Twenty-five years ago, on September 11, 2001, the world witnessed a terrorist attack that fundamentally changed the way governments, businesses, and ordinary people thought about security. The attacks in the United States caused enormous loss of life and disruption, exposing an important reality: major disruption can arrive suddenly, affect interconnected systems, and force organisations to operate under conditions they had never imagined. This event highlighted the need for organisations to be resilient in the face of unexpected disruptions.

Today, the nature of some of the threats facing society has changed, with disruption often beginning not with a physical attack, but with a few lines of malicious computer code, stolen passwords, compromised suppliers, or an attack on critical digital infrastructure. The lesson from September 11 remains relevant: security is important, but resilience is equally important. Organisations must prepare for cyber incidents, withstand them, continue delivering essential services, recover quickly, and learn from what happened. This is known as cyber resilience.

Cyber resilience is the ability of an organisation to prepare for cyber incidents, withstand them, continue delivering essential services, recover quickly, and learn from what happened. Cybersecurity asks: How do we protect ourselves from attack? Cyber resilience adds another question: If an attack succeeds, can we continue operating? That difference is becoming increasingly important as our dependence on digital systems has grown. In 2001, the world was already becoming digital, but our dependence on technology was far smaller than it is today.

In Tanzania, millions of people now use mobile phones and digital financial services as part of everyday life. Businesses depend on internet connectivity, cloud services, electronic payments, and digital communication. Government institutions are also expanding online services. This digital transformation brings enormous benefits, but it also creates new forms of vulnerability. Imagine a major bank being unable to process transactions for several hours or a hospital losing access to important systems.

Cyber resilience should no longer be regarded simply as an ICT issue; it is a business continuity and national resilience issue. Organisations need to ask difficult questions, such as what happens if their main data centre becomes unavailable or if ransomware locks important systems. These questions should be discussed before a crisis, not during one. Organisations therefore need tested business continuity and disaster recovery arrangements.

Another important principle is avoiding excessive dependence on a single system, supplier, communication route, or location. Engineers understand this very well; if one component fails, another should be capable of taking over. The same principle applies to cyber resilience. An organisation may need alternative internet connections, backup systems, geographically separated recovery facilities, and alternative communication channels.

Perhaps the biggest change needed today is recognising that cyber resilience cannot remain the responsibility of the ICT department alone. A major cyber incident can affect revenue, reputation, customers, regulatory obligations, and even the survival of an organisation. Boards should therefore ask management straightforward questions about critical systems, recovery time, and backup testing.

Key points

  • Organisations must prepare for cyber incidents and have tested business continuity and disaster recovery arrangements in place.
  • Cyber resilience is a business continuity and national resilience issue, not just an ICT issue.
  • Boards and senior executives should view resilience expenditure as an insurance policy protecting the organisation’s ability to operate.

Share this story

Written by

SaharaWire Newsroom
SaharaWire

Reporting for SaharaWire from the Nairobi bureau.