);
  • Link to LinkedIn
Contact Us: +61 2 9994 8914
Janellis Consulting, Strategy and Resilience
  • Home
  • Capabilities
    • Overview
    • Accreditations
      • Critical Thinking Professional Accreditation
      • Cyber Resilience Professional Accreditation
      • Organisational Resilience Accreditation
      • Stakeholder Engagement Accreditation
    • Case Studies
    • Capability Uplift
    • Executing Strategy
      • Project Delivery
      • Accelerating Strategy EPMO
      • Accelerating Strategy CEO & Executive
      • Stakeholder Engagement & Alignment
      • Change Management & Transformation
      • Strategic Project Management
      • Project Sponsor Capability
    • Organisational Resilience
      • Cyber Resilience Scorecard
      • Organisational Resilience Scorecard
      • Scenario-Based Planning
      • Post Incident Review
      • Governance in Crisis
      • Crisis Management Tools
      • Cyber Crisis Response
      • COVID19
      • City Resilience
    • Project Delivery
    • Scorecard Assessment
      • Cyber Resilience Scorecard
      • Organisational Resilience Scorecard
    • Tools & Frameworks
      • Decision Support Tool
      • Executive Level War Room
      • Organisational Resilience Framework
      • Critical Thinking Framework
  • Featured Insights
    • Case Studies
    • Spotlight Articles
      • Embedding a Unified Decision-Making Process
      • The Role of the Board in a Crisis
      • The Role of the CEO in a Crisis
      • Building a Culture of Cyber Resilience​
      • Responding to Cyber Security Risks
      • HBR Organisational Resilience Paper
      • Building an Agile Workforce
      • How to Build your Organisation’s Resilience
      • Creating a Thinking Organisation
    • Cyber Resilience Resources
    • COVID-19 Resources
    • Research Initiatives
      • Critical Thinking & Decision Making within Agile Environments
      • Strategies for Building Resilience in Critical Infrastructure
      • The Value of Change Management in Executing Strategy
  • Events
  • News
    • Spotlight Articles
    • Articles
    • In the Media
    • Awards
  • About Us
  • Contact
    • Contact Us
    • Join Us
    • Engage a Consultant
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu

Cyber Resilience: What does good look like?

An Executive and Board perspective

The headline story at the inaugural AFR Cyber Summit in Sydney, attended by leaders from government and business, was “ASIC to target boards, execs for cyber failures.”1

Joe Longo Chairman of Australian Securities and Investments Commission (ASIC) urged boards to prioritise cyber weaknesses, including third party vulnerabilities:

“For all boards, cyber security and cyber resilience have got to be top priorities. If boards do not give cyber security and cyber resilience sufficient priority, this creates a foreseeable risk of harm to the company and thereby exposes the directors to potential enforcement action by ASIC based on the directors not acting with reasonable care and diligence.”

The evolving nature, potential severity and velocity of cyber risks has brought cyber security into sharper focus and many organisations are taking a targeted approach to build and maintain cyber resilience. Yet cyber risk is just one operational risk that organisations are managing alongside other operational, strategic, financial and environmental risks.

DOWNLOADS

Article 7 pages

Executive and board resilience challenges

Executives and boards are facing many risk and resilience challenges:

  • An increasingly complex and wide range of risks including those related to cyber security and critical third-party providers.
  • On-going changes to regulations.
  • Increased accountability and penalties for non-compliance.
  • A vast array of guidelines and standards.
  • Internal structures that are based on functions and inherently siloed.

To date, executives and boards have focused on preventing cyber-attacks by investing in cyber security technology solutions rather than building cyber resilience which is a far broader capability.

“Cyber preparedness is not simply a question of having impregnable systems. While preparedness must include security, it must also involve resilience, meaning the ability to respond and weather a significant cybersecurity incident.”

Joe Longo, Chairman ASIC

ARTICLES

Responding to Cyber Security Risks

The Role of the Board in a Crisis

Increased accountabilities and penalties

New resilience regulations are increasing and expanding to include a wider range of industries. By imposing increased responsibility on boards to improve their oversight of operational risks, and management of third-party providers, many board members are now required to demonstrate they have taken ‘reasonable steps’ to meet their obligations.

Taking reasonable steps includes having appropriate governance, control and risk management systems along with safeguards against inappropriate delegations of responsibility.

Whilst the message of accountability from ASIC was directed at board members of all Australian organisations, executives in some industries have already been working within more stringent levels of accountability that continue to expand in reach.

The ASIC warning was specific to cyber risk and resilience, but boards and executives can expect increased scrutiny and accountability for all risks.

RESOURCES

How to Build your Organisation’s Resilience

A vast array of guidelines and standards

Many of the changes in regulation are designed to address specific risks. For example, Australia’s Privacy Legislation Amendment Bill 2022 includes some of the harshest financial penalties globally, designed to protect the privacy of data; while the new Digital Operational Resilience Act (DORA), addresses ICT-related risks in the financial services sector in the EU.2

In some instances, the regulations are very clear and in other instances, organisations can meet the requirements any way they see fit. This lack of clarity about ‘what good looks like’ makes it challenging for executives and board members to establish that ‘all reasonable steps have been taken’ from a compliance and assurance perspective.

Additionally, many standards and guidelines continue to evolve, based on lessons learnt and emerging threats. For example, many organisations use the National Institute of Standards and Technology (NIST) framework to improve their management of cyber security risk, yet the current version was developed in 2014. Version 2.0 is designed to better respond to current cyber risks, and remains under development.

Some frameworks and standards such as NIST and ISO27001 are extremely technical and specific to managing cyber-related risks, while executive and board level guidelines can also be too high-level, and few take an ‘all-risks’ approach to resilience.

RESOURCES

Providing Assurance to Regulators

Organisational Resilience Scorecard

Cyber Resilience Scorecard

Internal structures that are inherently siloed

Many organisations are structured to operate as functional areas which can create silos without enterprise-wide visibility of investments or capability. For example, organisational resilience capabilities span risk management, security, information technology, information security, business continuity, disaster recovery, emergency management, incident management, crisis management, insurance and audit. Typically, projects and capabilities in these areas are distributed across the organisation and are not sufficiently aligned, leading to an over-investment in some areas and under-investment in others and in some cases, contributing to gaps in capability.

What does good look like?

Leaders can draw on the experiences of owners and operators of critical infrastructure and those operating in high-risk industries who have taken an ‘all risks’ approach to developing their resilience and capability, in the following ways:

  1. A CEO-led Resilience Statement endorsed by the executive and board.
  2. An organisational resilience framework that operationalises the resilience statement by intelligently fusing resilience investments and capabilities into a holistic and integrated framework that includes Risk, Readiness, Response and Assurance.
  3. Embedded team-based critical thinking across all layers of the organisation.
  4. Scenario-based exercising activities that are designed to uncover blind spots, build capability and provide assurance.
  5. A scorecard of capability to measure and maintain capability and provide assurance to executives, boards, regulators and other key stakeholders.

Taking an all-risks approach draws on existing investments, capabilities and risk controls and builds the capability to respond to a range of current risks and emerging threats, while meeting the changing regulatory requirements.

EXPERTISE

Organisational Resilience

RESOURCES

Developing a Strong Risk Culture

1. CEO Resilience Statement

A CEO Resilience Statement can be used to mobilise the organisation to manage all types of risks including strategic, operational, financial, environmental and reputation. The Resilience Statement should be agreed by the executive and board and communicated to all levels of the organisation. The statement is used to align capability, guide decision-making, and prioritise investments in building organisational resilience.

2. Enterprise-wide Resilience Framework

The CEO Resilience Statement is operationalised using an enterprise-wide Resilience Framework that leverages existing capability and takes a holistic, integrated, and co-ordinated approach to the development and maintenance of capability.

The resilience framework extends beyond traditional risk management reporting, by integrating readiness and response capabilities and considering the interdependencies and links across the business and with external parties.

A fully integrated resilience model is achieved by intelligently fusing the disciplines of Risk; Readiness; Response and Assurance:

  • RISK: An ‘all risks’ approach to managing risk including emerging threats, extreme risks and those related to third party providers.
  • READINESS: Effective risk and security controls, plans, systems, procedures, frameworks, tools, training and testing.
  • RESPONSE: An adaptive capability to respond to a range of potential risks and threats and ensuring high-quality decision-making is occurring at all levels of the organisation and is aligned with third parties.
  • ASSURANCE: A governance structure that provides assurance to all key stakeholders internally and externally and that meets all regulatory requirements.

An integrated resilience framework helps divisions within organisations understand how their capability links to others in the organisation and will ensure alignment. New legislative requirements can be incorporated easily within the framework.

The framework needs to be sufficiently technical but high-level enough for executive and board level oversight.

The resilience statement and framework provide evidence to regulators and key stakeholders that ‘reasonable steps’ are being taken to embed and maintain risk and resilience capability.

EXPERTISE

HBR Organisational Resilience Framework

3. Embedded team-based critical thinking

Leading indicators of organisational resilience are embedded team-based critical thinking capabilities and transparent, high-quality decision-making.

Resilient organisations ensure robust and high-quality decision-making is occurring at all levels of the organisation in the key resilience areas of risk, readiness and response.

The importance of critical thinking in building cyber resilience cannot be overstated. In many Post-Incident Reviews (PIRs) following crisis events, the underlying issue or contributing factors are poor decision-making and a lack of critical thinking.

Cyber resilience decisions require complex decision-making skills, due to evolving technical complexity, conflicting or incomplete information and many competing stakeholders’ needs and expectations.

Other factors which contribute to the complexity of cyber resilience decisions are:

  • High levels of scrutiny, increased pressure from the regulators and greater demands for transparency and evidence of a robust, discoverable, and defendable decision-making process.
  • Compressed timeframes, social media, mainstream media and community expectations are driving the timeframes for decisions, even where there may be incomplete or inconsistent information.
  • Significant impacts where a single poor decision or an accumulation of poor decisions can result in cascading impacts.

Examples of cyber-related decisions with significant impacts include the decision to click on a phishing email, or more complex decisions such as those related to investments in critical third-party systems and strategies to build and maintain cyber resilience capability. All these decisions require critical thinking and high-quality decision-making.

A unified, robust, and transparent decision-making process embedded at all levels of the organisation will provide tangible evidence that leaders have taken ‘all reasonable steps’ to protect the organisation from known risks and emerging threats.

ARTICLE

The Value of Critical Thinking in becoming Agile and Resilient

Enabling critical thinking skills

Good decision-making is underpinned by critical thinking skills. The vast number of skills required to be a critical thinker, highlights the need for a team-based approach that draws upon the brains trust of the organisation. Critical thinking skills include: analysing; verifying; clarifying; forecasting; perceiving; synthesising; prioritising and communicating.

EXPERTISE

Critical Thinking Accreditation Program

Enterprise-wide critical thinking capabilities

Organisations should embed a decision-making framework that facilitates team-based critical thinking. The framework should enable individuals and teams to ‘step through’ a transparent process, work collaboratively, record information gathered and make key decisions.

The critical thinking framework should be used to:

  • Clarify the facts and assumptions in a changing situation.
  • Uncover vulnerabilities, blind spots and challenge assumptions.
  • Build a shared view of the risks and opportunities and generate new perspectives and unique insights.
  • Facilitate deeper levels of thinking for critical decisions that may have cascading impacts.
  • Understand the impacts across the organisation.
  • Re-calibrate and re-orient strategy using real-time data.
  • Enable a more agile and adaptive capacity to deal with change.
  • Facilitate robust, objective, discoverable and defendable decision-making.
  • Align a diverse group of stakeholders on complex issues.
  • Stress test strategy and develop contingency plans.

By driving critical thinking behaviours, organisations will become more resilient to current risks, enhance their skills to execute strategy and provide assurance to regulators.

Embedding critical thinking into ‘ways of working’

Advances in technology can enable and uplift critical thinking skills across the enterprise in a scalable, cost effective and accessible way.

For example, the Janellis Critical Thinking Framework is now available as a Microsoft Application (App), available on a mobile device and at the desktop.

Utilising a Critical Thinking App can embed critical thinking skills into current ways of working and ensure teams apply high-quality decision-making when developing strategy, managing risk, delivering projects, designing systems and responding to incidents or crisis situations.

ARTICLE

Digitally Enabled Team-Based Critical Thinking

4. Scenario-based exercising

Scenario-based exercising activities are an essential way to align investments in capability and provide assurance. Scenarios enable a broad range of stakeholders to understand their operating environment, share information, challenge assumptions, understand risk and assess strategic options. A key strategy in building cyber resilience is embedding critical thinking skills through scenario-based exercising activities.

Scenario-based exercising can be used to:

  • Identify areas that require immediate action and uncover blind spots and vulnerabilities.
  • Validate investments in key systems, plans or processes.
  • Create alignment across functional areas and between response teams.
  • Clarify roles, uplift and embed capability and build confidence.
  • Develop contingency plans for emerging threats.

Current and proposed legislation specifically mention scenario-based exercising and testing as a key metric of resilience and compliance.

Information is better evaluated within a scenario framework as it provides a context for making decisions, reaching consensus on key issues or opportunities and developing a plan of action. 

Scenario exercising and training allow teams to come together in a closed loop learning environment—which may include business partners—and engage in open and robust discussions. A series of scenarios enable teams to challenge preconceptions and draw conclusions that might otherwise be missed.

Key indicators of successful scenario-based exercising activities are:

  1. Developing credible scenarios by including current risks or emerging threats the organisation is managing.
  2. Allowing teams to practise using a decision-making framework for the chosen scenario or any other scenario or risk that may eventuate. Information generated should be both discoverable and defendable and the process should be used by all teams, for all scenarios.
  3. The opportunity to practise generating a situation report (Sitrep) as a key documented process to communicate between teams internally and to external teams and stakeholders.
EXPERTISE

Scenario Planning Process

Scenario Planning & Exercising

5. Cyber Resilience Scorecard

Defining and measuring cyber resilience is crucial to prioritising cyber resilience investments and providing assurance to boards, shareholders, insurance providers and other key stakeholders.

A scorecard can be used to meet regulatory requirements and provide executive and board level visibility of how cyber security investments are aligned and integrated within an organisation’s broader resilience capability. The scorecard can be used to align, measure, embed and maintain capability.

To date, executives and boards have primarily tracked and discussed cyber security rather than cyber resilience metrics to measure, embed and maintain capability. To build cyber resilience, boards need a balanced view of cyber vulnerabilities and threats and an understanding of the broader capabilities and impacts across the organisation.

A Cyber Resilience Scorecard provides boards with a comprehensive, qualitative review of cyber resilience indicators across the enterprise, in the areas of risk, readiness, response and assurance, and is used to:

  • Ensure cyber security investments are aligned with the broader risk and resilience capability.
  • Identify gaps in design or capability for cyber resilience, that need immediate action.
  • Validate and prioritise cyber resilience investments.
  • Identify areas of excellence that should be applied more broadly.
  • Ensure adequate cyber insurance cover and third-party support.
  • Provide assurance of current capability to key stakeholders internally and externally.
  • Ensure that ‘all reasonable steps’ have been taken to prevent, prepare and respond to a cyber incident.
  • Support the development of a cyber resilience capability uplift roadmap.

The scorecard reviews current investments and competencies against industry standards and provide recommendations for implementing and maintaining resilience across the organisation.

The cyber scorecard assists organisations in demonstrating they are effectively prepared to respond to a range of risks, threats and disruptive events, which provides assurance to boards, shareholders, insurance providers and other key stakeholders.

RESOURCES

Cyber Resilience Scorecard

Cyber Resilience Capability Uplift

Cyber Resilience Accreditation Program

Opportunities to build resilience

The insurance industry has a pivotal role to play in helping organisations build resilience. The cyber insurance industry is experiencing significant growth and cyber risk insurance presents unique challenges and opportunities.

Typically, policy holders insure against risks that are unlikely to eventuate, based on probabilities. In the case of cyber risk, the general view is that policy holders will experience a cyber incident during the term of the policy. This means that organisations seeking cyber insurance need to provide evidence of their cyber risk management investments and capabilities to their prospective insurance provider and this information will inform the overall cover, deductables and premiums.

Conversely, specialist cyber insurance providers are offering policy holders access to expertise and tools to help organisations prepare for and respond to cyber threats through risk portals and cyber incident response teams. Organisations can now expect their cyber insurance policy to include access to expertise, tools, and frameworks to develop and maintain their cyber resilience.

This ‘shared risk’ partnership model is an example of a third-party strategy that can bolster resilience for the insurance provider, policy holder and the broader supply-chain.

Cyber insurance is a crucial part of an organisation’s strategy to build resilience and provide assurance.

EXPERTISE

Cyber Resilience-What does good look like?

Post Incident Review (PIR)

A mature resilience capability

Organisations with a mature resilience capability demonstrate the following:

  • A CEO-led and board endorsed resilience statement that is used to inform decision-making and prioritise investments.
  • Integrated management of all risks including strategic, operational, environmental, financial and third-party risks.
  • High visibility of the known ‘catastrophic’ or ‘extreme’ risks at all levels.
  • Effective controls, plans, systems, procedures, frameworks and tools to manage risks, including training and awareness.
  • Adequate insurance cover for the risk profile.
  • Response capability built against known risks through exercising and training.
  • High levels of confidence to respond to emerging threats.
  • Consistent, robust, transparent, and high-quality decision-making and critical thinking at all levels of the organisation.
  • Effective stakeholder management both internally and externally.
  • Alignment of resilience capability with key inter-dependencies and third-party providers.
  • Effective governance structure, audit and reporting of capability using scorecard/dashboard methodologies.
  • Regular assurance to the board and other key stakeholders.
EXPERTISE

Organisational Resilience Scorecard

Organisational Resilience Capability Uplift

Organisational Resilience Accreditation

CASE STUDIES

Building Cyber and Information Security Resilience: Australian Superannuation Company

Building Cyber Resilience: Leading Australian Government Agency

Summary

The evolving nature, potential severity and velocity of cyber risks, and increased accountability and penalties for noncompliance, require organisations to take a targeted and focused approach to building cyber resilience. Until now, organisations have focused on preventing cyber-attacks by investing in cyber security technology solutions. The most efficient way to build cyber resilience is to take an ‘all risks’ approach, which draws on existing capabilities and prepares the organisation to respond to a range of current risks and emerging threats, while meeting changing regulatory requirements.

A best practice approach includes: a CEO resilience statement; a holistic and integrated resilience framework; embedded team-based critical thinking; an ongoing schedule of scenario-based activities and a scorecard record of capability to provide visibility and assurance.

To learn more, visit: Cyber Resilience Scorecard

Follow a manual added link

Critical Thinking Professional Accreditation

Read more >

Link to: Cyber Resilience Accreditation Program

Cyber Resilience Accreditation

Read more >

Link to: Project Delivery

Executing Strategy through Project Delivery

Read more >

Why is Critical Thinking Important?

“Team-based critical thinking allows us to be both agile and robust in our decision making, drawing upon the brains trust of the organisation”

CEO
Energy Company

“Critical thinking skills are essential skills for our organisation when responding to the rapid onset of change”

Managing Director
Critical Infrastructure

“By developing our critical thinking capabilities our teams can manage cyber crises more effectively. The tool also enables us to see the opportunities to execute strategy more efficiently”


Executive Leader
Insurance

Our Upcoming Events

Click on any of the below events to find out more details

Janellis AI Lab

AI Decision Lab | Critical Thinking in an AI-Enabled Environment

26 August, 2026 @ 16:30 - 17:30 AEST
Janellis AI Lab

AI Decision Lab | Critical Thinking in an AI-Enabled Environment

16 September, 2026 @ 16:30 - 17:30 AEST
See All Events

References

[1] Australian Financial Review. 2023. ASIC to target boards, execs for cyber failures. [ONLINE] Available at: https://www.afr.com/technology/asic-to-target-boards-execs-for-cyber-failures-20230913-p5e4bf. [Accessed 05 October 2023].

[2] Digital Operational Resilience Act (DORA) – Regulation (EU) 2022/2554. 2023. Digital Operational Resilience Act (DORA) – Regulation (EU) 2022/2554. [ONLINE] Available at: https://www.digitaloperational-resilience-act.com/. [Accessed 05 October 2023].

Quick Links

  • Home
  • Project Delivery
  • Cyber Resilience Accreditation
  • Capabilities
  • Executing Strategy
  • Capability Uplift
  • Organisational Resilience
  • Research
  • Events
  • About Us
  • Latest News
  • Contact

Upcoming Events

Aug 26
16:30 - 17:30 AEST

AI Decision Lab | Critical Thinking in an AI-Enabled Environment

Sep 16
16:30 - 17:30 AEST

AI Decision Lab | Critical Thinking in an AI-Enabled Environment

View Calendar

Get In touch

Email
info@janellis.com.au

Phone
Head Office: +61 2 9994 8914

Visit Us Online

  • www.janellis.com.au
  • www.criticalthinkinghub.com.au
  • www.cbdresponse.com.au

Office
141 Walker Street, North Sydney, NSW 2060

Media Enquiries
+61 2 9994 8942

media@janellis.com.au

Our Sites

cbd response logo
Critical thinking Hub
© Janellis | Privacy Policy
  • Link to LinkedIn
Scroll to top Scroll to top Scroll to top