Resilience: Knowing What Must Never Stop
Recent guidance from the Australian Government's CI Fortify initiative encourages operators of critical infrastructure to identify and isolate vital systems so they can continue operating during a cyber incident. It is practical advice for improving operational resilience, particularly for organisations responsible for delivering essential services.
The guidance also highlights a broader lesson that extends well beyond critical infrastructure. Before organisations can protect vital systems, they first need to understand what is truly vital. While that sounds straightforward, many organisations struggle to answer that question with confidence. They know the technology they operate, but have a less complete understanding of the services that technology exists to deliver.
Critical systems exist because critical services exist
Technology is not inherently critical. It becomes critical because it enables something the organisation cannot afford to lose.
Customers rarely experience technology failures. They experience service failures. Orders cannot be processed. Payments stop. Production lines sit idle. Patients wait longer for treatment. Technology is simply one of the many components that enables those services to operate.
This changes where resilience should begin. Rather than asking which systems are most important, organisations should first ask which services must never stop. Once those services are understood, it becomes far easier to identify the capabilities, information, people and technology that support them. Resilience starts with understanding what creates value for the organisation and the people it serves.
Understanding creates resilience
One of the biggest challenges organisations face is that everything gradually becomes important. Every application supports a business process. Every platform has users. Every project has a sponsor.
Over time, almost every piece of technology acquires the label of being "critical". When that happens, prioritisation becomes almost impossible. As the old saying goes “if everything is important, nothing is”.
Good resilience depends on making deliberate choices. Not every service carries the same importance, and not every system deserves the same level of protection. Understanding those differences allows organisations to focus their investment where it delivers the greatest value. This principle applies equally to large corporations, government agencies and small businesses.
That understanding extends well beyond technology. Critical services rely on business capabilities, information, people, suppliers, processes and technology working together. Removing any one of those elements can affect the organisation's ability to continue operating.
Resilience therefore becomes less about protecting individual systems and more about understanding how the organisation functions as a whole.
Designing resilience before it is needed
The Australian Government guidance discusses the ability to isolate vital systems during a cyber incident. That capability cannot be created once an incident has already begun. It needs to be considered as part of the way services, technology and operations are designed.
This is where enterprise architecture and governance make an important contribution. They provide the visibility needed to understand which services are essential, how they are delivered and where their dependencies exist. That understanding allows organisations to make informed decisions about segmentation, redundancy, recovery and continuity long before they are ever needed.
Resilience is not something that appears during a crisis. It is designed into the organisation over time through hundreds of decisions that improve its ability to continue delivering what matters most.
Knowing what must never stop
Organisations often measure resilience by how quickly they recover from disruption. Recovery is important, but it is only part of the story.
The more fundamental question is whether the organisation has identified what must continue before disruption ever occurs. Without that understanding, it becomes difficult to prioritise investment, design appropriate controls or make confident decisions during an incident.
Technology will continue to evolve. Threats will continue to evolve. Organisations will continue to evolve. The need to understand what creates value will remain constant.
Perhaps resilience does not begin with protecting systems at all.
It begins by understanding what creates value, and knowing what must never stop.
Sources
Australian Signals Directorate
CI Fortify – Advice for isolating vital systems
https://www.cyber.gov.au/business-government/secure-design/operational-technology-environments/ci-fortify/ci-fortify-advice-for-isolating-vital-systems