I’ve spent a lot of time recently speaking about resilience, recovery, and what it really means to “move beyond backup.”
Most organizations stop at the same checkpoint: “We have backups.”
Maybe they go a little further: “We test our backups.”
Sometimes they go further still: “We can recover system X in Y hours, and we run recovery exercises every quarter.”
Those statements sound reassuring. But they convey an illusion of cyber resilience.
Most recovery testing happens under ideal conditions.
- Trust still exists. Coordination still exists. Identity still works.
- The lights are still on. Documentation is available. Password vaults still work. Communication platforms still function. Phones still ring.
- The environment may simulate degradation or limited availability, but the organization itself is still intact.
That is not resilience. That’s rehearsing recovery while the assumptions behind the recovery plan remain true.
When resilience assumptions collapse
Real resilience is not about the primary plan. It is about what happens when the plan fails and the assumptions behind it collapse.
Which brings us to bank robberies.
Every successful heist follows the same basic plan:
- Get in.
- Get the money.
- Get out.
- Don’t get caught.
The difference between success and jail time is how the crew plans to survive when things stop going according to plan.
- Bonnie and Clyde. Chaos. Fast in. Fast out. Create confusion. Escape. Spend the rest of your life running.
- Point Break. A disciplined crew with principles, rules, routines, and trust. They take only what they need, avoid unnecessary escalation, and whatever they do, they never ever touch the vault.
- Ocean’s Eleven. Precision. Preparation. Defined roles. Constant coordination. Get in. Get out. No unnecessary risk.
Saul: I have a question. Say we get into the cage, and through the security doors there and down the elevator we can’t move, and past the guards with the guns, and into the vault we can’t open…
Ocean’s Eleven, 2001
Rusty: Without being seen by the cameras.
Danny: Oh yeah, sorry, I forgot to mention that.
Saul: Yeah well, say we do all that… uh… we’re just supposed to walk out of there with $150,000,000 in cash on us, without getting stopped?
Danny: Yeah.
Saul: Oh. Okay.
Bonnie and Clyde don’t make it out. The Ex-Presidents don’t make it out.
Ocean’s Eleven do. Why? Not luck.
Planning for failure. Contingencies. Coordination under pressure.
In other words: resilience.
Not because the plan was flawless but because the crew understood the operation well enough to adapt when reality interfered. That is the part most organizations miss.
Semperis research reveals that although 96% of organizations have a cyber crisis response plan, 71% still experienced business-stopping cyber incidents. One important reason for the gap is that most recovery plans are built around pre-existing successful conditions:
- Identity is intact.
- Access still works.
- Communication is reliable.
- Dependencies behave as expected.
- Teams can still coordinate.
But incidents do not preserve assumptions, and the original plan rarely survives contact with reality.
That is why resilience is not really about backup technology. It is about whether the organization can still operate once the dependencies behind the recovery process start to fail.
Resilience is operational
The most important part of any successful heist is execution.
In Ocean’s Eleven, the crew had roughly two weeks to plan, prepare, rehearse, test assumptions, and adapt before execution began. Weeks of preparation, backed by years of experience, distilled into a few minutes where failure would have ended the operation immediately.
Most organizations will never execute a casino heist. But they will eventually face the moment where critical systems stop working, communications become unreliable, authentication breaks down, and the recovery process no longer matches the scenario that was tested.
That is where resilience actually matters. Because resilience is not a technology problem. It is an operational one.
It is about whether teams can continue functioning when the assumptions behind the process collapse. Whether people understand the mission well enough to adapt without waiting for instructions that may never arrive.
If you want true cyber resilience, learn to rob a bank
Plan for failure. Rehearse under uncomfortable conditions. Build teams that can operate when the environment stops behaving as expected.
Why can a Formula 1 team change four tires in roughly three seconds? Because the operation has already been tested repeatedly under pressure. The team understands:
- The sequence
- The dependencies
- The timing
- The weak points
- What works
- What fails
And where they cannot eliminate failure, they design for it.
That’s resilience. Not the absence of failure, but the ability to continue operating when failure occurs.
Because cyber recovery isn’t really about bank heists or Formula 1 pit crews. It is about being able to recover what matters most, when it matters most. It’s about identity. It’s about trust.
It’s about resilience.
If authentication, privileged access, coordination, and trust collapse during an incident, backups alone do not restore operations. The crew still needs a way to function.
That is not just how you rob a bank. That is how you survive.
Read more about building cyber resilience
- How the Five Eyes AI Warning Changes Cyber Recovery and Resilience
- Rethinking Cyber Crisis Management: Why Plans Fail
- Beyond Cybersecurity: Crisis Resilience for the Public Sector
- Rehearse to Recover: Why Confidence Is Not the Same as Cyber Crisis Readiness
- The State of Enterprise Cyber Crisis Readiness | Semperis Reports
- Identity Resilience Checklist: 6 Ways to Think Beyond Backup
- HIP Podcast: Practice Makes Progress in Cyber Resilience with Jim Bowie, VP and CISO at Tampa General Hospital
- HIP Podcast: 130 MPH Decisions: What Drag Racing Teaches About Incident Response with Krista Arndt
- The Modern Model for Cyber Crisis Management
- Why Cyber Conflict Is a Human Problem
