identify external platforms, cloud services, AI models, SaaS providers and digital networks and plan for scenarios in which they become unreliable or untrusted.
  • Define decision rights in advance: Assign decision-makers (primary and secondary) and organizational protocols for disconnecting a service, constraining an AI capability or approving reconnection.
  • Establish trusted communications: Create secure, out-of-band channels and relationships with vendor counterparts to compare observations, verify information and coordinate action when ordinary communications or shared platforms cannot be trusted.
  • Invest in verification, not only restoration: Develop capabilities to verify the integrity, authenticity and provenance of data, transactions and automated actions. Ensure that recovery proves that systems and downstream processes are both available and trustworthy and communicate verification methods to critical partners.
  • Exercise together: Practise multi-party simulations where systems are degraded with vendors and platform partners to uncover decision gaps and strengthen resilience.

Cyber resilience has traditionally been measured by how quickly systems can be technologically restored. However, in the future, resilience will be increasingly measured by how effectively organizations can verify information and sustain sound decisions when certainty is scarce.

As highlighted here, trusted relationships and multi-party exercises with ecosystem partners to address gaps in trust while the stakes are still hypothetical will be key to mitigating the impact of future cyber crises.

Don't miss any update on this topic

Create a free account and access your personalized content collection with our latest publications and analyses.

Sign up for free

License and Republishing

World Economic Forum articles may be republished in accordance with the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International Public License, and in accordance with our Terms of Use.

The views expressed in this article are those of the author alone and not the World Economic Forum.

Stay up to date:

Cybersecurity

Share:
The Big Picture
Explore and monitor how Cybersecurity is affecting economies, industries and global issues
World Economic Forum logo

Forum Stories newsletter

Bringing you weekly curated insights and analysis on the global issues that matter.

Subscribe today

More on Cybersecurity
See all

Why a sustainable finance mechanism for cybersecurity is key to securing the global economy

Global Future Council on Cybersecurity

August 3, 2026

3:29

The biggest threats to cybersecurity today, according to 5 experts

About us

Engage with us

Quick links

Language editions

Privacy Policy & Terms of Service

Sitemap

© 2026 World Economic Forum