Cyber Resilience Requires Scenario-Based Thinking

Auteur zonder afbeelding icoon
Northwave
28 July 2026
3 min

Cyber Risk Has Become a Strategic Business Challenge

The biggest cyber threat today is not a single attack technique, but the speed at which cyber threats are evolving. Artificial intelligence enables attackers to identify vulnerabilities faster, create more convincing phishing campaigns and automate large parts of the attack lifecycle. At the same time, the boundaries between cybercrime, state-sponsored activity and hacktivism are becoming increasingly blurred, making it harder for organisations to understand which adversaries they are facing.

The growing dependence on digital infrastructure, interconnected supply chains and trusted third parties is creating additional exposure. As a result, cyber risk is no longer solely an IT concern. It has become a strategic business issue that requires board-level attention. Organisations must balance operational continuity, regulatory obligations and security investments while facing an increasingly unpredictable threat landscape.

Five Threats Organisations Should Prioritise

According to the Northwave Global Threat Landscape 2026, five developments currently deserve particular attention.

The first is cyber extortion. While ransomware remains a significant threat, attackers increasingly rely on stolen data as leverage. The possibility of public disclosure, regulatory consequences and reputational damage can have a greater impact than system downtime alone.

A second development is the evolution of Business Email Compromise (BEC). What was once primarily email fraud has expanded into broader identity abuse. Criminals increasingly exploit compromised accounts, digital identities and active sessions to impersonate trusted users.

Insider risk is also changing. Many incidents are no longer caused by malicious employees but by unintentional actions. The widespread adoption of AI tools introduces new challenges around data handling and access to sensitive information.

State-sponsored cyber activity continues to increase as well. Governments are using cyber operations for espionage, disruption of critical infrastructure and the collection of strategic intelligence. Alongside this trend, politically motivated hacktivist groups are increasingly targeting sectors such as energy, water management and industry.

Finally, software supply chains remain a significant concern. Organisations are becoming more dependent on third-party software, services and cloud providers, creating additional pathways for attackers to gain access.

Identity, Visibility and Resilience

To address these risks, organisations should focus on strengthening their security foundations. Identity and Access Management (IAM) plays a crucial role, particularly through phishing-resistant multi-factor authentication and effective identity governance.

At the same time, organisations need greater visibility across users, assets and systems. Technologies such as endpoint detection and response, vulnerability management and network segmentation help reduce the attack surface and improve detection capabilities.

However, prevention alone is no longer sufficient. The objective should be to slow attackers down, detect suspicious activity earlier and respond more effectively when incidents occur. Automation and AI can support these efforts by improving the speed and quality of detection and response processes.

Why Scenario-Based Thinking Matters

The traditional assumption that security technologies alone can prevent incidents is becoming increasingly difficult to sustain. The combination of automation, AI and rapidly evolving attack techniques has significantly reduced the time between vulnerability disclosure and exploitation.

As a result, resilience is becoming just as important as prevention. Organisations should identify which critical business processes must remain operational during a cyber crisis and determine in advance how decisions will be made under pressure.

Scenario-based planning helps organisations prepare for realistic situations rather than hypothetical worst-case events. Crisis exercises, recovery planning and decision-making rehearsals enable teams to respond faster and more effectively when incidents occur.

Ultimately, cyber resilience is determined by a combination of people, processes and technology. Organisations that regularly test their preparedness are better positioned to maintain operational continuity when disruptions occur.

Why This Discussion Is Relevant Now

Cybersecurity is increasingly shaped by geopolitical developments, digital sovereignty concerns and evolving regulations. European initiatives such as NIS2 and the Cyber Resilience Act are raising expectations around governance, accountability and resilience.

Against this backdrop, knowledge sharing remains essential. Events such as Cybersec Netherlands provide a forum for security leaders, researchers and practitioners to exchange experiences, discuss emerging threats and explore practical approaches to resilience.

As cybersecurity continues to evolve from a technical discipline into a strategic business function, organisations that invest in preparedness, collaboration and continuous learning will be better equipped to navigate future challenges.

Register for free for Cybersec Netherlands 2026

As cyber attacks continue to threaten today’s tech landscape, this event is the premier platform for seasoned cyber security professionals and innovative start-ups to exchange knowledge and tackle cybersecurity challenges together. Organizations across all sectors will discover strategies to boost cyber resilience and safeguard critical assets. Don’t miss this chance to strengthen your cyber defenses, register for free now!