• Skip to main content
  • Main Menu
  • Navigation for access to support pages
  • Navigation for access to legal pages
 Logo Viva Technology
  • FAQ
  • confirmation_numberGet Your Pass
  • Become a Partner
 Viva Technology

16-19 June 2027

Paris Expo Porte de Versailles

1 Place de la Porte de Versailles

F-75015 Paris France

More Infoarrow_right_alt

Event organizers

ThemesConference ProgramSpeakersPartners

Exhibitors at VivaTech

Startups at VivaTechInvestors at VivaTech2026 Startup Challenges and Awards

JournalistsMedia PartnersPress Releases

About UsOur CommitmentsPractical Information

©VivaTech 2016-2026 all rights reserved

Site MapSite NoticeB2B Terms & ConditionsData PrivacyStudent Terms & Conditions
What Cyber Resilience Really Means in 2026

What Cyber Resilience Really Means in 2026

Article by
Charles Albert Editorial Journalist @Viva Tech
Posted at: 07.20.2026in category:Top Stories
The organizations that survive cyberattacks aren't the ones that never get hit. They're the ones built to recover. Here's what that looks like in practice.

cyber-security.jpg We’ve all seen the stories about cyberattacks threatening businesses–from ransomware shutting down hospitals to security compromises impacting millions of customers. This is why cyber resilience has become one of the biggest business priorities of 2026.

AI has made cyber resilience even more urgent by accelerating the speed, scale, and sophistication of cyber threats. In light of this, the definition of cyber resilience has expanded from mainly focusing on prevention to also include detection, containment and recovery.

Beyond prevention: the shift to resilience

For years, cybersecurity strategies focused on keeping attackers out. Firewalls, antivirus software, and perimeter defenses were designed around the assumption that if you build strong enough walls, you can stop attacks before they happen.

That assumption no longer holds. Today, organizations operate across cloud environments, connected devices, third-party software providers and AI-powered workflows. Each of these digital connections is another opportunity for attackers to strike.

At the same time, AI has upended the security game, said Jamal Basrire, Leader for Cyber and Cloud Transformation at PwC, on stage at VivaTech 2026: “AI can now discover and exploit vulnerabilities at a scale and speed we've never observed in the past. So we are entering a world where both attackers and defenders operate at machine speed."

Cyber resilience recognizes this new reality. Instead of assuming breaches can always be prevented, resilient organizations prepare for the possibility that attacks will succeed, and build systems capable of maintaining critical operations anyway.

Why "never get hit" is no longer the goal

A resilient organization’s security goal isn’t perfection – it’s continuity.

That means identifying critical business services, protecting the systems that matter most, detecting threats quickly, minimizing operational disruption, and restoring services as quickly as possible. Recovery from attacks also needs to be built into the strategy from day one.

This approach changes how organizations measure success. Instead of only counting how many attacks were blocked, leaders are also tracking recovery time, business continuity, operational resilience, and the organization's ability to adapt after a security incident.

How the threat landscape changed overnight

AI allows attackers to automate phishing campaigns, generate convincing deepfakes, write malicious code more efficiently, and identify vulnerabilities at unprecedented speed.

"AI is so easy to use for attackers, for discovering vulnerabilities,” explains Damien Lucas, CEO of cloud provider Scaleway. “We know more and more about our vulnerabilities, and we have to actually fix them even quicker than ever. Because of that, it’s a lot of work."

Organizations have to counter these AI-powered attacks while also managing growing risks from ransomware, software supply chain attacks, insider threats, and increasingly complex cloud environments. The result is a cyber threat landscape where attacks arrive faster, evolve more quickly, and target every layer of the business.

AI on both sides of the firewall

Artificial intelligence makes attackers more effective, but it's also giving defenders new ways to identify and respond to threats.

How attackers are using AI to move faster

Cybercriminals are using generative AI to improve both the quality and quantity of attacks. Personalized phishing emails that once took hours can be made in seconds. Malware can be modified automatically to avoid detection. Social engineering attacks are becoming more convincing with AI-generated voices, images and videos.

"You don't need coding skills right now to do a scam or phishing website," warned Marijus Briedis, CTO of NordVPN, at VivaTech 2026. “You just shoot up the cloud of code, ask for it, and off you go."

Automation also allows attackers to scan large numbers of organizations simultaneously, increasing the chances they’ll find exploitable weaknesses.

How defenders are using AI to fight back

Fortunately, defenders can use these same technologies to combat attacks.

AI can analyze billions of events across enterprise networks, helping security teams identify unusual behavior far sooner than traditional rules-based systems. Automated incident response can isolate compromised devices within seconds, limiting the spread of an attack.

Still, Lucas says organizations can’t ease up: "We should assume that it's benefiting the attackers more. We should assume that the attackers are using all the latest technologies in AI and even more, because this is the only way we will be able to correctly protect our cloud."

This is why companies are also investing heavily in predictive analytics, continuous monitoring, and intelligent automation to improve detection and accelerate recovery after attacks.

The organizational resilience gap

While more organizations understand the need for cyber resilience, not all are progressing at the same pace.

Why large enterprises and SMBs are drifting apart

Large enterprises tend to have dedicated cybersecurity teams, mature governance structures, and significant investment in resilience programs.

Smaller organizations often operate with fewer resources, even while facing many of the same threats. SMBs are also more likely to depend on third-party software, cloud platforms, and managed service providers to access enterprise-grade technology.

These services improve efficiency, but they also create shared risks. A vulnerability affecting one provider can impact thousands of customers simultaneously, regardless of their own internal security measures.

Building resilience requires organizations to understand not only their own systems, but also the resilience of their suppliers, partners, and digital ecosystem.

What highly resilient organizations actually do differently

According to the World Economic Forum’s most recent Global Cybersecurity Outlook report, the most cyber resilient organizations share several common characteristics:

  • Resilience rises to the top. In highly resilient organizations, CEOs are very concerned about evolving risks such as AI-related vulnerabilities.
  • Cybersecurity is treated as a business function, not just an IT responsibility. Highly resilient companies regularly test incident response plans, maintain offline backups, monitor their supply chains, and invest in employee awareness.
  • They assume disruption will happen. Instead of asking, "How do we prevent every attack?," highly resilient businesses ask, "How do we continue serving customers if one succeeds?"

Governance, boards, and shared responsibility

Executives increasingly recognize that cybersecurity incidents can adversely affect revenue, reputation, customer trust, regulatory compliance, and shareholder confidence.

Why cyber resilience is now a boardroom conversation

Boards are increasingly involved in security strategy. Andres Sutt, Estonia’s former Minister of Entrepreneurship and Information Technology, says this is imperative to cyber resilience: "It has to be a topic at the C-level. discussed regularly. What's the resilience of our organization in terms of cyber? If you can't get there, then you will certainly fail."

Instead of focusing solely on whether security controls are in place, leaders are asking:

  • Which business services are most critical?
  • How quickly can we recover from disruption?
  • What are our biggest third-party dependencies?
  • Are we prepared for a crisis involving AI or cloud infrastructure?

Cyber resilience provides a framework for addressing these questions.

The role of regulation in raising the floor

Governments are also shifting expectations.

In Europe, initiatives such as the EU Cyber Resilience Act establish baseline cybersecurity requirements for connected products placed on the market, encouraging security throughout the product lifecycle.

Other frameworks, including NIS2 and sector-specific regulations, similarly emphasize governance, accountability, incident reporting and operational resilience.

These initiatives signal that cyber resilience is becoming an organizational expectation.

Building a resilient organization from the inside out

Technology alone can’t ensure resilience. Organizations also need the right people, processes, and culture to respond effectively when incidents occur.

People, culture, and the human layer of defense

Employees are both the strongest and weakest links in cybersecurity.

Regular awareness training, simulated phishing exercises, clearly defined incident reporting procedures, and cross-functional crisis planning all help organizations respond more effectively when attacks occur. "It's not the computer who clicks on the wrong link,” says Sutt. “It's always a human, and these awareness campaigns are equally important."

Cyber resilience also requires preparation. Strong identification and prevention strategies are essential, but Briedis says people play an irreplaceable role: "When the new technology comes in and we don't understand it yet fully, we tend to make mistakes. And that's where the human firewall comes in. You have to be vigilant and educate yourselves.”

Supply chains, third parties, and the risks you can't fully control

Critical business operations increasingly rely on software vendors, cloud providers, data processors, AI services, and other external partners.

Every connection creates potential risk, so enterprise resilience requires understanding supplier dependencies, evaluating third-party resilience, and continuously monitoring digital ecosystems.

Organizations are also turning to behavioral analytics to identify suspicious activity across interconnected environments before small anomalies become major incidents.

What comes next

Cyber resilience has to evolve alongside technology to keep up with attackers.

Quantum, AI governance, and the threats on the horizon

Quantum computing is emerging as the next technology that could reshape encryption standards. "Quantum is coming and quantum will revolutionize all that,” warns Lucas. “It's very important to get prepared for quantum." Organizations should begin considering quantum's impact on cybersecurity as part of their long-term resilience strategy.

The rise of autonomous AI agents, which are able to automate both attacks and defensive responses, will raise security stakes even higher. And increasing regulatory oversight will require organizations to show compliance, as well as measurable resilience.

Resilience as a competitive advantage

The organizations best positioned for the next decade won't necessarily be the ones that experience the fewest attacks. They'll be the ones that recover the fastest, maintain customer trust during disruptions, and adapt continuously as threats evolve.

Cyber resilience is ultimately about maintaining critical services, customer trust and the ability to operate, even when under attack.

For more on how to build up cyber resilience, watch this session from VivaTech 2026: “AI, Security, and Trust: Who Protects the Digital World?”

Share this

Related articles

 Photo News

The Tech Ending the Language Barrier

September 30 2026

From software that translates documents to earbuds that make conversations across the world easier, technology is revolutionizing the way we communicate across borders.

Top Stories
 Photo News

Relive the Best of VivaTech 2026

September 24 2026

Discover the hot topics of VivaTech 2026 and get your own personalized deep dive on the things that matter to you.

Top Stories
 Photo News

How Startup Culture is Perpetuating the Gender Pay Gap

September 18 2026

On International Equal Pay Day we dive into the gender pay gap that persists in the startup and tech community, and what is being done to close it.

Top Stories
  1.  Logo Viva Technology
  2. News
  3. What Cyber Resilience Really Means in 2026