Recent cyber incidents affecting major UK organisations serve as a timely reminder that resilience is not measured by the absence of attacks. Even organisations with mature security capabilities can experience cyber events. The real differentiator is how effectively services continue to operate, how quickly organisations understand and contain risk, and whether they have built the capability to respond with confidence when the unexpected occurs. Reports last week indicate that a cyber incident affecting Manchester Airports Group resulted in customer data being accessed, while airport operations and aviation security remained unaffected.
For leaders responsible for critical digital services, the lesson is clear: the most important decisions made during a cyber incident are often the decisions made months, or even years, beforehand.
Too often, cyber security is treated as a final assurance activity. A project reaches delivery milestones, technical decisions have been made, systems have been built, and security is then invited to validate the outcome. While assurance remains important, this approach frequently identifies risks when they are most expensive to fix and most disruptive to delivery.
Effective cyber resilience starts much earlier
Organisations that successfully manage digital risk bring security expertise into the design and delivery process from the outset. Security architects, risk specialists, operational teams and delivery leaders should be working together from discovery through to live operation. Early collaboration helps identify potential risks, informs design decisions and ensures security becomes an integral part of delivering successful outcomes rather than a compliance exercise undertaken at the end.
This does not mean applying every possible security control to every service.
No organisation can eliminate risk entirely, nor should it attempt to do so. The most resilient organisations adopt proportionate, risk-based decision making. They focus on understanding what they are trying to protect, what could compromise delivery, and where investment in security and resilience provides the greatest benefit. This allows resources to be directed where they matter most while maintaining the agility needed to deliver modern digital services at pace.
When approached in this way, security becomes an enabler rather than a blocker.
One of the biggest misconceptions in digital transformation is that cyber security slows progress. In practice, organisations that embed security early often move faster because they avoid costly redesign, reduce uncertainty and create clear governance around decision making. Teams gain confidence to adopt new technologies, modernise legacy platforms and innovate safely because risk is understood and managed throughout the delivery lifecycle.
Preparedness is also about people
Lasting resilience cannot depend solely on a small team of cyber specialists. Critical services are delivered by multidisciplinary teams, and resilience grows when knowledge is shared across architects, engineers, service managers, product owners and operational leaders. Organisations that invest in capability building, coaching and collaborative ways of working create a culture where security is everyone’s responsibility rather than someone else’s problem.
This capability is often the difference between organisations that simply comply with security requirements and those that are genuinely prepared to withstand disruption.
As leaders consider their own organisation's readiness, there are three practical questions worth asking:
1. Are security and resilience considerations embedded at the start of every major digital initiative?
If security discussions begin only at assurance gates or before deployment, opportunities to reduce risk early may already have been lost.
2. Can teams explain why key security decisions have been made?
Strong organisations understand their risks and the outcomes they are protecting. Security should be informed by context and risk, not implemented as a checklist exercise.
3. Are we building organisational capability alongside delivering projects?
True resilience is achieved when knowledge is transferred, skills are developed and confidence is built across delivery and operational teams.
Cyber incidents will continue to evolve in scale, sophistication and frequency. The goal for leaders should not be to create an unrealistic expectation that incidents will never occur. Instead, the objective should be to ensure that critical services remain resilient, trusted and capable of supporting organisational outcomes when challenges do arise.
“Preparedness does not begin when an incident is declared”.
It begins with the decisions made during service design, delivery and operation long before that day arrives.
Methods will be at the UKHSA Conference 2026 - Stand D2. Come and speak to us about secure-by-design services, cyber resilience and building lasting organisational capability.