
A new report from the UK's HM Treasury has assessed the benefits of financial services firms going beyond minimum mandated security requirements and investing in operational and cyber resilience as a means to survive our increasingly volatile times.
With analysis by leading Big 4 consultancies and data from economists and insurers, this latest publication champions the core theme that resilience delivers value well beyond risk reduction alone.
Against the backdrop of 2025's cyber annus horriblis for many well known UK brands, data in the UK shows the number of highly significant cyber incidents increasing year on year with a 50% increase in reports to NCSC-UK, the third consecutive year of upward trending activity.
Cyber risk is no longer simply an IT issue, it is an enterprise risk affecting revenue, customers, operations and shareholder value.
As such, the question for executives is no longer "Can we prevent every attack?" but rather "Can we continue to operate when an attack succeeds?"
Operational resilience thus becomes a competitive capability that enables organisations to recover quickly, maintain customer confidence and continue growing despite disruption.
The largest costs associated with an incident often arise from:
In many cases, incidents have a modest and manageable impact, typically between 0.2% and 4.6% of annual turnover in the UK. But there are also those black swan, edge case events that can be far more severe in scale and potentially threaten overall business continuity.

Where companies proactively invest in organisational resilience - both technical and cultural changes - the magnitude of loss caused can be reduced in two principal ways:
The UK analysis shows four key benefits of moving beyond the simplistic world view that cybersecurity spend is a cost that prevents bad things from happening.
Organisations that treat investment beyond the prescribed minimal regulatory obligations see:
Whilst the outcomes and benefits seem clear, the analysis suggests that getting to this position can be complex for many organisations.
"Rather than treating prevention, response, recovery and continuity as separate conversations, firms with the strongest outcomes are those that balance investment across these domains, informed by where capabilities have the greatest impact on likelihood and loss"
The most common recommendation in the report is that prevention efforts alone are insufficient.
Data from KPMG identifies how different defensive security capabilities reduce the likelihood of a major ransomware incident with security training, email filtering and web traffic controls contributing 10 to 15% reductions in incident likelihood.

Alongside technical controls, investment should balance prevention, detection, response and recovery procedures through a process of understanding the most critical business assets and services - including supply chain and technology dependencies - to quantify the potential impacts on customers.
The ability to recover quickly is as valuable as reducing the likelihood of compromise.
And here is where crisis management and incident communications, business continuity efforts and supply chain management are also key areas to focus on as organisational culture is matured.
Alongside monitoring the effectiveness of foundational controls, such as patching and vulnerability management, Boards should move resilience beyond just compliance reporting and vanilla risk management updates.
Cyber resilience must be seen as a strategic business capability embedded into corporate strategy with investment decisions supporting continuous improvement. On this basis, security investment evolves from simple risk mitigation to supporting overall business transformation, innovation and growth.