Cyber resilience becomes an economic investment criterion

August 25, 2026

Companies are increasingly assessing IT investment not only in terms of cost savings or productivity gains, but also by the contribution technology makes to operational resilience. Data platforms, artificial intelligence, cloud infrastructure and cybersecurity are becoming ever more interdependent. Modernising these areas in isolation can create new dependencies; treating them as part of a common resilience architecture can help organisations identify risks earlier and respond more effectively to economic disruption.

Geopolitical tensions, fragile supply chains and persistent cost pressure are changing the logic behind technology investment. Until relatively recently, a new IT system could often be justified primarily by lower process costs, faster workflows or additional capacity. Today, another measure is becoming increasingly important: how effectively can an organisation maintain operations when conditions change unexpectedly?

Resilience is therefore becoming an economic consideration in its own right. A production stoppage, cyberattack or sudden supply-chain disruption does not create a purely technical problem. It can affect revenue, customer relationships, delivery capability and competitiveness. Modern IT consequently has to fulfil two requirements at the same time: it must improve efficiency while strengthening the organisation’s ability to respond to disruption.

Data quality determines responsiveness

The starting point is often data. Companies may possess large volumes of operational information, but those data are frequently distributed across ERP systems, production environments, cloud applications and IoT infrastructure. Only when information can be combined and placed in a meaningful context does it become possible to identify changes early enough to act on them.

The strategic value of modern analytics platforms therefore lies less in producing additional dashboards than in making deviations visible sooner. Changes in lead times, demand, inventories or costs can be identified earlier and translated into business decisions. This requires consistent data models, clear responsibilities and interoperable systems. A fragmented data landscape remains a risk even when sophisticated analytics tools are placed on top of it.

Artificial intelligence reinforces this relationship. Predictive models can anticipate developments and prepare possible courses of action, while AI agents are expected to take over an increasing number of defined process steps autonomously. Their usefulness, however, depends on a continuous supply of current and trustworthy information. AI does not compensate for poor data quality; in some circumstances, it can amplify its consequences.

The strategic question is therefore not simply how much AI an organisation uses, but whether its underlying information architecture is robust enough to support reliable automated decisions.

Infrastructure becomes part of risk management

The role of cloud computing is undergoing a similar shift. Cloud is no longer merely an alternative to an organisation’s own data centre. The more important question is whether an architecture can scale applications flexibly, absorb failures and restore critical processes quickly when disruption occurs.

Distributed systems, automated failover mechanisms and redundant data storage can significantly improve operational continuity. At the same time, an uncontrolled expansion of cloud environments can introduce new risks. Multiple platforms, inconsistent access models and growing numbers of interfaces can complicate governance, make costs more difficult to control and potentially increase the attack surface.

Modernisation should therefore not be equated with moving as many services as possible into the cloud. A more strategic approach is to assess availability, security, performance and cost together. For business-critical applications in particular, organisations need to understand which dependencies are being created and how quickly services could be restored if part of the infrastructure becomes unavailable.

That turns infrastructure design into a component of enterprise risk management rather than a purely technical decision.

Cybersecurity determines operational continuity

The same development is most apparent in cybersecurity. As business processes become more digitally interconnected, the consequences of security incidents become increasingly operational. A compromised account can affect production, communications or financial processes, while a ransomware incident can develop from an IT problem into a corporate crisis within hours.

Security can therefore no longer be treated simply as a separate protective layer surrounding the business. Modern architectures increasingly integrate controls into identities, devices, applications and processes.

Zero-trust principles, for example, reduce reliance on implicit trust between users and systems. Identity and access management controls permissions, while monitoring and detection technologies are intended to identify suspicious behaviour as early as possible. The objective is not simply to build a higher technical barrier, but to reduce the number of opportunities an attacker has to move through an organisation unnoticed.

Yet prevention alone does not create resilience. Organisations also have to assume that some protective controls will eventually fail. Tested backups, clearly defined recovery procedures and regular crisis exercises are therefore becoming as important as threat detection itself.

The relevant measure is no longer simply whether an organisation can prevent a cyber incident. It is also how quickly it can return to controlled operations once one has occurred.

The return on IT investment is changing

This shift also alters the economic assessment of technology expenditure. An investment can generate value not only by reducing labour costs or automating a process, but also by shortening a production outage, identifying a supply problem earlier or enabling faster decisions under uncertain conditions.

Jana-Irina Luley, Senior Director and General Manager DTS at Dell Technologies, has argued in this context for a more integrated approach to technology modernisation. Her assessment is that organisations can strengthen their resilience more effectively when data analytics, automation and flexible infrastructures are considered together rather than modernised as separate disciplines. The underlying comments were previously published by it-welt.at.

For companies, this points to a broader investment principle. Resilience does not depend on any single technology. AI requires reliable data. Cloud environments require disciplined governance. Digital processes only create lasting value when they are adequately protected and can be restored quickly after disruption.

IT investment is therefore becoming an investment in the organisation’s capacity to remain operational, make decisions and continue delivering under pressure. In a volatile economic environment, that may become one of the most important criteria of all: not which technology appears most advanced, but which architecture allows the business to keep functioning when the next disruption has already begun.

Related Articles

Editor’s note: Organised crime has become a service industry

Operation Jackal IV is significant not simply because of the number of arrests it produced, but because of what it reveals about the structure of contemporary organised crime. Technical infrastructure, social engineering and money laundering are increasingly...

Interpol operation targets West African organised crime networks

Fifty-eight arrests, 263 identified suspects and investigations spanning six continents: Interpol’s Operation Jackal IV has targeted West African organised crime networks involved in financial fraud, money laundering and Crime-as-a-Service. The cases illustrate how...

Share This