The metrics organizations should track to measure their cyber resilience
As incidents become which are becoming almost avoidable, having a way to measure and quantify cyber resilience is becoming more iomportant. Image: REUTERS/Shannon Stapleton
- As cyber disruptions become increasingly inevitable, cyber resilience can no longer just be treated as an ambition; it needs to be a measurable capability.
- Resilience metrics should demonstrate whether controls and capabilities in place will meaningfully reduce business impact and accelerate recovery.
- Measurable outcomes – how effectively an organization can detect, absorb, contain and recover from disruption – underpin an effective cyber resilience strategy.
Most leaders today recognize that not every cyber incident can be prevented. In an environment shaped by AI-enabled threats, fragile supply chains and geopolitical volatility, cyber disruption is no longer an exception to plan around; it has become a condition that organizations need to operate through.
While this mindset shift is important, it also raises a harder question: how can organizations know whether they are resilient before an incident exposes the answer? And what can they do about it?
Answering these questions requires making cyber resilience measurable. It is crucial to translate resilience from a broad ambition into something leaders can assess, test and improve over time.
The problem with measuring the wrong things
Cybersecurity has no shortage of metrics. Organizations can count vulnerabilities, alerts, patches, training completion rates, audit findings and tool coverage. These measurements matter, but they do not always reveal whether an organization can continue operating during a major incident.
A company may have strong technical controls yet still be unprepared for a crisis. Response plans may be untested, backups may not be recoverable in time or critical business dependencies may be unclear. These gaps show why resilience cannot be measured only by the presence of controls; it must be measured by whether the organization can actually limit disruption through these controls.
The World Economic Forum’s Unpacking Cyber Resilience report defined cyber resilience as an organization’s ability to minimize the impact of significant cyber incidents on its primary goals and objectives. In other words, resilience should be measured by business impact, not only by cybersecurity activity.
What to measure
Organizations rely on many services, systems and assets, but not all are equally critical during a cyber incident.
Resilience measurement should start by defining the organization’s “minimum viable business”: the essential services and capabilities that must keep running, or recover first, for the organization to fulfil its core mission under degraded conditions. Only from this starting point can leaders ask the questions that matter:
· How long can a critical service be offline?
· How quickly can a recovery decision be made?
· Which suppliers or systems create single points of failure?
· What manual workarounds exist if digital systems are unavailable?
· What level of disruption can the business tolerate?
Recovery time is not just an IT metric
One of the most useful measures of cyber resilience is time: time to detect, time to decide, time to contain, time to recover, time to restore customer-facing services.
The World Economic Forum defines cyber-resilient organizations as those able to “shrink the V” — reducing the depth and duration of disruption after an incident. This idea is valuable because it turns resilience into something observable. The smaller the operational dip, and the faster the recovery, the more resilient the organization.
But recovery should not be understood only as restoring technology. True recovery also means restoring operations, protecting trust, limiting financial damage and maintaining confidence among customers, employees, regulators and partners.
This is why resilience metrics need to be meaningful to business leaders, not only cybersecurity teams. Recovery time objectives and recovery point objectives are important, but so are decision-making speed, customer impact, legal response time, communications readiness and the ability to keep critical services running.
The best cyber resilience test is a realistic exercise
Resilience cannot be fully measured in a questionnaire. A self-assessment may show whether plans exist, but it cannot show whether they work under pressure. That is why exercises are becoming one of the most important tools for measuring cyber resilience. Tabletop simulations, recovery drills and crisis rehearsals reveal what static metrics often miss: confusion, unclear ownership, slow escalation, missing data, communication gaps and unrealistic assumptions.
The Forum’s Global Cybersecurity Outlook 2026 shows a gap between highly resilient and insufficiently resilient organizations: 44% of highly resilient organizations simulate cyber incidents or plan recovery exercises with ecosystem partners, compared with 16% of insufficiently resilient organizations. That difference matters.
During a real incident, organizations rarely fail because they lack a policy, but they fail because people do not know who decides, what to prioritize or how to coordinate under stress.
A good resilience exercise does not need to be overly complex. It needs to be realistic enough to force trade-offs. For example: if a ransomware attack disrupts customer systems and internal communications at the same time, who decides what gets restored first? If a supplier outage affects a critical service, how quickly can the organization switch to an alternative? If legal, communications and technical teams disagree, how is the decision escalated? These are measurable questions.
Extending resilience beyond the organization
That said, we cannot look at cyber resilience in isolation. True resilience is an ecosystem issue as no organization operates independently in our highly interconnected world. They rely on cloud providers, software vendors, logistics partners, payment systems, outsourced services and shared infrastructure. A weakness in one part of the ecosystem can quickly become a crisis elsewhere.
Yet many organizations still measure supplier risk through periodic assessments rather than operational resilience. The more useful question is not only whether a supplier has controls, but whether the business can continue if that supplier fails. This requires measuring ecosystem readiness: supplier recovery times, alternative providers, contractual escalation routes, shared incident playbooks and joint exercises.
In resilience terms, a supplier is not just a vendor; it needs to be part of the organization’s recovery capability or it quickly becomes its weakest point.
From scores to decisions
The next step in measuring cyber resilience is not to create another score for its own sake. The purpose of measurement is better decision-making. A strong resilience measurement approach should help leaders decide where to invest, what to fix first and what risks they are willing to accept. It should show whether money is reducing business impact, not just increasing cybersecurity activity.
That makes resilience measurement a leadership tool. It helps boards ask sharper questions:
· Are we protecting the services that matter most?
· Have we tested our recovery assumptions?
· Do we know how fast we can make decisions in a crisis?
· Can we operate if a critical supplier fails?
· Are we improving over time?
In an era when cyber disruption is increasingly unavoidable, these may be the most important cybersecurity questions an organization can ask. The future of cyber resilience will not be defined by organizations that claim to be prepared. It will be defined by those that can prove it.
Don't miss any update on this topic
Create a free account and access your personalized content collection with our latest publications and analyses.
License and Republishing
World Economic Forum articles may be republished in accordance with the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International Public License, and in accordance with our Terms of Use.
The views expressed in this article are those of the author alone and not the World Economic Forum.
Stay up to date:
Cybersecurity
Forum Stories newsletter
Bringing you weekly curated insights and analysis on the global issues that matter.
More on CybersecuritySee all
Leo Simonovich and Filipe Beato
July 24, 2026




