From Aspiration to Resilience: Rethinking Data Security
Cybersecurity maturity is no longer about how many controls an organisation has, but how well it can protect, withstand, recover and adapt when those controls inevitably fail.
Sanchez P.
10/7/202647 min read


Abstract
Cybersecurity is increasingly becoming a question of organisational resilience rather than solely technical protection. As organisations adopt cloud services, depend on interconnected suppliers and software ecosystems, and integrate generative artificial intelligence into business processes, traditional perimeter-based security models are becoming less sufficient. This paper examines this transition in the Swiss context using findings from the MSM Research AG study Data Security in Switzerland: Between Aspiration and Reality, based on a survey of 84 Swiss organisations, and situates these findings within recent academic research on Zero Trust, cloud security, supply-chain risk, Shadow AI and cyber resilience. The analysis identifies a persistent security-maturity paradox: although organisations report high levels of security maturity and continue to invest substantially in cybersecurity, important implementation gaps remain in regulatory integration, third-party risk management, cloud-security assurance and the governance of emerging AI use. The paper argues that these gaps are interconnected and cannot be addressed effectively through additional security controls or expenditure alone. Instead, security maturity should be understood as a demonstrable organisational capability encompassing visibility, governance, prevention and protection, detection and response, and recovery and adaptation. This perspective shifts the focus from counting implemented controls towards assessing whether organisations can protect critical information and services, manage digital dependencies, withstand disruption, recover effectively and adapt when preventive controls fail. The paper proposes that Swiss organisations should therefore complement preventive cybersecurity with data-centric Zero Trust, stronger supply-chain and cloud governance, responsible AI governance and systematic resilience testing. The Swiss evidence illustrates a broader transformation in cybersecurity: as organisations increasingly operate without a single, clearly defined perimeter, security maturity must be measured by the organisation's ability to remain secure and operational across distributed and continuously changing digital environments.
Keywords: cybersecurity, data security, cyber resilience, Zero Trust, supply-chain risk, Shadow AI, Switzerland, governance
1. Introduction
The strategic importance of data security has increased as organisations become more digitally interconnected and increasingly dependent on cloud services, external technology providers and distributed digital infrastructures. These developments have weakened the assumptions underlying traditional perimeter-based security models, in which organisational systems could be protected primarily through a defined network boundary. Recent research instead emphasises security architectures based on continuous verification, least-privilege access and dynamic assessment of users, devices and resources (Gambo and Almulhem, 2026). At the same time, the growing organisational dependence on external suppliers has created additional sources of cyber risk, as disruptions or compromises within interconnected supply chains can affect the availability, integrity and confidentiality of organisational assets (Herburger, Wieland and Hochstrasser, 2024). The organisational use of artificial intelligence introduces a further governance challenge, as employees increasingly adopt AI tools outside formally approved frameworks, creating what recent research describes as ‘Shadow AI’ (Silic, Silic and Kind-Trüller, 2025).
These developments have important implications for how data security should be understood. Rather than treating cybersecurity primarily as a technical exercise concerned with preventing unauthorised access, organisations increasingly need to develop capabilities that allow them to prepare for, withstand, respond to and recover from cyber incidents. Recent research on organisational cyber resilience highlights precisely this shift, arguing that cyber resilience should be understood as an organisational capability rather than solely as a collection of technical controls (Neri, Niccolini and Virili, 2024). Similarly, research on cyber resilience emphasises the importance of preparation, absorption, recovery and adaptation when organisations face successful cyber incidents (Alhidaifi, Asghar and Ansari, 2024; Tzavara and Vassiliadis, 2024).
The 2026 MSM Research study Data Security in Switzerland: Between Aspiration and Reality provides a timely empirical perspective on these developments in the Swiss context. Based on a survey of 84 Swiss companies, the study reports that cybersecurity, disaster recovery and business continuity are receiving an increasing share of external ICT expenditure. At the same time, 57 per cent of respondents assess their security maturity as high or very high. However, this positive perception exists alongside significant implementation gaps, particularly in regulatory compliance, third-party and supply-chain risk management, and cloud security (MSM Research AG, 2026). The study therefore identifies a potential discrepancy between perceived security maturity and demonstrable organisational capability—a tension that is consistent with the broader literature's movement from control-based cybersecurity towards organisational cyber resilience (MSM Research AG, 2026; Neri, Niccolini and Virili, 2024).
This discrepancy is particularly significant because the expansion of digital dependencies increases the number of actors, technologies and organisational interfaces that must be governed simultaneously. Zero Trust research demonstrates the limitations of relying on implicit trust within increasingly complex digital environments (Gambo and Almulhem, 2026). Supply-chain research shows that cyber resilience depends not only on an organisation's internal controls but also on its ability to sense, respond to and adapt to risks arising across interconnected supply networks (Herburger, Wieland and Hochstrasser, 2024). Research on Shadow AI further demonstrates how technological adoption can outpace formal governance, creating gaps between organisational policies and actual employee behaviour (Silic, Silic and Kind-Trüller, 2025). Taken together, these perspectives suggest that security maturity cannot be adequately assessed by the existence of individual controls alone; it must also reflect the organisation's ability to govern dependencies, detect emerging risks and maintain operations when preventive controls fail.
Against this background, this paper addresses the following research question:
How can Swiss organisations move from perceived security maturity towards demonstrable cyber resilience in an increasingly decentralised and data-centric digital environment?
The paper argues that this transition requires a shift from a predominantly preventive and perimeter-oriented security model towards an integrated approach centred on organisational governance, data-centric Zero Trust, digital supply-chain resilience and AI governance. These dimensions are closely interconnected. Effective governance establishes accountability for security decisions; Zero Trust provides a framework for controlling access within distributed digital environments; supply-chain resilience addresses risks arising beyond organisational boundaries; and AI governance addresses emerging forms of technology adoption that can create new data flows and governance gaps (Gambo and Almulhem, 2026; Herburger, Wieland and Hochstrasser, 2024; Silic, Silic and Kind-Trüller, 2025).
The paper therefore positions the Swiss evidence within the emerging literature on organisational cyber resilience. Its central proposition is that security maturity should be understood not primarily as the accumulation of preventive controls, but as an organisation's demonstrated capacity to protect critical information, manage digital dependencies, withstand disruption, recover from cyber incidents and adapt to changing technological and threat environments (Alhidaifi, Asghar and Ansari, 2024; Neri, Niccolini and Virili, 2024; Tzavara and Vassiliadis, 2024).
2. From cybersecurity to organisational resilience
Traditional cybersecurity has largely been concerned with protecting information systems and data against unauthorised access, disruption and compromise. Preventive and detective controls such as firewalls, endpoint protection, intrusion detection, encryption and access controls are designed to reduce the likelihood and potential impact of security incidents. This approach has historically been associated with the assumption that organisations can identify and protect a relatively stable boundary between trusted internal environments and untrusted external actors. However, the increasing complexity and interdependence of digital infrastructures has made such assumptions less sustainable.
Digital transformation has expanded the organisational technology environment far beyond traditional corporate networks. Cloud services, remote work, software-as-a-service applications, outsourced IT operations and interconnected digital ecosystems have created dependencies that extend across organisational boundaries. Consequently, cybersecurity can no longer be understood solely as the protection of systems located within a clearly defined perimeter. Instead, organisations must also be capable of maintaining secure operations when technologies, services, suppliers and users extend beyond their direct control.
This development has contributed to a growing distinction between cybersecurity and cyber resilience. While cybersecurity traditionally focuses on protecting systems and preventing, detecting and responding to cyber threats, cyber resilience addresses the organisation's ability to continue operating despite successful attacks or other disruptive events. AlHidaifi, Asghar and Ansari (2024) describe cyber resilience in terms of an organisation's or system's ability to withstand cyber attacks and return to an acceptable state when preventive cybersecurity measures fail. Tzavara and Vassiliadis (2024) similarly demonstrate that the emergence of cyber resilience reflects a growing recognition that cybersecurity controls cannot guarantee the prevention of every incident. Cyber resilience therefore complements prevention with the capabilities required to absorb disruption, recover operations and adapt to changing conditions.
The distinction is important because a security architecture can be highly effective at preventing known threats while remaining vulnerable to failures that originate outside its immediate control. A resilient organisation must therefore consider not only whether preventive controls are in place, but also whether it can detect and contain incidents, maintain critical functions, recover affected systems and learn from disruption. Cyber resilience consequently shifts the focus from the question of whether an organisation can prevent every attack to whether it can continue to fulfil its critical functions when prevention fails (AlHidaifi, Asghar and Ansari, 2024; Tzavara and Vassiliadis, 2024).
This perspective is particularly relevant to the Swiss findings presented by MSM Research. The relatively high level of perceived security maturity may indicate that many organisations have established substantial preventive capabilities. However, the comparatively limited adoption of systematic compliance processes, third-party risk management and comprehensive cloud-security measures points to a broader issue: security maturity cannot be assessed adequately by counting individual controls or measuring the presence of security technologies alone (MSM Research AG, 2026).
The concept of organisational cyber resilience provides a stronger framework for understanding this gap. Neri, Niccolini and Virili (2026) develop an integrative conceptual framework that connects cyber resilience with organisational resilience and emphasises the organisational dimensions of cybersecurity. Their analysis demonstrates that cyber resilience extends beyond technical protection and encompasses organisational characteristics, processes and the capacity to respond and adapt to cyber-related disruption. Cybersecurity therefore becomes not only an engineering challenge, but also a question of organisational capability, coordination and adaptation.
This organisational perspective helps explain the maturity paradox identified by MSM Research (2026). An organisation may possess sophisticated security technologies and conduct extensive employee-awareness programmes while still lacking the organisational mechanisms required to coordinate security across cloud environments, external suppliers, regulatory requirements and emerging technologies. High perceived maturity may therefore coexist with significant structural vulnerabilities.
The central implication is that cybersecurity maturity should increasingly be evaluated in terms of demonstrable organisational resilience, rather than solely through the presence of preventive controls. A mature organisation must be able not only to protect its systems before an incident occurs, but also to identify dependencies, respond effectively when controls fail, maintain critical operations, recover from disruption and adapt its security practices as technologies and threats evolve (Neri, Niccolini and Virili, 2026; AlHidaifi, Asghar and Ansari, 2024; Tzavara and Vassiliadis, 2024). This shift from prevention towards resilience provides the conceptual foundation for examining the specific organisational challenges identified in the Swiss data-security landscape.
3. The maturity paradox: perception versus implementation
One of the most significant findings of the MSM Research study is the apparent gap between perceived security maturity and systematic implementation. Fifty-seven per cent of surveyed Swiss organisations rate their security maturity as high or very high. At the same time, approximately 64 per cent report having defined security and data processes, while 79 per cent have established security-awareness activities such as training and onboarding (MSM Research AG, 2026). These figures indicate that information security has become an established organisational priority and that many organisations have put important foundational capabilities in place.
However, the picture changes when maturity is considered in areas that require sustained coordination, verification and organisational integration. Only around 21 per cent of respondents report systematically embedding and auditing regulatory compliance, while approximately 14 per cent systematically manage third-party and supply-chain risks (MSM Research AG, 2026). The contrast suggests that the challenge facing Swiss organisations is not necessarily a lack of security activity, but rather the uneven development of security capabilities across the organisation.
This distinction is important because the existence of a security control does not necessarily demonstrate that the organisation can use that control effectively under adverse conditions. Recent research on cybersecurity maturity models similarly cautions against treating maturity as a simple aggregation of implemented controls. Büyüközkan and Güler (2025), for example, show that cybersecurity maturity models vary considerably in their scope and structure and argue for more comprehensive approaches to maturity assessment. Papachristofis et al. (2025) likewise emphasise the importance of evaluating cybersecurity capabilities according to organisational context, risk, criticality and complexity rather than relying exclusively on maturity levels.
The same principle applies to security awareness. Employee training and onboarding are important components of organisational security, but awareness alone does not demonstrate secure behaviour or organisational resilience. A recent evidence review by Bada et al. (2025) shows that cybersecurity culture extends beyond awareness and training to include organisational values, employee behaviour, management commitment and the extent to which security becomes embedded in everyday organisational practices. Consequently, the 79 per cent reported adoption of awareness activities should not automatically be interpreted as evidence of effective security behaviour or operational preparedness.
The maturity paradox can therefore be understood as a difference between the presence of security practices and the demonstrated ability to operationalise them consistently. An organisation may have documented policies, conduct employee training and deploy sophisticated security technologies while still lacking the mechanisms required to identify critical dependencies, coordinate security decisions across organisational boundaries or respond effectively when preventive controls fail. Maturity is consequently better understood as a capability that must be demonstrated in practice rather than as a collection of controls that an organisation can claim to possess.
From this perspective, a mature organisation should be able to answer questions that go beyond control ownership: Can it identify its most critical data and business processes? Can it determine who has access to them and whether that access remains justified? Can it detect anomalous activity and rapidly revoke compromised privileges? Can it continue critical operations when a key supplier or cloud service becomes unavailable? Can it restore systems following a ransomware incident? Can management coordinate technical, operational, legal and regulatory decisions during a major disruption?
These questions shift the assessment of security maturity from control ownership to organisational capability. They also connect the concept of maturity directly to cyber resilience. Organisational resilience depends not only on preventive measures but also on the ability to detect disruption, coordinate a response, maintain critical functions, recover operations and learn from incidents. Research on organisational learning following cyber incidents similarly shows that resilience depends on organisations' ability to evaluate incidents systematically and translate experience into organisational learning (see, for example, the findings of the 34-organisation practitioner study reported by [the authors] in 2024).
The distinction becomes particularly important in the context of regulatory compliance. The Swiss Federal Act on Data Protection (FADP) requires controllers and processors to implement appropriate technical and organisational measures based on the risks involved. It also places responsibilities on controllers regarding the security capabilities of processors (FADP, 2020). Compliance is therefore not conceptually separate from operational security or supplier governance. A compliance framework that exists primarily as documentation, without mechanisms for verification, testing and continuous improvement, may create the appearance of governance without establishing equivalent operational capability.
This does not mean that compliance processes, security awareness or documented controls are ineffective. Rather, they represent inputs into organisational capability, not conclusive evidence of it. The distinction is important because compliance-oriented approaches can create incentives for organisations to demonstrate that formal requirements have been addressed without necessarily demonstrating that the underlying security objectives can be achieved in practice. Research on cybersecurity maturity assurance in supply chains provides a related warning: formal maturity requirements imposed on suppliers can sometimes encourage perfunctory compliance rather than substantive security improvement (Song et al., 2024).
The Swiss findings should therefore not be interpreted as evidence that organisations are failing to invest in cybersecurity. Instead, they point towards a more nuanced conclusion: security investment and perceived maturity do not necessarily translate into evenly distributed, demonstrable organisational capability. The maturity challenge lies increasingly in connecting individual controls with governance, supplier oversight, cloud security, compliance, human behaviour and operational resilience.
The central implication is that security maturity should be assessed not only by asking what controls an organisation has implemented, but also by asking whether those controls are integrated, tested, measurable and effective when the organisation is under stress. This provides a more meaningful basis for evaluating the maturity paradox identified by MSM Research and reinforces the broader argument of this paper: mature cybersecurity should ultimately be understood as the organisational capacity to protect critical assets, manage dependencies and maintain or restore essential operations when preventive controls are insufficient (MSM Research AG, 2026; Papachristofis et al., 2025).
4. From perimeter security to data-centric Zero Trust
The findings of the MSM Research study support a transition from traditional perimeter-oriented security towards a more data-centric and context-aware security model. Traditional perimeter security assumes that organisational boundaries provide a meaningful basis for establishing trust: systems and users inside the network are generally treated as more trustworthy than those outside it. The increasing use of cloud services, remote access, distributed applications and external providers has weakened this assumption. Zero Trust responds to this development by removing implicit trust and requiring access decisions to be continuously evaluated based on identity, context and risk.
Recent research reinforces this shift. Gambo and Almulhem's (2026) systematic literature review identifies Zero Trust Architecture (ZTA) as a response to the limitations of traditional perimeter-based models and highlights continuous authentication, conditional access, dynamic trust evaluation and least privilege as core characteristics of the approach. Their review further emphasises the use of granular access controls and continuous monitoring across complex and distributed environments. Alalmaie et al. (2024) similarly identify Zero Trust as increasingly relevant in environments in which organisations rely on cloud services and third-party providers, arguing that the model can reduce the risks associated with increasingly distributed security environments.
Zero Trust should nevertheless not be reduced to an identity and access-management strategy. Its central contribution is to change the basis on which access decisions are made: access should not be granted simply because a user, device or application is located within a trusted network. Instead, access should be evaluated according to the identity of the requesting entity, the security posture of the device, the requested resource, the surrounding context and the level of privilege required. Recent systematic research confirms that authentication, authorisation and access control remain the most consistently implemented components of Zero Trust, while areas such as continuous auditing, orchestration and environmental context remain less developed. This indicates that effective Zero Trust implementation requires integration across multiple security capabilities rather than the deployment of a single technology.
For data security, this distinction is particularly important. A genuinely data-centric security model begins with an understanding of what information the organisation holds, how sensitive that information is, where it is stored, who or what can access it, and how it may be used or transferred. Zero Trust then provides a framework for enforcing access decisions around this information. In this sense, Zero Trust and data-centric security are complementary: data classification establishes the security requirements associated with information, while Zero Trust mechanisms help enforce those requirements through contextual and least-privilege access decisions.
This interpretation is consistent with the priorities identified by MSM Research. Automated data classification is identified as a leading security priority, followed by data-loss prevention for cloud and collaboration environments and stricter data-residency controls (MSM Research AG, 2026). These priorities indicate a movement away from protecting systems primarily because they belong to the organisation towards protecting information according to its sensitivity, regulatory requirements and business value.
Data classification is therefore an important prerequisite for differentiated security controls. Without sufficient knowledge of the information being processed, organisations have limited ability to determine which data requires stronger authentication, encryption, monitoring, retention restrictions or loss-prevention controls. A sensitive customer record, an internal management document and publicly available marketing material should not necessarily be subject to identical security requirements. Classification can provide the basis for applying proportionate controls according to the potential consequences of unauthorised disclosure, modification or loss.
The strategic implication is that Zero Trust should increasingly be implemented around identity, context and information rather than network location. A legitimate employee accessing highly sensitive customer information from an unmanaged device should not automatically receive the same level of access as when using a compliant corporate device. Similarly, an external application requesting access to sensitive organisational data should receive only the permissions necessary for its defined function and should remain subject to appropriate monitoring and policy enforcement. Such decisions reflect the principle of least privilege while recognising that trust is contextual rather than a permanent property of a user or device (Gambo and Almulhem, 2026).
This approach also changes how organisations should think about cloud security. In multi-cloud and hybrid environments, infrastructure, applications and data are distributed across services that may be operated jointly by the organisation and external providers. Security therefore depends not only on preventing attacks but also on maintaining visibility into configurations, identities, data flows and access policies across a continuously changing environment. Recent Zero Trust research identifies cloud environments as one of the major application domains for ZTA while also highlighting challenges relating to scalability, orchestration and the integration of security controls across heterogeneous environments (Kumar et al., 2025).
The MSM findings on cloud security are therefore significant. The comparatively limited adoption of cloud-security posture management suggests that organisations may still struggle to translate Zero Trust principles into continuous operational visibility. The risk is not limited to an attacker exploiting a technical vulnerability. Organisations may also fail to identify excessive privileges, insecure configurations, inappropriate data exposure or deviations from established security policies as cloud environments evolve.
A mature data-centric Zero Trust model should consequently combine continuous identity verification, least-privilege access, device and environmental assessment, data classification, monitoring and policy enforcement. The objective is not to create another security perimeter, but to establish multiple, context-sensitive controls around critical information and business resources. This represents an important step in addressing the maturity paradox identified in the previous section: security maturity depends not merely on possessing access controls, but on the organisation's ability to apply those controls dynamically and consistently to the information and resources that matter most.
5. Cloud security and the problem of continuous configuration
Cloud adoption fundamentally changes the conditions under which security is managed. In traditional on-premises environments, organisations generally exercised direct control over physical infrastructure, network architecture and system configurations. Cloud environments redistribute these responsibilities across cloud service providers, customers, managed-service organisations and application teams. Security therefore becomes a shared and continuously changing responsibility, rather than a function that can be managed solely through controls within the organisation's own infrastructure (Ukeje, Gutierrez and Petrova, 2024; Ahmadi, 2024).
This redistribution of responsibility creates an important governance challenge. Cloud providers secure parts of the underlying infrastructure, while customers remain responsible for aspects such as identities, access permissions, applications, configurations and, depending on the service model, data protection. Where responsibilities are poorly understood or inadequately monitored, gaps can emerge between what an organisation assumes is protected and what is actually under its control. Research on cloud security repeatedly identifies this shared-responsibility problem as a significant source of security and privacy risk (Ukeje, Gutierrez and Petrova, 2024; Ahmadi, 2024).
Cloud security is consequently not a periodic compliance exercise but a continuous configuration and assurance problem. Cloud environments can change rapidly as resources are provisioned, applications are deployed, permissions are modified and services are integrated. Misconfigurations, excessive privileges, exposed interfaces and inconsistent security policies can therefore emerge even when an organisation's original cloud architecture was securely designed. A recent systematic literature review of security misconfigurations similarly identifies continuous monitoring and automated detection and remediation as important areas for improving configuration security (Moraes et al., 2024).
This dynamic character of cloud environments is particularly relevant to the MSM Research finding that cloud-security controls such as Cloud Security Posture Management (CSPM) remain comparatively under-adopted. If security policies are defined only at a point in time, organisations may have limited visibility into whether cloud resources continue to comply with those policies as the environment changes. The resulting risk is therefore not simply the existence of an isolated misconfiguration, but the possibility of configuration drift between the intended security state and the actual security state.
The maturity implications are significant. An organisation may have a formal cloud-security policy, documented responsibilities and contractual requirements for its cloud providers while lacking the operational capability to determine whether thousands of cloud resources comply with those requirements at any given moment. Cloud security maturity should therefore be assessed not only according to whether appropriate policies and controls exist, but also according to whether their implementation can be continuously observed, tested and corrected.
This reinforces the maturity paradox identified earlier. The transition to cloud can increase technological agility and scalability while simultaneously making security assurance more difficult. The systematic review by Ukeje, Gutierrez and Petrova (2024), for example, identifies information security and privacy as persistent challenges in cloud adoption and highlights the need for structured approaches to managing these risks. More recent research similarly emphasises that cloud environments introduce a complex and evolving security landscape requiring organisations to integrate security into broader digital-transformation processes rather than treating it as an isolated technical concern (2025).
The appropriate response is therefore not simply to acquire additional security technologies. Organisations require continuous visibility across assets, configurations, identities, applications and data flows, combined with mechanisms for identifying deviations from defined security requirements and initiating corrective action. CSPM can support this process by continuously assessing cloud configurations against security policies and recognised control requirements. However, the technology is most effective when integrated into organisational governance, risk management and operational processes rather than operated as a standalone security function.
This also changes the role of encryption and key-management strategies. Customer-controlled approaches such as Bring Your Own Key (BYOK) and Hold Your Own Key (HYOK) can strengthen organisational control over cryptographic keys and support requirements relating to data confidentiality, sovereignty and regulatory control. They should nevertheless be understood as one layer within a broader security architecture. Encryption protects data against particular forms of unauthorised disclosure, but it does not prevent a compromised identity from accessing legitimately decrypted data, eliminate excessive permissions, secure vulnerable applications or address malicious behaviour by authorised users.
Consequently, stronger control over encryption keys does not remove the need for effective identity and access management, least-privilege principles, monitoring and governance. This is consistent with the broader data-centric Zero Trust argument developed in the previous section: protecting sensitive information requires multiple complementary controls operating across identity, devices, applications, infrastructure and data.
The strategic implication is that cloud security maturity should increasingly be understood as the ability to maintain a secure and observable state while the underlying environment continuously changes. Mature organisations must therefore be able to identify what cloud resources they operate, understand who or what can access them, determine whether their configurations remain compliant with organisational requirements, detect deviations and remediate them before they develop into significant security exposures.
This represents an important shift from periodic security assessment to continuous security assurance. In the context of the Swiss findings, the relatively limited adoption of cloud-security posture management is therefore not merely a technology gap. It may indicate a broader organisational challenge: translating formal security requirements into continuously verifiable controls across increasingly distributed and dynamic digital infrastructures (MSM Research AG, 2026).
6. Third-party and supply-chain risk as the critical weakness
The most significant weakness identified by the MSM Research study concerns the systematic management of third-party and supply-chain risk. Only approximately 14 per cent of surveyed organisations report systematically managing this area, leading MSM Research to describe supply-chain risk as an “Achilles’ heel” of Swiss data security (MSM Research AG, 2026). This finding is particularly significant because digital organisations increasingly depend on external providers for cloud infrastructure, software, managed services, data processing and other critical capabilities. Security therefore extends beyond the boundaries of the organisation itself.
Recent research supports this assessment. Latsiou and Lambrinoudakis (2026) argue that increasing reliance on outsourcing, cloud services and interconnected digital providers has expanded the cyber supply-chain attack surface. Their systematic analysis of cyber supply-chain risk management highlights the difficulty organisations face in identifying, assessing and treating risks that originate within complex networks of external dependencies. The central challenge is not simply whether a supplier has appropriate security controls, but whether the organisation has sufficient visibility and control over the risks introduced through its dependency on that supplier.
The problem is therefore fundamentally structural. An organisation can maintain strong internal security controls while remaining vulnerable through an external provider with privileged access to systems, applications or sensitive information. A compromised software component, cloud platform, managed-service provider or technology vendor can introduce risk into the organisation without directly defeating its internal perimeter controls. The security of the organisation consequently becomes partly dependent on the security practices, architecture and resilience of entities over which it has limited direct control (Latsiou and Lambrinoudakis, 2026).
This creates an important distinction between organisational security and organisational resilience. Preventive controls can reduce the likelihood that a supplier-related incident will compromise organisational assets, but they cannot eliminate dependency risk. Organisations must therefore also consider how they will operate if a critical provider is compromised, becomes unavailable or can no longer be trusted.
Herburger, Wieland and Hochstrasser (2024) provide an important organisational perspective on this issue. Based on 79 in-depth interviews involving 28 firms across four Central European supply chains, they conceptualise cyber supply-chain resilience through the dynamic capabilities of sensing, seizing and transforming. Their findings indicate that resilience depends on organisations' ability to identify emerging cyber risks, develop appropriate responses and adapt structures and practices as the threat environment changes. Supply-chain resilience is therefore not simply a technical property of individual suppliers; it is also an organisational capability that must be developed across interconnected firms.
This perspective exposes a limitation of traditional supplier-assurance approaches. Questionnaires, contractual security clauses and periodic assessments can provide valuable evidence, but they represent snapshots of a supplier's security posture. They do not necessarily demonstrate how a supplier will behave during a rapidly developing cyber incident, whether critical dependencies can be replaced, or whether the organisation can continue operating when an external service becomes unavailable. Latsiou and Lambrinoudakis (2026) similarly identify limitations in existing cyber supply-chain risk-management practices and emphasise the need for more systematic approaches to identifying and treating risks across interconnected supply networks.
The objective should therefore shift from supplier compliance to dependency resilience. Organisations need to understand not only whether suppliers satisfy defined security requirements, but also which suppliers are operationally critical, what data and privileges they possess, which downstream dependencies they introduce and what consequences would arise if their services were compromised or interrupted.
This requires a more risk-based approach to supplier governance. Critical suppliers should be subject to stronger requirements for security assurance, access control, incident notification, resilience testing and recovery arrangements. Depending on the nature of the dependency, organisations may also require software bills of materials (SBOMs), software-dependency monitoring, vulnerability-management information, contractual rights to audit or verify controls, defined recovery objectives and tested incident-coordination procedures. The appropriate level of assurance should reflect the criticality and concentration of the dependency, rather than applying identical requirements to every supplier.
Supplier segmentation is therefore particularly important. A provider that processes highly sensitive information or operates a business-critical service represents a fundamentally different risk from a supplier providing a non-critical commodity service. Risk-based segmentation enables organisations to concentrate assurance and resilience investments where disruption would have the greatest consequences. This is consistent with the broader shift from control-based security towards organisational resilience: the question is not simply whether a supplier is secure, but whether the organisation can continue to function if that supplier's security or availability is compromised.
The same principle applies to software dependencies. Modern applications are often assembled from large numbers of third-party libraries, open-source components, APIs and externally maintained services. Vulnerabilities within these dependencies can therefore propagate across organisational boundaries. Software supply-chain security requires visibility into these dependencies and mechanisms for assessing their vulnerabilities and provenance. SBOMs and dependency-scanning mechanisms can support this visibility, but their effectiveness ultimately depends on whether organisations integrate the resulting information into vulnerability management, risk assessment and incident response.
A resilient supply-chain strategy should therefore combine supplier visibility, risk-based segmentation, continuous or event-driven monitoring, contractual security requirements, dependency transparency, incident-notification mechanisms and tested response and recovery arrangements. The objective is not to eliminate third-party dependencies—an increasingly unrealistic goal—but to understand and manage them according to their potential impact on critical organisational functions.
The fundamental question consequently changes from “Is this supplier compliant?” to “What happens to our organisation if this supplier is compromised or unavailable tomorrow?”
This question connects supply-chain security directly to business continuity and organisational resilience. It forces management to consider dependencies, alternatives, recovery capabilities and the potential consequences of supplier failure rather than relying solely on assurances that preventive controls are in place. In this sense, the low level of systematic supply-chain risk management identified by MSM Research represents more than a specific control gap. It indicates a potential weakness in the organisation's ability to remain resilient when critical functions depend on actors outside its direct control (MSM Research AG, 2026; Herburger, Wieland and Hochstrasser, 2024; Latsiou and Lambrinoudakis, 2026).
6. Third-party and supply-chain risk as the critical weakness
The most significant weakness identified by the MSM Research study concerns the systematic management of third-party and supply-chain risk. Only approximately 14 per cent of surveyed organisations report systematically managing this area, leading MSM Research to describe supply-chain risk as an “Achilles’ heel” of Swiss data security (MSM Research AG, 2026). This finding is particularly significant because digital organisations increasingly depend on external providers for cloud infrastructure, software, managed services, data processing and other critical capabilities. Security therefore extends beyond the boundaries of the organisation itself.
Recent research supports this assessment. Latsiou and Lambrinoudakis (2026) argue that increasing reliance on outsourcing, cloud services and interconnected digital providers has expanded the cyber supply-chain attack surface. Their systematic analysis of cyber supply-chain risk management highlights the difficulty organisations face in identifying, assessing and treating risks that originate within complex networks of external dependencies. The central challenge is not simply whether a supplier has appropriate security controls, but whether the organisation has sufficient visibility and control over the risks introduced through its dependency on that supplier.
The problem is therefore fundamentally structural. An organisation can maintain strong internal security controls while remaining vulnerable through an external provider with privileged access to systems, applications or sensitive information. A compromised software component, cloud platform, managed-service provider or technology vendor can introduce risk into the organisation without directly defeating its internal perimeter controls. The security of the organisation consequently becomes partly dependent on the security practices, architecture and resilience of entities over which it has limited direct control (Latsiou and Lambrinoudakis, 2026).
This creates an important distinction between organisational security and organisational resilience. Preventive controls can reduce the likelihood that a supplier-related incident will compromise organisational assets, but they cannot eliminate dependency risk. Organisations must therefore also consider how they will operate if a critical provider is compromised, becomes unavailable or can no longer be trusted.
Herburger, Wieland and Hochstrasser (2024) provide an important organisational perspective on this issue. Based on 79 in-depth interviews involving 28 firms across four Central European supply chains, they conceptualise cyber supply-chain resilience through the dynamic capabilities of sensing, seizing and transforming. Their findings indicate that resilience depends on organisations' ability to identify emerging cyber risks, develop appropriate responses and adapt structures and practices as the threat environment changes. Supply-chain resilience is therefore not simply a technical property of individual suppliers; it is also an organisational capability that must be developed across interconnected firms.
This perspective exposes a limitation of traditional supplier-assurance approaches. Questionnaires, contractual security clauses and periodic assessments can provide valuable evidence, but they represent snapshots of a supplier's security posture. They do not necessarily demonstrate how a supplier will behave during a rapidly developing cyber incident, whether critical dependencies can be replaced, or whether the organisation can continue operating when an external service becomes unavailable. Latsiou and Lambrinoudakis (2026) similarly identify limitations in existing cyber supply-chain risk-management practices and emphasise the need for more systematic approaches to identifying and treating risks across interconnected supply networks.
The objective should therefore shift from supplier compliance to dependency resilience. Organisations need to understand not only whether suppliers satisfy defined security requirements, but also which suppliers are operationally critical, what data and privileges they possess, which downstream dependencies they introduce and what consequences would arise if their services were compromised or interrupted.
This requires a more risk-based approach to supplier governance. Critical suppliers should be subject to stronger requirements for security assurance, access control, incident notification, resilience testing and recovery arrangements. Depending on the nature of the dependency, organisations may also require software bills of materials (SBOMs), software-dependency monitoring, vulnerability-management information, contractual rights to audit or verify controls, defined recovery objectives and tested incident-coordination procedures. The appropriate level of assurance should reflect the criticality and concentration of the dependency, rather than applying identical requirements to every supplier.
Supplier segmentation is therefore particularly important. A provider that processes highly sensitive information or operates a business-critical service represents a fundamentally different risk from a supplier providing a non-critical commodity service. Risk-based segmentation enables organisations to concentrate assurance and resilience investments where disruption would have the greatest consequences. This is consistent with the broader shift from control-based security towards organisational resilience: the question is not simply whether a supplier is secure, but whether the organisation can continue to function if that supplier's security or availability is compromised.
The same principle applies to software dependencies. Modern applications are often assembled from large numbers of third-party libraries, open-source components, APIs and externally maintained services. Vulnerabilities within these dependencies can therefore propagate across organisational boundaries. Software supply-chain security requires visibility into these dependencies and mechanisms for assessing their vulnerabilities and provenance. SBOMs and dependency-scanning mechanisms can support this visibility, but their effectiveness ultimately depends on whether organisations integrate the resulting information into vulnerability management, risk assessment and incident response.
A resilient supply-chain strategy should therefore combine supplier visibility, risk-based segmentation, continuous or event-driven monitoring, contractual security requirements, dependency transparency, incident-notification mechanisms and tested response and recovery arrangements. The objective is not to eliminate third-party dependencies—an increasingly unrealistic goal—but to understand and manage them according to their potential impact on critical organisational functions.
The fundamental question consequently changes from “Is this supplier compliant?” to “What happens to our organisation if this supplier is compromised or unavailable tomorrow?”
This question connects supply-chain security directly to business continuity and organisational resilience. It forces management to consider dependencies, alternatives, recovery capabilities and the potential consequences of supplier failure rather than relying solely on assurances that preventive controls are in place. In this sense, the low level of systematic supply-chain risk management identified by MSM Research represents more than a specific control gap. It indicates a potential weakness in the organisation's ability to remain resilient when critical functions depend on actors outside its direct control (MSM Research AG, 2026; Herburger, Wieland and Hochstrasser, 2024; Latsiou and Lambrinoudakis, 2026).
8. Shadow AI and the changing data-security perimeter
The rapid adoption of generative artificial intelligence introduces a further challenge to data-centric security. Unlike traditional enterprise software, many generative AI services can be accessed immediately through web interfaces or consumer applications without requiring installation, procurement or direct involvement from an organisation's IT function. Employees can therefore introduce new information-processing capabilities into the workplace faster than organisations can formally assess and govern them. This development has contributed to the emergence of “Shadow AI”, referring to the use of AI tools outside formally established organisational governance frameworks.
Silic, Silic and Kind-Trüller (2025) conceptualise Shadow AI as the unauthorised or insufficiently governed use of AI systems within organisations. Their empirical study, combining a survey of 140 professionals with interviews with executives, identifies risks including data privacy, governance gaps, algorithmic bias and the difficulty of maintaining effective oversight as AI adoption develops rapidly. Importantly, their analysis suggests that organisational AI governance can lag behind actual employee behaviour, creating a form of governance drift in which employees adopt AI capabilities before corresponding policies, controls and accountability structures have been established.
Puthal et al. (2025) similarly identify Shadow AI as an emerging cybersecurity concern. Their analysis highlights the potential for AI services to introduce new attack surfaces and create additional channels through which organisational information can be processed or transferred outside established security boundaries. The concern is therefore not limited to whether an AI application itself is malicious. Legitimate AI services can create security exposure when employees submit sensitive organisational information to systems that have not been approved, assessed or configured for that type of data.
The relevance to the Swiss findings is immediate. MSM Research identifies automated data classification and data-loss prevention (DLP) for cloud and collaboration environments among the leading data-security priorities (MSM Research AG, 2026). These capabilities become increasingly important in an environment in which employees can transfer organisational information to external AI services through ordinary, authorised devices and web connections. Traditional perimeter controls may provide limited protection because the activity can occur through legitimate internet access rather than through an obviously malicious connection.
This illustrates an important limitation of perimeter-based security. From a network perspective, an employee accessing a public AI service may appear to be engaging in legitimate web activity. From a data-security perspective, however, the same activity may represent a significant disclosure event if sensitive customer information, confidential documents, source code or personal data are submitted to an external AI service. The relevant security question therefore shifts from “Is the connection authorised?” to “Is this user authorised to transfer this information to this service for this purpose?”
This distinction reinforces the data-centric Zero Trust approach developed earlier. Identity and device controls remain important, but they are insufficient when the principal risk concerns how authorised users handle information. Organisations increasingly need to combine identity, data classification, DLP, application controls and contextual policies to determine whether particular information can be transferred to particular AI services. The objective is not necessarily to prevent AI use, but to ensure that the use of AI is consistent with the sensitivity, regulatory requirements and business value of the information being processed.
The organisational challenge is therefore not simply one of technical restriction. Generative AI can create legitimate productivity benefits, including assistance with research, coding, document analysis and knowledge work. A blanket prohibition may consequently encourage employees to circumvent formal systems rather than eliminate AI use. Radanliev, Santos and Ani (2025) argue that the cybersecurity implications of generative AI need to be considered together with organisational resilience and responsible deployment. Their analysis supports the broader view that organisations need to develop governance capabilities that allow them to capture the benefits of AI while managing its emerging risks.
The appropriate response is therefore likely to involve governance combined with proportionate technical controls, rather than prohibition alone. Organisations should establish clear policies governing acceptable AI use, classify information according to sensitivity, define approved AI services and use cases, provide employees with practical guidance and training, and apply technical controls where the risk justifies them. Depending on the organisational context, these controls may include DLP policies, restrictions on transferring sensitive information, application-level access controls, logging and monitoring, and defined processes for assessing and approving new AI services.
Governance should also address the underlying reasons why employees adopt unsanctioned AI tools. If employees use Shadow AI because approved tools are unavailable, inefficient or incapable of meeting legitimate business requirements, simply prohibiting those tools may have limited effect. The organisation should therefore treat Shadow AI as a potential signal of unmet business needs as well as a security risk. Understanding which tools employees are using, why they are using them and what information they are processing can provide valuable information for improving both security governance and technology strategy.
This makes Shadow AI particularly useful as a test of organisational maturity. A control-oriented organisation may primarily ask whether employees are complying with an AI policy. A resilient organisation asks a broader set of questions: What AI services are actually being used? What information is being processed? Why are employees using them? Which uses create unacceptable risk? Which legitimate uses should be enabled? And can the organisation detect and respond when sensitive information is transferred inappropriately?
The maturity challenge therefore lies in closing the gap between formal AI governance and actual AI behaviour. Shadow AI demonstrates how rapidly changing technologies can create governance gaps even when organisations have established conventional security controls. Effective data security consequently requires organisations to continuously reassess not only their technical infrastructure but also the ways in which employees interact with emerging technologies and information.
In this sense, Shadow AI extends the central argument of this paper. The security perimeter is no longer defined solely by networks and systems; it is increasingly defined by where organisational data can travel, which services can process it and under what conditions. Organisations that can govern these data flows while enabling legitimate technological innovation demonstrate a more mature form of cyber resilience than organisations that rely primarily on prohibition or perimeter-based controls (Silic, Silic and Kind-Trüller, 2025; Puthal et al., 2025; Radanliev, Santos and Ani, 2025).
9. Governance: making cybersecurity a management responsibility
The Swiss findings suggest that one of the central challenges of data security is ultimately a question of governance and organisational accountability. Approximately half of the organisations surveyed by MSM Research report having clearly defined governance roles involving functions such as the Chief Information Security Officer (CISO), Data Protection Officer (DPO) or data owners (MSM Research AG, 2026). The existence of these roles represents an important foundation. However, formal role definitions alone do not establish effective governance. Security responsibilities must be accompanied by appropriate decision-making authority, resources, escalation mechanisms and accountability.
This distinction is particularly important because contemporary cyber risk increasingly crosses traditional organisational boundaries. Decisions concerning the security of critical data may involve information security, data protection, information technology, procurement, legal affairs, business operations and external suppliers simultaneously. These functions therefore cannot manage cyber risk effectively as isolated organisational silos. Effective governance requires mechanisms through which these perspectives can be coordinated and translated into decisions about risk acceptance, security investment, supplier relationships, data processing and operational resilience.
Recent research on organisational cyber resilience reinforces this broader understanding of cybersecurity. Neri, Niccolini and Virili (2026) argue that cyber resilience should be understood within the wider organisational context rather than as a purely technical capability. This perspective places governance, organisational processes and adaptation alongside technological controls. Cybersecurity consequently becomes a management responsibility because decisions about security ultimately concern how the organisation allocates resources, accepts risk and protects the continuity of critical activities.
Management must therefore understand the organisation's critical dependencies. This requires visibility into which business activities depend on which information assets, applications, cloud services, suppliers and technological infrastructures. Without this understanding, security decisions may be made at the level of individual systems without recognising the potential consequences for critical business processes. Conversely, understanding these dependencies allows management to prioritise protection and resilience measures according to business impact rather than treating all systems and information as equally important.
The Swiss Federal Act on Data Protection (FADP) illustrates the relationship between governance and operational security. The legislation requires controllers and processors to implement appropriate technical and organisational measures based on the risks involved and establishes responsibilities for controllers concerning the security capabilities of processors (FADP, 2020). Data-protection governance is therefore not separate from cybersecurity governance. Decisions about how personal data is collected, processed, transferred and protected necessarily involve both legal and technical considerations.
This interdependence becomes particularly important when organisations rely on external providers. A decision to transfer personal or sensitive information to a cloud service, managed-service provider or other processor is simultaneously a business, procurement, data-protection and cybersecurity decision. Governance arrangements must therefore provide a mechanism for integrating these perspectives rather than allowing responsibility to become fragmented between departments.
Effective governance also requires clearly defined decision rights during cyber incidents. Organisations should establish in advance who has authority to isolate systems, suspend accounts, disable integrations, invoke business-continuity procedures, approve emergency security measures and escalate incidents to senior management. They should also determine who is responsible for assessing regulatory notification requirements, coordinating with external providers, communicating with affected stakeholders and documenting major decisions.
These arrangements are particularly important because the time available for decision-making during a major cyber incident may be limited. Waiting for responsibilities to be negotiated during an incident can delay containment and increase operational and regulatory consequences. Incident-response plans should therefore define not only technical procedures but also escalation paths, decision authority and communication responsibilities.
Incident response should consequently be understood as an organisational governance process rather than solely as a Security Operations Centre (SOC) function. Security teams may detect and technically contain an incident, but management may need to decide whether critical services should be taken offline, whether alternative suppliers should be activated, whether customers or regulators must be notified, and how business operations should be prioritised. These decisions require information from multiple functions and cannot be delegated entirely to technical specialists.
The same principle applies to cyber-risk acceptance. Technical teams can identify vulnerabilities and estimate potential impacts, but decisions about whether a particular risk is acceptable ultimately depend on the organisation's business objectives, legal obligations and risk appetite. Governance should therefore establish explicit mechanisms for escalating risks that exceed defined tolerances and for ensuring that risk acceptance is documented at an appropriate management level.
This suggests that cybersecurity governance should be evaluated not only by asking “Who is responsible for security?”, but also by asking “Who has the authority to make decisions when security, business continuity, legal obligations and commercial interests conflict?” The latter question provides a more meaningful test of organisational maturity because it examines whether governance structures function under conditions of uncertainty and operational pressure.
The maturity challenge identified by MSM Research can therefore be viewed partly as a governance challenge. Organisations may have formally assigned CISO, DPO or data-owner responsibilities while still lacking sufficiently integrated decision-making across data, technology, suppliers and business operations. The next stage of maturity is consequently not simply to create additional governance roles, but to ensure that existing roles are connected through clear accountability, risk ownership, escalation mechanisms and management oversight (MSM Research AG, 2026; Neri, Niccolini and Virili, 2026).
Ultimately, cybersecurity becomes a management responsibility when cyber risk is incorporated into the same decision-making processes used to manage financial, operational, legal and strategic risks. In a highly interconnected digital environment, protecting information and maintaining operational resilience cannot be delegated entirely to IT or security specialists. It requires management to understand critical dependencies, define acceptable risk, allocate resources accordingly and ensure that the organisation can make coordinated decisions when preventive controls fail.
10. From prevention to assume-breach resilience
The cumulative evidence suggests that Swiss organisations should increasingly complement preventive cybersecurity with an assume-breach approach to organisational resilience. Assume-breach does not imply accepting inadequate security or abandoning preventive controls. Rather, it recognises that no security architecture can guarantee the prevention of every successful intrusion, credential compromise, supply-chain failure or disruptive cyber incident. The strategic objective therefore becomes twofold: reduce the probability and impact of successful attacks while ensuring that the organisation can continue operating when preventive controls fail.
This perspective is consistent with the development of cyber resilience as a distinct field of research. AlHidaifi, Asghar and Ansari (2024) conceptualise cyber resilience around an organisation's ability to prepare for, withstand, recover from and adapt to cyber attacks and disruptions. Tzavara and Vassiliadis (2024) similarly demonstrate that cyber resilience emerged partly in response to the limitations of prevention-oriented cybersecurity models. Resilience therefore does not replace cybersecurity; it extends it by addressing the consequences of incidents that cannot be completely prevented.
The assume-breach philosophy has important implications for how organisations design security controls. Rather than assuming that identities, systems or suppliers will remain trustworthy, organisations should design for the possibility that individual security boundaries may be compromised. This reinforces the logic of Zero Trust: access should remain constrained even when credentials are compromised, privileges should be limited according to business need, and security decisions should be continuously evaluated rather than based on permanent assumptions of trust (Gambo and Almulhem, 2026).
The same principle applies to organisational dependencies. Organisations should consider the possibility that a critical cloud provider may become unavailable, that a key supplier may be compromised, that a software dependency may contain a critical vulnerability or that sensitive information may be exposed through an emerging technology such as generative AI. Resilience therefore requires organisations to identify their most consequential dependencies before an incident occurs and determine how critical functions can be maintained if those dependencies fail.
Recovery capabilities are consequently central to cyber resilience. Organisations should maintain tested mechanisms for restoring critical systems and data, protecting backup environments from compromise and prioritising recovery according to business impact. Depending on the threat environment and business requirements, this may include appropriately segregated or immutable backups, privileged-access controls, recovery environments, defined recovery objectives and documented restoration procedures. The objective is not simply to possess backups, but to demonstrate that critical services and information can actually be restored within acceptable operational and regulatory parameters.
Testing is essential because documented recovery capabilities do not necessarily translate into operational resilience. An organisation may have a comprehensive incident-response plan while discovering during a real incident that contact information is outdated, decision authority is unclear, dependencies are poorly understood or recovery procedures do not work as expected. Regular testing therefore provides a mechanism for converting formal plans into demonstrated capability.
Importantly, resilience testing should extend beyond technical IT recovery. A major cyber incident can simultaneously affect operations, finance, legal affairs, communications, procurement, data protection and executive decision-making. Technical penetration tests may reveal vulnerabilities in systems, but they do not necessarily reveal whether management can make timely decisions when business continuity, regulatory obligations and commercial pressures conflict. Tabletop exercises, crisis simulations and appropriately scoped red-team exercises can therefore complement technical security testing by examining the organisation's ability to coordinate under realistic conditions.
Such exercises should test more than the technical sequence of detection and containment. They should examine whether the organisation can identify critical business functions, establish decision authority, communicate with relevant stakeholders, escalate supplier incidents, assess regulatory obligations and prioritise recovery when not all systems can be restored simultaneously. In this sense, resilience testing becomes a test of organisational coordination rather than simply a test of technological controls.
The assume-breach perspective also changes how security investment should be evaluated. The objective is not to maximise the number of preventive controls but to reduce the potential consequences of failure across multiple layers. An organisation may therefore obtain greater resilience from combining strong identity controls, segmentation, monitoring, supplier visibility, tested backups and crisis-management capabilities than from adding another isolated preventive technology.
This provides a direct connection to the maturity paradox identified earlier. A mature organisation should be able to demonstrate not only that preventive controls exist, but also that it can operate when those controls are bypassed or unavailable. This requires evidence from exercises, recovery tests, incident simulations, supplier assessments and other forms of operational assurance. Security maturity consequently becomes a question of demonstrated resilience rather than declared preparedness.
The concept of assume-breach resilience therefore represents the synthesis of the preceding arguments. Data-centric Zero Trust limits the consequences of compromised identities and reduces excessive access. Cloud-security governance provides continuous visibility into changing configurations and dependencies. Supply-chain resilience addresses risks arising beyond the organisation's direct control. AI governance addresses new data flows and emerging forms of technology adoption. Together, these capabilities create multiple layers of resilience around critical organisational assets and functions.
The ultimate objective is not to create an organisation that can guarantee the prevention of every cyber incident. Such an objective is neither technically realistic nor consistent with the evolving nature of digital risk. The objective is to create an organisation that can anticipate significant risks, withstand disruption, maintain critical functions, recover within acceptable parameters and adapt its security practices after an incident (AlHidaifi, Asghar and Ansari, 2024; Tzavara and Vassiliadis, 2024; Neri, Niccolini and Virili, 2026).
Cyber resilience therefore becomes meaningful only when it can be demonstrated under conditions of uncertainty and degradation. The decisive question is no longer simply “Can we prevent the attack?”, but also “If prevention fails, can we continue to operate, recover effectively and learn from the disruption?” This represents the fundamental shift from preventive cybersecurity towards organisational resilience.
11. Towards a new model of security maturity
The MSM findings suggest that conventional approaches to assessing security maturity require reconsideration. Assessments based primarily on the number of implemented controls, the existence of formal policies or organisations' own perceptions of maturity can create a misleading picture of security capability. The gap between the high levels of perceived maturity reported by Swiss organisations and the comparatively limited implementation of systematic compliance, third-party risk management and cloud-security practices illustrates this problem. Maturity should therefore be assessed not simply by the presence of security measures, but by the organisation's ability to demonstrate that those measures function as an integrated capability under changing and adverse conditions.
A more meaningful model of security maturity can be structured around five interconnected dimensions: visibility, governance, prevention and protection, detection and response, and recovery and adaptation. These dimensions should not be understood as independent maturity categories. Rather, they represent complementary capabilities that collectively determine whether an organisation can manage cyber risk across the full lifecycle of an incident.
First, visibility provides the foundation for effective security management. Organisations need to know what data they hold, where critical systems and applications are located, which identities have access to them, how cloud environments are configured, and which suppliers and software dependencies support important business processes. Without sufficient visibility, organisations cannot reliably determine what needs to be protected, which dependencies are critical or where vulnerabilities and excessive access may exist. This is particularly important in distributed cloud and supply-chain environments, where the traditional organisational perimeter provides increasingly limited visibility.
Second, governance establishes ownership and accountability for security decisions. This includes clearly defined responsibilities, decision rights, escalation mechanisms, regulatory processes and coordination across security, IT, privacy, procurement, legal and business functions. Governance is what converts security information into organisational decisions. Without it, even accurate technical information may fail to produce timely action, particularly when security requirements conflict with operational, financial or commercial priorities. Organisational cyber resilience therefore depends not only on technical capabilities but also on structures that enable coordinated decision-making and adaptation (Neri, Niccolini and Virili, 2026).
Third, prevention and protection encompass the controls that reduce the probability and potential impact of security incidents. These include identity and access management, least-privilege controls, encryption, segmentation, data-loss prevention, secure development practices and security awareness. The purpose of this dimension is not to reproduce an exhaustive catalogue of controls, but to assess whether preventive measures are appropriately aligned with the organisation's critical assets, data and dependencies. In a data-centric security model, protection should increasingly be determined by the sensitivity and business importance of information rather than solely by the network location of the systems processing it.
Fourth, detection and response determine whether an organisation can recognise and contain a security incident once preventive controls are bypassed or fail. This requires appropriate monitoring, anomaly detection, incident-response capabilities, escalation procedures and coordination across relevant functions. The emphasis should be on operational effectiveness rather than the mere existence of a security operations function or incident-response plan. An organisation with sophisticated monitoring but unclear decision authority may detect an incident without being able to contain it effectively. Detection and response therefore represent the point at which technical security capabilities must connect directly with organisational governance.
Fifth, recovery and adaptation determine whether the organisation can sustain critical operations during disruption, restore affected capabilities and improve its security posture afterwards. This includes tested backups, recovery procedures, business continuity arrangements, crisis management and mechanisms for incorporating lessons from incidents and exercises. Cyber resilience research emphasises that effective resilience extends beyond absorbing an incident to recovering and adapting afterwards (AlHidaifi, Asghar and Ansari, 2024). From an organisational perspective, this means that recovery should be treated as an ongoing capability rather than an emergency activity that begins only after an incident has occurred (Neri, Niccolini and Virili, 2026).
The five dimensions are consequently interdependent. Visibility without governance produces information without accountability. Governance without visibility limits the quality of decision-making. Prevention without detection and response leaves organisations vulnerable when controls are bypassed. Detection without recovery may contain an incident without restoring critical operations. Recovery without adaptation risks repeating the same weaknesses. Security maturity should therefore be evaluated across the connections between these capabilities, rather than through isolated control inventories.
This perspective also changes the role of maturity levels. Instead of asking whether an organisation is "basic", "managed" or "advanced", an assessment should examine whether critical capabilities are defined, implemented, continuously monitored, tested and demonstrably effective. Importantly, maturity should also be evaluated in relation to organisational context. The security requirements of a highly interconnected organisation handling sensitive data and relying heavily on external providers cannot be meaningfully assessed using the same assumptions as those of a smaller organisation with a substantially different risk profile. Maturity assessment therefore needs to incorporate factors such as business criticality, exposure, dependencies and organisational complexity rather than relying exclusively on generic control thresholds.
The MSM findings provide a useful empirical illustration of why this distinction matters. High perceived maturity can coexist with substantial gaps in specific capabilities. An organisation may have extensive awareness programmes and formal security processes while lacking systematic supplier-risk management or continuous cloud-security assurance. Conversely, a smaller organisation may operate with fewer formal controls while maintaining strong visibility, clear accountability and effective recovery capabilities. The relevant question is therefore not how many security practices exist, but whether the organisation can demonstrate that its most important risks are understood, controlled, monitored and recoverable.
This leads to a different definition of security maturity: maturity is the demonstrated organisational capability to protect critical information and services, detect and contain disruption, maintain essential operations, recover effectively and adapt as risks change. Such a definition incorporates both preventive cybersecurity and cyber resilience. It also provides a more direct connection between security investment and organisational outcomes because it evaluates whether security capabilities actually support the continuity and resilience of critical business functions.
The resulting model can therefore be summarised as:
Visibility → Governance → Prevention and Protection → Detection and Response → Recovery and Adaptation
The sequence should not be interpreted as a purely linear process. These capabilities form a continuous cycle in which incidents, exercises, technological change and changes in the threat environment generate new information that feeds back into visibility, governance and preventive measures. Maturity is consequently not a static state that an organisation reaches once; it is the demonstrated capacity to maintain and improve these interconnected capabilities over time.
This represents a shift from control-based maturity to capability-based maturity. The central question is no longer simply “How many controls have we implemented?” but rather “Can we demonstrate that our organisation can protect what matters, detect and contain disruption, continue critical operations when controls fail, recover effectively and learn from the experience?” In this sense, security maturity becomes inseparable from organisational resilience.
12. Discussion
The Swiss evidence points to a security-maturity paradox that is unlikely to be unique to Switzerland. Organisations are increasing cybersecurity investment, strengthening awareness and formalising security processes, while the environments they are expected to protect are simultaneously becoming more distributed, interconnected and dependent on external technologies and providers. The resulting challenge is therefore not simply to increase security investment, but to ensure that investment translates into demonstrable organisational resilience.
This distinction is important because additional security expenditure does not necessarily produce greater security capability. Organisations can accumulate security technologies, policies and compliance activities without developing the governance structures and operational integration required to use them effectively. In complex environments, adding further tools without clarifying ownership, improving visibility or integrating security processes can itself increase operational complexity. The relevant measure of investment should therefore be its contribution to the organisation's ability to understand risk, prevent and contain incidents, maintain critical operations and recover when preventive controls fail.
The MSM findings identify four areas in which this resilience capacity appears particularly constrained: regulatory integration, third-party and supply-chain risk management, cloud security and Shadow AI. These should not, however, be interpreted as four independent weaknesses. They reflect different manifestations of the same underlying challenge: organisations are attempting to secure increasingly distributed data, technologies and dependencies with governance models that may still be structured around more clearly defined organisational and technological boundaries.
Regulatory integration illustrates this problem particularly clearly. Compliance requirements become difficult to operationalise when organisations cannot reliably identify where data is stored, processed or transferred, which suppliers have access to it, or who is accountable for relevant decisions. Regulatory compliance therefore depends partly on the same visibility and governance capabilities required for effective cybersecurity. Formal policies or compliance documentation cannot compensate for an inability to identify critical data flows, dependencies and responsibilities.
The same interdependence is visible in cloud security. Cloud environments increase flexibility and scalability but distribute responsibility across cloud providers, customers, managed-service providers and internal teams. Weak visibility into configurations, identities and data flows makes it difficult to determine whether security policies are being implemented consistently. This connects cloud security directly to governance and data-centric security rather than treating it as a purely technical infrastructure problem (Ahmadi, 2024; Ukeje, Gutierrez and Petrova, 2024).
Third-party and software supply-chain risk extends this problem beyond the organisation's direct control. Organisations may maintain strong internal security while remaining exposed through suppliers, cloud providers, managed services or software dependencies. Research emphasises that supply-chain resilience requires organisational capabilities for sensing, responding and transforming rather than relying solely on contractual assurances or static assessments (Herburger, Wieland and Hochstrasser, 2024; Latsiou and Lambrinoudakis, 2026). The critical issue is therefore not simply whether a supplier satisfies a predefined security requirement, but whether the organisation understands the dependency and can continue critical operations if that dependency is compromised or unavailable.
Shadow AI represents a further extension of the same boundary problem. Employees can introduce external AI services into organisational workflows without those services necessarily being incorporated into established security, privacy or procurement processes. As Silic, Silic and Kind-Trüller (2025) demonstrate, organisational use of AI can develop faster than formal governance structures, creating gaps between actual employee practices and approved technology frameworks. Puthal et al. (2025) similarly identify Shadow AI as an emerging cybersecurity challenge because it can introduce new data flows and attack surfaces. The issue is therefore not AI alone, but the difficulty of governing technologies that allow data and processing activities to move faster than formal organisational controls.
These four areas converge on the importance of data visibility and governance. Effective DLP and AI governance depend on knowing which information is sensitive and under what circumstances it may be processed or transferred. Effective supplier-risk management depends on knowing which third parties have access to critical systems and information. Effective cloud governance depends on understanding where data and identities are located and how configurations change. Regulatory compliance depends on the organisation's ability to demonstrate that these activities are appropriately governed. Weakness in one capability can therefore amplify weaknesses elsewhere.
This interdependence also explains why the four priorities identified by MSM Research—regulation and governance, AI governance, software supply-chain security and cyber resilience—should not be treated as separate workstreams. They represent complementary responses to the same structural transformation in organisational risk. Governance establishes accountability and decision rights; data-centric Zero Trust limits access and reduces the consequences of compromised identities; supply-chain security addresses dependencies beyond the organisation's direct control; and cyber resilience ensures that critical functions can continue when preventive measures fail.
The academic literature supports this integrated interpretation. Zero Trust research emphasises continuous verification, least privilege and context-sensitive access as alternatives to implicit trust based on network location (Gambo and Almulhem, 2026). Supply-chain research highlights the need for organisational capabilities and governance to manage dependencies and cyber disruption (Herburger, Wieland and Hochstrasser, 2024; Latsiou and Lambrinoudakis, 2026). Research on Shadow AI demonstrates that technological adoption can outpace formal governance and create new security and data-protection risks (Silic, Silic and Kind-Trüller, 2025; Puthal et al., 2025). Cyber-resilience research, meanwhile, shifts attention from preventing every incident towards preparing organisations to withstand, recover from and adapt to incidents that cannot be completely prevented (AlHidaifi, Asghar and Ansari, 2024; Neri, Niccolini and Virili, 2026).
The implication is that cybersecurity maturity should increasingly be understood as a systems capability rather than a collection of individual controls. A mature organisation does not necessarily have the greatest number of security technologies or the most extensive set of formal policies. Rather, it can demonstrate that its security, governance, technology and business-continuity capabilities reinforce one another. It knows what matters, who is responsible, where dependencies exist, how access is controlled, how incidents will be detected and contained, and how critical operations will continue if preventive controls fail.
This interpretation also qualifies the meaning of cybersecurity investment. Investment remains essential, particularly as threat exposure and technological complexity increase. However, the marginal value of additional tools is likely to depend increasingly on whether organisations can integrate those tools into coherent operating models. The strategic challenge is therefore to move from security accumulation to security integration: from acquiring more controls to developing capabilities that operate across organisational boundaries and remain effective under conditions of disruption.
The Swiss case consequently illustrates a broader transformation in cybersecurity. As organisations adopt cloud services, rely on interconnected suppliers, integrate AI into business processes and distribute data across increasingly complex ecosystems, the traditional concept of a clearly defined security perimeter becomes progressively less useful. The organisation itself increasingly has no single perimeter. Its effective security boundary is instead defined by identities, data flows, technological dependencies, suppliers and business processes.
The resulting strategic imperative is not to recreate the old perimeter around a more complex environment, but to develop security capabilities that function despite the absence of a single perimeter. This requires visibility, governance, data-centric protection, continuous detection and response, supply-chain assurance and tested recovery capabilities to operate as an integrated system. The transition identified in the Swiss evidence is therefore not simply from weaker to stronger cybersecurity, but from perimeter-based security towards demonstrable organisational resilience.
13. Conclusion
The analysis of Swiss organisations presented in this paper reveals a fundamental tension in contemporary cybersecurity. Organisations are investing more in security, strengthening awareness and formalising security processes, yet the environments they must protect are becoming increasingly distributed, interconnected and dependent on technologies and providers beyond their direct control. The resulting challenge is not simply a lack of security investment. It is a question of whether existing investments translate into demonstrable organisational capability.
The MSM Research findings illustrate this tension particularly clearly. The relatively high levels of perceived security maturity and substantial cybersecurity investment coexist with significant gaps in regulatory integration, third-party risk management and cloud-security assurance, while the emergence of Shadow AI introduces additional challenges for data governance and organisational control. These findings suggest that maturity cannot be inferred from the existence of policies, awareness programmes or individual technical controls. An organisation may appear mature when assessed through the presence of controls while remaining vulnerable when those controls are tested by disruption, dependency failure or rapidly changing technology.
This paper therefore argues for a shift from control-based to capability-based security maturity. A mature organisation should be able to demonstrate visibility of its critical data, systems, identities and dependencies; clear governance and accountability; effective preventive and protective controls; reliable detection and response; and tested recovery and adaptation capabilities. These dimensions are interdependent. Visibility enables governance, governance directs protection, protection must be complemented by detection and response, and recovery ensures that the organisation can continue operating when prevention fails. Maturity is consequently not a static level that can be reached through the accumulation of controls, but an organisational capability that must be maintained and demonstrated over time.
The analysis further shows that the major security challenges identified in the Swiss evidence are interconnected. Cloud security, third-party risk, software supply chains, regulatory compliance and Shadow AI all challenge the assumption that security can be achieved by protecting a clearly defined organisational perimeter. Data increasingly moves across cloud platforms, suppliers, applications and AI services, while critical business processes depend on technologies and organisations outside the traditional IT boundary. The appropriate response is therefore not to reconstruct the perimeter around an increasingly complex ecosystem, but to develop security mechanisms that remain effective when the perimeter itself is fluid.
Four capabilities are particularly important in this transition. Data-centric Zero Trust reduces the consequences of compromised identities and excessive access by continuously evaluating who or what should have access to which resources and under what conditions. Cloud and supply-chain governance provide visibility and control over dependencies that organisations cannot secure through internal controls alone. AI governance ensures that emerging technologies do not create uncontrolled data flows or bypass established security and privacy requirements. Cyber resilience provides the final layer by ensuring that critical operations can continue and recover when preventive measures are bypassed or fail.
This leads to a broader interpretation of the assume-breach principle. The objective is not to accept successful attacks as inevitable, nor to reduce investment in prevention. Rather, organisations should recognise that prevention alone cannot provide complete assurance. Credentials may be compromised, suppliers may become unavailable, software dependencies may be exploited and new technologies may introduce risks that existing controls were not designed to address. Mature organisations therefore need to combine prevention with the capacity to detect, contain, withstand, recover from and learn from disruption.
The practical implication is that cybersecurity investment should increasingly be evaluated according to the resilience capacity it creates, rather than the number of technologies or controls it adds. Security leaders and senior management should ask not only whether appropriate controls exist, but whether critical dependencies are understood, decision rights are clear, suppliers can be assessed, cloud configurations are continuously governed, sensitive data can be controlled across its lifecycle, and critical operations can be restored under realistic conditions. Exercises, recovery testing, supplier assessments and incident simulations are therefore not supplementary activities; they are mechanisms for demonstrating whether security maturity exists in practice.
For Swiss organisations, this represents a shift from perceived security maturity towards demonstrable cyber resilience. The objective is not to create an organisation that can guarantee prevention of every cyber incident. Rather, it is to create an organisation that understands what matters, knows where its dependencies lie, limits the consequences of compromise, responds effectively to disruption, maintains critical functions and continuously improves its ability to withstand future threats.
The Swiss case thus reflects a broader transformation in the meaning of cybersecurity maturity. As organisations increasingly operate across cloud environments, supplier ecosystems, software dependencies and AI-enabled services, they can no longer rely on a single security perimeter or on preventive controls as the primary measure of maturity. The defining characteristic of a mature organisation is instead its ability to remain secure, operational and adaptable when the environment changes and when individual controls fail. In this sense, the future of cybersecurity maturity is not measured by how much security an organisation has implemented, but by how convincingly it can demonstrate that it can continue to function when security is put to the test.
References
Alalmaie, A., Waheed, N., Alalyan, M., Nanda, P., Jia, W. and He, X. (2024) ‘Zero Trust for Intrusion Detection System: A Systematic Literature Review’, Proceedings of the 16th International Conference on Agents and Artificial Intelligence, pp. 170–177.
Alhidaifi, S.M., Asghar, M.R. and Ansari, I.S. (2024) ‘A survey on cyber resilience: key strategies, research challenges, and future directions’, ACM Computing Surveys, 56(8), pp. 1–48.
FADP (2020) Federal Act of 25 September 2020 on Data Protection (Data Protection Act). Swiss Confederation, Fedlex.
Gambo, M.L. and Almulhem, A. (2026) ‘Zero Trust Architecture: A Systematic Literature Review’, Journal of Network and Systems Management, 34, article 25.
Herburger, M., Wieland, A. and Hochstrasser, C. (2024) ‘Building supply chain resilience to cyber risks: a dynamic capabilities perspective’, Supply Chain Management: An International Journal, 29(7), pp. 28–50.
Latsiou, A. and Lambrinoudakis, C. (2026) ‘Cyber Supply Chain Risk Management: From Threats to Treatment’, International Journal of Information Security, 25, article 40.
MSM Research AG (2026) Data Security in Switzerland: Between Aspiration and Reality. September 2026, powered by Swisscom. The study surveyed 84 Swiss companies.
Neri, M., Niccolini, F. and Virili, F. (2024) ‘Organizational cyber resilience: toward an integrative conceptual framework’. Neri et al. as 2026, with Management Review Quarterly, 76(1), 789–840
Puthal, D., Mishra, A.K., Mohanty, S.P., Longo, A. et al. (2025) ‘Shadow AI: Cyber Security Implications, Opportunities and Challenges in the Unseen Frontier’, SN Computer Science, 6, article 405.
Radanliev, P., Santos, O. and Ani, U.D. (2025) ‘Generative AI cybersecurity and resilience’, Frontiers in Artificial Intelligence, 8, 1568360.
Silic, M. and Kind-Trüller, K. (2025) ‘From Shadow IT to Shadow AI – Threats, Risks and Opportunities for Organizations’, Strategic Change, pp. 1–16.
Tzavara, V. and Vassiliadis, S. (2024) ‘Tracing the evolution of cyber resilience: a historical and conceptual review’, International Journal of Information Security, 23, pp. 1695–1719.
Contact
Reach out via email for inquiries.
Subscribe to newsletter
info@grcadvisory.ch
© 2025. All rights reserved.