Resilience Became a Board Problem in 2025. Most Architectures Have Not Caught Up
2025 was the year cyber resilience stopped being an IT concern and became a governance one. DORA has applied in full across the EU financial sector since January, NIS2 has been transposed into national law across member states, and both frameworks put responsibility explicitly on management bodies — boards approve the risk measures and can be held liable for failings.
The regulations moved quickly. The architectures underneath most organizations did not.
Why this reaches beyond the EU
Plenty of organizations outside the EU fall in scope through the services they provide or the customers they serve. If you supply software or infrastructure to an in-scope entity, their obligations land on you contractually whether or not the regulation names you directly. That flow-down is the part teams miss.
The 72-hour clock is an engineering requirement
Mandatory incident reporting inside tight windows sounds like a policy matter. It is not. Hitting a 72-hour notification deadline means being able to answer, quickly and defensibly, what was accessed, what moved, and when — which is a question about logging, retention, and correlation decided long before the incident.
- Can you reconstruct a timeline? If logs live in three systems with different retention windows, the answer under pressure is no.
- Is the incident plan documented and rehearsed? Tabletop exercises exist because the first run-through should not be the real one.
- Who declares an incident? Ambiguity here burns hours you do not have.
Third-party risk is now your risk
Both frameworks push hard on supply chain and ICT provider diligence, and DORA introduces oversight of critical third-party providers directly. You are expected to assess, document, and evidence the resilience of your vendors. An outage or breach at a provider is your regulatory exposure even when your own systems were never touched.
The 2025 disruptions made that concrete — a ransomware attack on an aviation technology provider in September grounded operations at major European airports, and the affected airlines had done nothing wrong themselves.
Resilience is not a security control you buy. It is a property of how the system was built — and it is expensive to add afterwards.
What actually moves the needle
The controls that satisfy regulators are the same ones that survive real incidents: multi-factor authentication everywhere, immutable backups that have been restored from in anger, segmentation that limits blast radius, and recovery objectives that someone has actually timed rather than estimated.
We build these in at architecture time on client platforms, because retrofitting evidence-grade logging and tested recovery into a live system costs several times what designing for it would have. If you are scoping a platform now, this belongs in the first design review, not the security audit before launch.


