A cyber resilience framework is the structure that organises how you withstand and recover from cyber attack, covering five operational functions with governance across all of them: identify, protect, detect, respond and recover. It differs from a cyber security framework in where the weight falls. Security frameworks concentrate on keeping attackers out. A resilience framework assumes some will get in and gives equal standing to detecting them, responding well and restoring service.
- Five functions, not just the protective ones, each with named owners and evidence.
- Governance across the whole thing, because unowned functions decay first.
- Recognised standards supplying the detail, rather than a structure invented in house.
- The same controls serving security, privacy and continuity rather than three parallel sets.
- Evidence produced by running it, so the framework can be shown to work.
What is a cyber resilience framework?
A cyber resilience framework organises the work of surviving cyber attack into functions, assigns each one an owner, and defines what evidence each produces. The point of a framework is coverage. Without one, effort concentrates wherever the last incident or the loudest vendor pointed, which in most organisations means prevention is well funded while detection and recovery are assumed rather than tested.
The framing that separates resilience from security is the assumption you start from. Security asks how to stop the attack. Resilience asks what happens when one succeeds, and treats that as the normal case rather than the failure case. Both matter, and the difference is one of emphasis rather than opposition, but it changes what gets funded and what gets tested.
For the definition of cyber resilience itself, how it differs from cyber security and where the EU Cyber Resilience Act fits, see cyber resilience. This page is about how the framework is structured.
What are the functions of a cyber resilience framework?
The five operational functions below are the widely adopted structure, with governance as a sixth that runs across all of them rather than sitting in sequence.

- Identify: know what you have and what threatens it. Asset inventory, data flows, supplier dependencies and a risk assessment that is current rather than annual.
- Protect: the safeguards. Access control, patching, encryption, segmentation, backup and the training that makes them stick.
- Detect: the capability to notice. Logging, monitoring, alerting and someone actually watching, which is the part most often missing.
- Respond: containment, decision making, forensics and communication, including to regulators and customers when required.
- Recover: restoring service and learning. This is where recovery planning and continuity meet cyber, and where an untested plan is exposed.
- Govern: ownership, risk appetite, oversight and reporting across all five. Without it the functions drift apart and nobody notices until an incident.
The value of naming all six is that gaps become visible. An organisation with strong protection and no detection has bought locks and no alarm. One with detection and no rehearsed response finds out during the incident that nobody knows who decides.
Which frameworks and standards can you build on?
You do not need to invent this, and the choice is less about picking a winner than about recognising that the available frameworks do two different jobs. Some give you structure and vocabulary. Others give you a certifiable management system that an auditor can verify. A working framework uses both.
| Framework | What it gives you | Where it fits |
|---|---|---|
| NIST CSF 2.0 | The function structure used above, with categories beneath each. Descriptive rather than certifiable. | Structure. A shared language across technical and board audiences, and a way to assess coverage. |
| NCSC Cyber Assessment Framework | Four objectives covering risk management, protection, detection and minimising impact. | Structure, for UK operators of essential services and organisations assessed against that regime. |
| CIS Controls | A prioritised list of technical safeguards in implementation order. | Structure, when the question is which control to implement next rather than how to organise the programme. |
| ISO 27001 | A certifiable management system for information security, with Annex A controls, independently audited. | The security domain of the Resilience Loop. Proving it externally rather than organising it internally. |
| ISO 27701 | A management system for privacy information, certifiable alongside ISO 27001. | The privacy domain of the Loop. Necessary because most cyber incidents also involve personal data. |
| ISO 42001 | A certifiable management system for AI, covering how AI systems are governed and controlled. | The AI domain of the Loop. Necessary once AI forms part of the estate you are defending. |
| ISO 22301 and ISO/IEC 27031 | Continuity management and ICT readiness, supplying the recover function properly. | Recovery, which is usually the weakest function. |
Read down the right hand column and the shape of the answer appears. The structural frameworks tell you what to cover. The certifiable ones prove you are covering it, and the three that matter for a modern estate are precisely the three domains of the Resilience Loop: information security, data privacy and AI governance.
That matters for scope, not just tidiness. A cyber resilience framework built on the security standard alone will handle the attack and miss its consequences. A ransomware event that exposes customer records is a privacy matter with its own notification obligations and deadlines. A model trained on data you cannot account for is an AI governance problem that a security control set was never designed to catch. Both sit inside the boundary of what a cyber incident now involves, so a framework scoped to security alone has gaps that only appear during an incident, which is the worst moment to discover them.
The practical combination, then, is a structural framework for coverage and vocabulary, the Loop’s three certifiable management systems underneath it, and ISO 22301 filling out recovery. That sounds like a great deal of framework, and it would be if each were run as a separate programme with its own control set. Run as one system it is considerably less work than it looks, which is the subject of the next section.
There's a bigger picture behind this.
This page covers one part of business resilience. Real Resilience — IO’s framework for connecting security, privacy and AI governance — is where the full picture comes together.
How is this different from a business resilience framework?
Scope. A cyber resilience framework covers one threat class, thoroughly. It organises everything relating to attack, compromise and technology recovery, and it is the right lens when the risk you are managing is an adversary.
A business resilience framework is wider. It covers disruption of any origin, including flood, supplier failure, key person loss and regulatory change, and it treats information security, data privacy and AI governance as one connected system rather than three. The cyber framework nests inside it as the security lens.
There is a third framework worth distinguishing, because the terms are used loosely. An operational resilience framework is the regulatory model built around important business services and impact tolerances. It asks how long a service can be down before harm becomes unacceptable, whatever the cause. Cyber resilience is one of the causes it plans for.
- Cyber resilience framework: one threat class, in depth. Adversary driven.
- Business resilience framework: all disruption, plus security, privacy and AI as one system.
- Operational resilience framework: services and tolerances, driven by regulatory expectation.
How do you put a cyber resilience framework in place?
Assessment first, and honestly. The most common mistake is adopting a framework and declaring the work started, when the framework’s value is in the gaps it exposes.
- Assess against all six functions: score current capability against a maturity tier, expecting protect to look better than detect, respond and recover. See how to score each function.
- Fix the weakest function before improving the strongest: marginal gains in prevention are worth less than a first real detection capability.
- Assign every function an owner: a function without a named owner is not being run, whatever the documentation says.
- Map controls once: implement each control against every framework that asks for it rather than repeating the work per standard.
- Test the response and recovery functions: these are the two that cannot be verified by inspection. Only exercises tell you whether they work.
- Report on a cycle: coverage by function, tested versus assumed, and what changed since last time.
Sequencing this against a finite budget is a strategic question rather than a structural one, and it is covered under cyber resilience strategy.
ISO 27001 made easy
An 81% Headstart from day one
We’ve done the hard work for you, giving you an 81% Headstart from the moment you log on. All you have to do is fill in the blanks.
How does the framework connect to the Resilience Loop?
Almost every control a cyber resilience framework asks for is also asked for by something else. Access management appears in your security standard, your privacy obligations and your recovery plans. Supplier assessment appears in all three. Run as separate programmes, that control is documented three times and evidenced properly in none of them.

The Resilience Loop runs information security under ISO 27001, data privacy under ISO 27701 and AI governance under ISO 42001 as one connected system, with cyber resilience as a lens over that shared control set. Ransomware shows why this matters. It is a security incident, frequently a personal data breach and a recovery event simultaneously, and an organisation running those as three programmes answers it three times while the clock runs.
How do you prove the framework works?
Each function produces evidence, and the framework is judged on that rather than on its documentation. Identify produces a current asset and risk picture. Protect produces control records. Detect produces monitoring coverage and alert handling. Respond and recover produce exercise records, real incident timelines and the improvements that followed. Govern produces the reporting trail.
The functions that get skipped are always respond and recover, because they are the two that cannot be evidenced by inspection. A control can be shown to exist. A response capability can only be shown by having exercised it. The approach is set out in how to evidence resilience, and the Resilience Score gives you a starting baseline. Certification under ISO 27001 gives the whole thing independent verification, which is a stronger claim than self assessment.
Why choose ISMS.online for a cyber resilience framework?
Frameworks fail on maintenance rather than design. ISMS.online is built to keep all six functions owned, current and evidenced.
- One control set, every framework: map a control once and satisfy NIST CSF, ISO 27001, ISO 27701, ISO 42001 and ISO 22301 together instead of maintaining parallel sets.
- Coverage visible by function: see at a glance where detection or recovery is thin rather than discovering it during an incident.
- Owners and review cycles built in: every function has a named owner and a review date, with reminders that stop drift.
- Exercises and incidents recorded together: response and recovery evidence accumulates as you work rather than being reconstructed.
- Supplier risk in the same system: the third parties your resilience depends on are assessed and monitored alongside your own controls.
- Helps you achieve certification: the structure and evidence an ISO 27001 audit asks for, prepared as you go.
- Built for UK and regulated markets: designed for organisations that have to prove resilience to auditors and customers.
See how it fits together on the business resilience platform, or book a demo.
FAQs
What is the difference between a cyber security framework and a cyber resilience framework?
They cover much the same functions, and the difference is emphasis. A cyber security framework is weighted towards keeping attackers out. A cyber resilience framework starts from the assumption that some attacks will succeed and gives detection, response and recovery the same standing as prevention. In practice this shows up in budget and testing: resilience programmes exercise their response and recovery capability, whereas security programmes often assume it.
Is NIST CSF or ISO 27001 better for cyber resilience?
They do different jobs and are commonly used together. NIST CSF gives you a structure and a shared vocabulary for assessing coverage across functions, but it is descriptive and there is nothing to certify against. ISO 27001 gives you a management system that is independently audited and certifiable, which is what customers and tender processes ask for. Using CSF to organise the conversation and ISO 27001 to prove the result is a well trodden combination.
How many functions does NIST CSF 2.0 have?
Six. Version 2.0 added Govern to the five that came before it, which were identify, protect, detect, respond and recover. Govern is not a stage in a sequence. It sits across the other five and covers ownership, risk appetite, oversight and reporting, reflecting that most framework failures are governance failures rather than technical ones.
Do small organisations need a cyber resilience framework?
Yes, though a much lighter one. The six functions apply at any size, and the value for a smaller organisation is in coverage rather than depth: knowing that someone owns detection and that recovery has actually been tested. The failure pattern is the same at every scale, which is heavy investment in prevention and an untested assumption that recovery will work.
Where does the EU Cyber Resilience Act fit into this?
The Cyber Resilience Act regulates products with digital elements rather than the internal resilience of an organisation, so it sits alongside a framework instead of inside it. If you build or sell software or connected hardware, it places obligations on the security of what you ship, including vulnerability handling and update provision. If you only consume technology, it shapes what you can expect from suppliers. Detail is on the cyber resilience overview page.






