Cybersecurity

Four ways organizations can collaborate on cyber resilience

Digital security and privacy background. Cyber and crypto security shield on futuristic screen technology background. cyber resilience

Trusted digital ecosystems are built on cyber resilience. Image: Getty Images/da-kuk

Sander Zeijlemaker
Research Affiliate Cybersecurity, MIT Sloan (CAMS), Managing Director, Disem Institute
Michael Siegel
Principal Research Scientist and Director, MIT CAMS
This article is part of: Centre for Cybersecurity
  • As artificial intelligence (AI) enables cyber risk to move at machine speed, the gap between organizations' risk management capabilities and the disruption bad actors can cause is growing.
  • Interconnectedness is also making cyber risk systemic, allowing any disruptions to cascade across the digital ecosystems that underpin society.
  • Cyber resilience must evolve so that it can adapt alongside technology in order to create trusted digital ecosystems.

Digital transformation and artificial intelligence (AI) are reshaping cyber resilience.

As AI accelerates cyber risk at machine speed, many organizations are struggling to keep up with adversaries that can automate reconnaissance, vulnerability discovery, exploitation and data analysis.

This expands bad actors’ reach while reducing their costs and need for human intervention. It also creates a growing defence gap. Adversaries can rapidly adopt and adapt AI, but defenders such as governments, hospitals and companies are more likely to face budget, talent and technology, as well as regulatory requirements.

Have you read?

At the same time, interconnectedness is transforming cyber risk into a systemic risk because it enables disruptions to cascade across organizations and sectors.

Incidents such as the AWS outage in October 2025 and the Salesloft Drift supply-chain breach earlier that year demonstrate how failures in one organization or technology provider can have consequences far beyond their immediate boundaries. Adverse AI use can rapidly exploit shared infrastructure and dependencies, scaling disruption faster than organizations can effectively respond.

As a result, trust is becoming a critical condition for cyber resilience. In interconnected and AI-driven ecosystems, trust in the integrity of systems, data and autonomous actions is as critical as technical reliability because organizations must rely on technologies and partners they do not fully control.

Beyond individual resilience, or even coordinated resilience across organizations, the real challenge for today’s organizations is to make cyber resilience an adaptive property of the digital ecosystems on which economies and societies have increasingly come to depend. This includes healthcare digital ecosystems comprised of multiple hospitals, labs and suppliers, for example, or energy ecosystems mad up of multiple utilities, grid operators and technology providers, among others.

The organizations in these digital ecosystems must continuously understand dependencies, anticipate disruption, enable trusted action and learn across organizational boundaries.

Figure 1. Moving Toward Resilient Digital Ecosystems
How to build cyber resilience into digital ecosystems. Image: Created by Sander Zeijlemaker using AI.

Creating resilient digital ecosystems

Realizing this vision requires connecting intelligence, governance and defensive capabilities across and between organizations without compromising sovereignty or creating new systemic vulnerabilities.

Four capabilities can help organizations build more resilient digital ecosystems:

1. Understanding how cyber disruption can develop

Digital resilience is about more than mapping dependencies, it means understanding how they evolve and influence systemic risk. Understanding this helps organizations continuously connect critical services, technologies, suppliers, threats and operational contexts.

This dynamic intelligence can reveal cascading failure pathways, assess the ecosystem-wide blast radius of cyber incidents, support scenario exploration, identify critical intervention points and prioritize investments to strengthen resilience.

Combining these foundations with threat intelligence and AI, helps organizations anticipate how emerging threats may propagate across digital ecosystems. This shifts cyber resilience from merely understanding dependencies to anticipating disruption and informing action in advance.

Organizations are already exploring this through AI-powered knowledge graphs for threat intelligence, dynamic detection of emergent threats and contextual monitoring of complex agent ecosystems. However, these approaches have yet to be integrated into living resilience models that anticipate cascading disruption across digital ecosystems.

2. Anticipating where cyber disruption may emerge

Organizations’ cyber defence must evolve beyond monitoring and preparing for known threats to allow companies to anticipate how emerging attacks could develop and propagate before disruption occurs.

Connecting threat intelligence, vulnerabilities and attacker behaviour with infrastructure topology and ecosystem context can reveal plausible attack pathways and how they may propagate. It can also identify intervention points where action could prevent or contain disruption. AI can analyze these relationships at a scale and speed, continuously translating evolving intelligence into organization-specific scenarios, priorities and potential interventions.

For instance, MIT researchers are developing AI-enabled adversaries that use cyber knowledge to plan and execute attack steps. Organization’s are also adopting elements of this approach through AI-powered threat intelligence, autonomous red teaming and AI-assisted threat hunting.

3. Enabling trusted action at machine speed

In an AI-enabled cyber resilience model, trust must increasingly apply to information and action. And organizations using autonomous models must be able to trust what systems report and whether they can be trusted to act at machine speed.

Governance must therefore evolve beyond periodic compliance to continuously define how autonomous systems can operate safely and responsibly. This requires setting clear decision rights, accountability and operational boundaries, including which decisions can be automated and when human intervention is required.

Organizations are already beginning to translate elements of this approach into practice through bounded agent authority, continuous assurance, human oversight and governance of autonomous AI. The next step would be to converge everything into a resilience-by-design model in which trusted autonomy becomes an operational capability while preserving accountability and human control.

4. Distributing cyber defence learning across organizational boundaries

Collective cyber resilience must go beyond sharing information to scale defensive learning across organizational boundaries. Secure-by-design architectures, interoperability and strong information-flow controls are critical to ensuring that collective defence does not result in new systemic vulnerabilities. This could lead to an ecosystem that becomes more resilient with every threat it encounters.

For instance, a Dutch cybersecurity lab connects universities and research organizations so they can share and jointly use distributed internet of things (IoT) security capabilities while retaining control of their local infrastructure. Organizations are already putting elements of this approach into practice through shared defensive knowledge, continuous learning from operational feedback and autonomous defensive agents.

Evolving cyber resilience

A resilient digital ecosystem continuously understands, anticipates, acts and learns as cyber risks evolve.

Organizations can start building cyber resilience today by connecting dependency, threat and operational data, while also testing disruption and propagation scenarios. They must also define the defensive decisions AI can make versus those where human oversight is required. And they must identify trusted partners for sharing defensive insights or capabilities.

The goal is not to create immediate autonomy, but to progressively build a more adaptive and resilient digital ecosystem.

Loading...

Abhishta Abhishta (Twente University), Alberto Quintavalla (Erasmus University Rotterdam), Florian Hahn (Twente University) and Cristoffer Leite (Technical University Eindhoven) also contributed to this article.

Don't miss any update on this topic

Create a free account and access your personalized content collection with our latest publications and analyses.

Sign up for free

License and Republishing

World Economic Forum articles may be republished in accordance with the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International Public License, and in accordance with our Terms of Use.

The views expressed in this article are those of the author alone and not the World Economic Forum.

Stay up to date:

Cybersecurity

Related topics:
Cybersecurity
Resilience, Peace and Security
Global Risks
Artificial Intelligence
Technological Innovation
Emerging Technologies
Business
Digital Trust and Safety
Share:
The Big Picture
Explore and monitor how Cybersecurity is affecting economies, industries and global issues
World Economic Forum logo

Forum Stories newsletter

Bringing you weekly curated insights and analysis on the global issues that matter.

Subscribe today

More on Cybersecurity
See all

How AI-era disinformation targets both human and machine cognition

Dr. Jean-Marc Rickli and Tobias Knappe

September 8, 2026

Why the energy sector must plan for post-quantum cyber security now

About us

Engage with us

Quick links

Language editions

Privacy Policy & Terms of Service

Sitemap

© 2026 World Economic Forum