This year, the UK has witnessed two major cyber-attacks with far-reaching consequences: the ransomware incident that hit the retail sector and the disruption at Jaguar Land Rover (JLR). These events are not isolated, illustrating a shift in the landscape where cyber risks are growing and the impacts are more widespread.
Against this backdrop, Scotland has refreshed its strategic framework for cyber resilience, leading the way in the UK, while aligning with European frameworks.
Despite differences in approach (namely Scotland’s focus on societal resilience and shared responsibility versus the EU’s focus on regulatory compliance), the central aim remains consistent: to keep pace with the evolving threats and opportunities presented by our increasingly digital world.
This commitment underscores Scotland’s proactive stance in adapting to the modern cyber landscape and ensuring that its strategies remain robust.
What Is Cyber Resilience And Why Does It Matter?
The term “cyber resilience” is often referenced; however, its definition is not always consistent or well understood. According to the Scottish framework:
‘Cyber resilience is the ability to prevent, withstand, respond to, recover and learn from cyber incidents.’
Cyber resilience goes beyond cybersecurity’s traditional emphasis on prevention and response.
The Scottish framework recognises that these measures alone are insufficient for minimising the overall impact of a cyber threat. By emphasising the concept of resilience, the framework draws attention to the limitations of relying solely on cybersecurity practices for prevention and response; instead reframing the challenge towards enduring, recovering and learning from incidents to thrive despite ongoing risks.
Importantly, the framework stresses that achieving true resilience requires more than the efforts of just technology and security teams. It advocates for shared responsibility across the entire ecosystem, highlighting that everyone has a role to play in strengthening cyber resilience.
Nevertheless, it remains to be seen whether the concept of “cyber resilience” will resonate with those outside the immediate cyber and technology community.
A Vision for Scotland: Seven Outcomes for a Resilient Nation
Scotland’s Strategic Framework for a Cyber Resilient Nation sets out a bold vision through seven outcomes:
- People recognise the cyber risks and are well prepared to manage them.
- National cybersecurity coordination and response arrangements are effective.
- Scotland’s digital public services are cyber resilient.
- Public sector organisations effectively manage their cyber risks.
- Businesses recognise the cyber risks and are well prepared to manage them.
- Third sector organisations recognise the cyber risks and are well prepared to manage them.
- Scotland has a flourishing cybersecurity industry and a skilled cyber security profession.
Among the seven key steps, the third, ensuring digital public services are cyber resilient, and fourth, the effective management of cyber risks in public sector organisations, deserve particular attention.
The framework rightly prioritises the resilience of public services, recognising their critical role in society as the threat landscape evolves.
However, in practice, these services do not operate in isolation.
The framework itself acknowledges that Scotland’s digital public services are deeply interconnected with the third sector, which comprises around 46,000 organisations delivering vital support in areas such as health, social care, and education.
This interdependence presents a significant challenge: while some services clearly fall within the scope of Critical National Infrastructure (CNI), many others do not, yet all have a profound impact on people’s lives.
The Isle of Skye incident, where a cyber-attack on the Co-op supply chain disrupted essential goods for residents, is a stark reminder that vulnerabilities in one part of the ecosystem can cascade across sectors, affecting communities in unexpected ways.
This example illustrates how our drive for accessibility and interconnectedness also increases the vulnerability of public services to cyber threats. This emphasises the necessity of ensuring public systems are resilient and secure by default, particularly as the threat landscape continues to evolve.
As we drive for greater accessibility and interconnectedness, we must also recognise that this increases the complexity of building resilience.
Embedding cyber resilience cannot be confined to technical controls or compliance checklists; it must become part of the culture, leadership, and daily operations across both public and third sector organisations.
The framework’s call for shared responsibility, partnership, and a whole-of-society approach is essential, but translating this into practice will require sustained effort, resources, and a recognition that the weakest link, wherever it lies, can have real-world consequences for people of Scotland and beyond.
Implementing the Seven Outcomes
The primary challenge is to ensure that the ambitions of the framework are achieved not only within public services but across the entire ecosystem of organisations that we depend on.
To establish true resilience in an ever more interconnected world, cyber resilience requires more than mere awareness; substantial investment and strong leadership are essential.
While the framework rightly focuses on security professionals to ensure effective risk communication, the greatest impact may come from boards and leaders in all sectors actively acknowledging and managing these risks from a business standpoint.
Recommended reading
- Scots Gov Sets Out Refreshed Cyber Resilience Strategy
- UK Facing 4 Major Cyber-Attacks Each Week, Warns NCSC
- Winners Announced For The 2025 Scottish Cyber Awards
As the imperative now is to initiate action organisation-wide, this should begin with engaging boards and all operational teams in simulated exercises to prepare for actual cyber threats, which will aid in the identification of critical assets.
It is equally important to assess how these assets interact, as their interconnectivity will greatly influence recovery strategies. Recovery planning must be thorough and inclusive, extending beyond technical departments.
These exercises should clearly articulate the significance of resilience and the potential consequences of prolonged service disruptions. When stakeholders comprehend the full impact, they are more likely to support resilience initiatives.
In essence, advancing cyber resilience necessitates recognising that it encompasses far more than technical safeguards; it is about cultivating a culture of awareness and preparedness throughout society, which the Scottish framework signals.





