From Data Security to Cyber Resilience
Modern data security is evolving from protecting organisational networks to building resilient, data-centric organisations that can govern cloud ecosystems, supply chains and AI-driven risks.
Sanchez P.
9/14/202660 min read


Abstract
The rapid adoption of cloud computing, distributed digital services, interconnected supply chains and artificial intelligence is challenging conventional approaches to organisational data security. This paper examines these developments through a critical analysis of Data Security in Switzerland: Between Aspiration and Reality: Effective Protection Starts with a Data-Centric Security Strategy, an MSM Research study of 84 Swiss companies, complemented by recent peer-reviewed literature on data-centric security, cyber supply-chain risk, organisational cyber resilience and artificial intelligence governance. The analysis identifies three interconnected transformations in contemporary security practice. First, security is shifting from a network-perimeter model towards a data-centric approach in which visibility, classification, location and control of information become foundational governance capabilities. Second, the effective security boundary is expanding beyond the organisation to encompass cloud providers, SaaS platforms, software dependencies and other ecosystem relationships. Third, the limitations of preventive security and self-assessed maturity increase the importance of cyber resilience: the organisational capacity to prepare for, withstand, recover from and adapt to disruption. Shadow AI illustrates the convergence of these developments by demonstrating how employees can transfer organisational information into external AI systems faster than formal governance mechanisms can adapt.
The analysis further identifies a socio-technical dimension to data security. Technical controls depend on employee behaviour, organisational processes, governance arrangements and external dependencies, meaning that security weaknesses can propagate across organisational boundaries. The MSM findings nevertheless require critical interpretation because they are based on self-reported assessments, a relatively small sample and a cross-sectional industry survey rather than independently validated measures of security capability. Their significance therefore lies less in statistical generalisation than in their convergence with established themes in the peer-reviewed literature. The paper concludes that effective data security should be understood not as the accumulation of technical controls, but as an organisational capability that combines data visibility, ecosystem governance, independent assurance, controlled AI adoption and recovery capacity. The resulting management challenge is to build organisations that are sufficiently visible to understand their exposure, sufficiently governed to control dependencies, and sufficiently resilient to continue operating when preventive controls inevitably fail.
Keywords: data security; cybersecurity; cyber resilience; data-centric security; cloud security; supply-chain risk; Shadow AI; organisational resilience; Switzerland
1. Introduction: From Data Security to Organisational Cyber Resilience
The security of organisational data has traditionally been approached through a predominantly technological lens. Firewalls, endpoint protection, encryption, access controls and intrusion-detection systems have formed the core of conventional information-security practice. This approach remains essential, but it increasingly rests on an assumption that is becoming difficult to sustain: that organisational data can be protected by securing a relatively bounded technological environment. Digital transformation has progressively dissolved that boundary. Cloud computing, software-as-a-service platforms, distributed work, external suppliers, interconnected operational technologies and artificial intelligence have created an environment in which organisational data routinely moves across technological, organisational and jurisdictional boundaries.
This transformation requires a corresponding shift in the conceptualisation of security. Rather than treating the network, device or application as the primary object of protection, organisations increasingly need to treat data itself, its context, its permitted uses and its movement through an extended digital ecosystem as the central security concern. Hennessy et al. (2009) anticipated this shift through the concept of data-centric security, arguing that effective protection depends on classifying information according to its permissible use, appropriate handling requirements and business value. More recent cloud research similarly demonstrates the importance of dynamic data classification as organisations outsource storage and processing to increasingly complex cloud environments (Ali et al., 2023).
Data Security in Switzerland: Between Aspiration and Reality provides an empirically grounded snapshot of this transition. Produced by MSM Research AG in September 2026, the study draws on responses from 84 Swiss companies and examines four dimensions of data security: technological measures, organisational frameworks, operational challenges and companies’ own assessments of security maturity. Its central proposition is significant: data security can no longer be regarded as a narrowly defined ICT responsibility but must be understood as a strategic component of organisational resilience (MSM Research AG, 2026).
The empirical findings reveal a striking tension between security investment, organisational confidence and persistent exposure. Approximately half of the companies surveyed identify ICT security as their greatest challenge, while the study estimates that around one in seven francs of external ICT expenditure in 2026 will be directed towards cybersecurity, disaster recovery and business continuity. Yet important weaknesses remain, particularly in cloud security, third-party risk management, regulatory implementation and the governance of emerging technologies. The result is a paradox of high strategic awareness alongside uneven operational capability: organisations recognise the importance of data security and continue to invest in it, while the environments through which their data flows are simultaneously becoming more distributed, interconnected and difficult to control.
This tension is consistent with the wider cybersecurity literature. Boyson (2014) argues that the globalisation and outsourcing of IT systems require organisations to move beyond conventional internal security towards cyber supply-chain risk management (CSCRM), integrating cybersecurity, supply-chain management and enterprise risk management to establish strategic control over end-to-end processes and extended enterprise partners. The security boundary is therefore no longer equivalent to the organisational boundary. Suppliers, software dependencies, cloud providers and other technology partners become part of the organisation’s effective risk environment.
The implications are particularly important in cloud and software ecosystems. As data, applications and infrastructure become distributed, traditional perimeter-based controls cannot by themselves provide sufficient assurance. Data must be identified, classified and protected according to its sensitivity and intended use, while dependencies and third-party relationships must be incorporated into risk management. This suggests a movement from asset-centred security towards data-centric and ecosystem-aware security. The distinction matters because the compromise of a supplier, cloud service, software component or connected platform may create consequences for organisational data even when the organisation’s own perimeter controls remain intact.
The same logic extends to artificial intelligence. AI introduces not simply another technological asset to be secured, but a new mechanism through which organisational knowledge can be accessed, transformed and potentially disclosed. The emergence of Shadow AI—the unauthorised use of AI tools outside established governance frameworks—illustrates this problem particularly clearly. Puthal et al. (2025) identify risks including sensitive-data exposure, unmonitored AI systems, data leakage, model-related vulnerabilities and compliance failures. Silic, Silic and Kind-Trüller (2025) further conceptualise Shadow AI as a sociotechnical governance problem: employees may adopt AI because it improves productivity while organisational policies and controls lag behind actual practice, producing a “governance drift zone” in which formal governance exists but does not adequately shape behaviour. Their findings also point to responsibility gaps in functions such as HR and legal, where AI-generated outputs may be used without sufficient human scrutiny.
Recent research suggests that the problem is deeper than unauthorised technology adoption. Sebastian’s (2026) Digital Shadow AI Risk Theory (DART) identifies six interconnected dimensions of AI-related organisational risk: unintentional disclosure, the trust–dependence paradox, data-sovereignty conflict, knowledge dilution, the ethical black-box problem and organisational feedback loops. His empirical analysis indicates that policy awareness and training can reduce risky data sharing, while efficiency incentives can encourage employees to disclose information to AI systems. The implication is that AI governance cannot be reduced to technical access controls. It must address the behavioural, cognitive and organisational processes through which employees interact with AI.
This reinforces the relevance of human-centred AI. Shneiderman (2020) argues that trustworthy AI should combine high levels of automation with meaningful human control, rather than treating automation and human oversight as mutually exclusive alternatives. Reliability, safety and trustworthiness therefore depend not only on the technical performance of AI systems but also on the design of human–machine relationships and the preservation of human responsibility. For organisational data security, this means that AI governance should incorporate clear accountability, appropriate human validation, transparency and controls over the types of information that employees are permitted to submit to AI systems.
Taken together, these developments indicate that the central problem is no longer simply how to prevent unauthorised access to organisational data. The more fundamental question is how organisations can maintain control, accountability and continuity across an increasingly distributed digital environment in which security failures cannot always be prevented.
This is where the concept of cyber resilience becomes critical. AlHidaifi, Asghar and Ansari (2024) define cyber resilience in terms of an organisation’s capacity to prepare for, absorb, recover from and adapt to adverse cyber events. Their systematic review demonstrates the limitations of approaches that focus exclusively on preventing individual attacks and highlights the need for broader resilience capabilities. Dupont et al. (2023) similarly argue that the increasing sophistication and inevitability of cyberattacks make complete protection unrealistic. Their analysis of 58 cybersecurity professionals identifies definitional, environmental, internal and regulatory tensions that complicate the implementation of cyber resilience in practice.
The organisational dimension is particularly important. Neri, Niccolini and Virili (2025) show that cyber resilience must be understood alongside organisational resilience, particularly because contemporary attacks increasingly exploit human and organisational vulnerabilities. Their integrative framework positions cyber resilience not simply as a technical capability but as an organisational capacity involving multiple dimensions and temporal stages. Hilger (2026) develops this systemic perspective further through the Cyber Resilience Cube, which conceptualises resilience across three dimensions: time (Plan, Absorb, Recover and Adapt), system scale (from component to ecosystem) and domain (technical, organisational, human and institutional). This framework reinforces the proposition that resilience must be considered beyond individual systems and across interconnected organisational ecosystems.
Recent work also points towards greater quantitative discipline in resilience management. Shingleton and Paté-Cornell (2026) propose a probabilistic approach for measuring organisational cyber resilience and estimating the risk-reduction contribution of cybersecurity controls. This is important because resilience should not become merely a broad managerial aspiration; organisations increasingly need to understand which controls reduce risk, how much resilience they provide and where investment produces the greatest reduction in potential loss.
The evidence therefore points to three interdependent transformations.
First, organisations are moving from perimeter security towards data-centric security. The primary object of protection is increasingly the data itself—its classification, permissible use, sensitivity, location, movement and exposure—rather than simply the network through which it travels. Data-centric security is particularly relevant to cloud environments, where traditional network boundaries have limited explanatory and protective value (Hennessy et al., 2009; Ali et al., 2023).
Second, organisations are moving from internal security towards ecosystem and supply-chain security. Digital dependencies have extended the effective organisational attack surface to suppliers, cloud platforms, software components, service providers and other external partners. Cyber supply-chain risk management consequently requires security to be integrated with enterprise risk management and supply-chain governance rather than treated as a purely technical function (Boyson, 2014).
Third, organisations are moving from preventive cybersecurity towards adaptive cyber resilience. The objective is no longer simply to prevent compromise but to ensure that critical organisational functions can withstand disruption, detect and contain attacks, recover essential services and adapt to changing threats. This represents a shift from a predominantly control-oriented conception of security towards a mission- and continuity-oriented conception of resilience (AlHidaifi, Asghar and Ansari, 2024; Dupont et al., 2023; Neri, Niccolini and Virili, 2025; Hilger, 2026; Shingleton and Paté-Cornell, 2026).
Artificial intelligence cuts across all three transformations. AI can strengthen detection, classification, automation and response, but it can simultaneously create new channels through which organisational knowledge is disclosed or transformed. Shadow AI therefore exposes a broader governance problem: the boundary between authorised and unauthorised technology use is becoming increasingly difficult to maintain when employees can access powerful AI capabilities outside formal enterprise systems. Effective governance must consequently combine technical controls with data classification, employee awareness, training, human oversight, accountability and organisational processes (Shneiderman, 2020; Puthal et al., 2025; Silic, Silic and Kind-Trüller, 2025; Sebastian, 2026).
The contribution of the MSM study is therefore not simply that Swiss organisations are spending more on cybersecurity. Its deeper significance lies in the tension it exposes between security aspiration and security capability. Organisations increasingly recognise data security as strategically important, yet the operational environment in which security must be delivered is simultaneously becoming more distributed, interdependent and adaptive. The challenge is consequently not to choose between data security, supply-chain security, AI governance and cyber resilience. Rather, these should be understood as dimensions of the same emerging security paradigm: protecting organisational data and critical business functions across an interconnected ecosystem in which prevention is necessary but no longer sufficient.
From this perspective, the transition from data security to cyber resilience is not a replacement of cybersecurity controls but a reconfiguration of their purpose. Preventive controls remain necessary, but their value must ultimately be judged by their contribution to organisational resilience: the ability to understand what matters, protect it according to its context, recognise compromise, contain its consequences, sustain critical operations, recover effectively and learn from disruption. This represents a fundamental shift from securing a bounded organisation towards governing a dynamic digital ecosystem.
2. The MSM Research Study: From ICT Security to Business Resilience
The conceptual starting point of the MSM Research study is significant because it positions data security not simply as the protection of information assets, but as a component of business resilience. This framing represents an important conceptual shift. Conventional cybersecurity is principally concerned with reducing the probability and impact of unauthorised access, compromise and disruption. Resilience extends the question further: how effectively can an organisation continue to perform its critical functions when protective controls are bypassed, systems are disrupted or adverse conditions evolve? Security therefore becomes not only a question of prevention, but also of preparedness, absorption, recovery, adaptation and organisational continuity (MSM Research AG, 2026).
The distinction is important because contemporary organisations operate in environments in which complete prevention cannot realistically be assumed. Cloud services, interconnected systems, external suppliers, software dependencies, distributed work and increasingly autonomous technologies create multiple and changing pathways through which disruption can propagate. Cybersecurity controls remain essential, but their effectiveness ultimately has to be considered in relation to the organisational consequences of failure. Shingleton and Paté-Cornell (2026), for example, explicitly develop a probabilistic approach for measuring organisational cyber resilience and quantifying the risk-reduction contribution of cybersecurity controls. Their argument is consequential: because successful prevention cannot always be guaranteed, organisations must also understand their capacity to recover from potentially catastrophic loss.
The MSM study identifies digital transformation and an evolving threat landscape as major drivers of this transition. One in two surveyed Swiss companies identifies ICT security as its greatest challenge, while the study associates increasing expenditure on cybersecurity, disaster recovery and business continuity management with the changing risk environment (MSM Research AG, 2026). These findings suggest that security expenditure is increasingly being understood not merely as an investment in technical protection, but as an investment in the organisation's capacity to sustain operations under adverse conditions.
This interpretation corresponds closely with the contemporary cyber-resilience literature. AlHidaifi, Asghar and Ansari (2024), in their systematic survey of cyber-resilience research, conceptualise resilience around the organisation's capacity to prepare for, absorb, recover from and adapt to the adverse effects of cyberattacks. Their work demonstrates that cyber resilience has emerged as a necessary complement to prevention-oriented cybersecurity rather than as a replacement for it. The distinction can therefore be expressed as a movement from asking how can an organisation prevent compromise? towards also asking how can it continue to function when compromise occurs?
Neri, Niccolini and Virili (2025) develop this argument by bringing organisational resilience and cyber resilience together within an integrative conceptual framework. Their contribution is particularly relevant to the MSM study because it challenges a technologically narrow understanding of resilience. Cyber resilience is embedded within organisational structures, processes, people and decision-making rather than residing exclusively within technical infrastructure. The ability to withstand and recover from cyber disruption consequently depends upon organisational capabilities as well as technological controls. This is consistent with wider resilience research, which conceptualises organisational resilience as a capability that operates before, during and after adverse events rather than simply as a post-incident recovery mechanism.
The organisational character of resilience also has implications for governance. If cyber resilience is a property of the organisation rather than merely of its information systems, responsibility for resilience cannot remain concentrated within the ICT function. Governance, risk management, business continuity, operational management, human resources and senior leadership all become relevant to the organisation's capacity to anticipate and respond to disruption. Recent empirical work on cyber-resilience management similarly identifies governance, investment decisions, continuous monitoring, training, management support and employee capability as interconnected components of resilient systems.
This broader conception is also evident in research that moves beyond the individual organisation towards the wider sectoral environment. Cybersecurity maturity models have traditionally concentrated on individual firms, business units or technological components. However, systemic approaches argue that resilience increasingly depends upon the relationships between organisations, regulators, service providers and supply-chain partners. The PROGRESS framework, for example, explicitly incorporates IT and operational-technology supply chains, regulatory actors and external service providers, arguing that sectoral resilience depends on cooperation, information flows and feedback across organisational boundaries. This reinforces the MSM study's underlying implication that business resilience cannot be separated from the resilience of the ecosystem on which the organisation depends.
The transition also changes how security maturity should be interpreted. A technically mature organisation may possess extensive preventive controls while remaining operationally vulnerable if it cannot identify its critical processes, tolerate disruption, make rapid decisions or restore essential services. Conversely, resilience requires organisations to develop capabilities that allow them to anticipate threats, absorb shocks, coordinate responses and learn from disruption. In this respect, resilience should not be understood simply as a higher level of cybersecurity maturity; it represents a different organising logic for understanding security performance.
This distinction is particularly relevant to the MSM study's tension between security aspiration and operational capability. The report indicates substantial awareness of the strategic importance of data security and significant investment in cybersecurity and continuity capabilities, while simultaneously identifying weaknesses in areas such as cloud security, third-party risk and the implementation of security processes (MSM Research AG, 2026). The resulting picture is not one of organisational failure, but of an organisation-wide transition in which security capabilities are developing faster in some dimensions than in others.
The academic literature helps explain why such unevenness should be expected. Organisational resilience is not a single technical capability that can be installed through a discrete security investment. It emerges from the interaction of technologies, governance arrangements, organisational routines, human capabilities and decision-making processes. Resilience therefore develops dynamically through experience and through the organisation's capacity to anticipate, respond to and learn from changing conditions. This capability-based perspective is particularly important because it shifts attention from the presence of individual controls towards the relationships between controls and organisational outcomes.
The economic dimension is equally important. Once cybersecurity is interpreted as a component of business resilience, investment decisions can no longer be based solely on the technical severity of individual vulnerabilities. They must also consider business criticality, potential operational disruption, recovery requirements, regulatory obligations, customer trust and the consequences of prolonged service interruption. Shingleton and Paté-Cornell's (2026) work is relevant here because it seeks to quantify both organisational resilience and the risk-reduction effects of cybersecurity controls, thereby linking technical controls with management-level decisions about risk and investment.
The MSM study can therefore be interpreted as an empirical manifestation of a broader theoretical movement in cybersecurity research. Security is increasingly becoming a property of the organisation and its ecosystem rather than simply a collection of technical controls. The objective is no longer exhausted by keeping attackers outside the perimeter. Instead, effective security increasingly means ensuring that critical information, processes and services remain sufficiently protected, recoverable and adaptable when organisational boundaries are breached or disrupted.
This conceptual shift can be represented as a progression:
ICT security → information security → cyber risk management → cyber resilience → business resilience.
The progression does not imply that earlier stages become obsolete. Firewalls, encryption, identity management, endpoint security and other preventive controls remain fundamental. Rather, their purpose is being reframed. They are increasingly understood as components of a larger organisational capability whose ultimate objective is not simply the absence of incidents, but the continuity and adaptability of the organisation under conditions of digital disruption.
Accordingly, the principal significance of the MSM study lies in its positioning of data security within this broader business context. Its findings suggest that Swiss organisations are confronting a security environment in which technological protection, organisational governance, operational continuity and strategic decision-making are becoming inseparable. The report therefore provides empirical support for the proposition advanced in the cyber-resilience literature: effective cybersecurity should ultimately be evaluated not only by the controls an organisation possesses, but by its capacity to anticipate disruption, withstand compromise, recover critical capabilities and adapt to the changing conditions of the digital environment.
3. Theme One: The Emergence of Data-Centric Security
3.1 From the Network Perimeter to the Data Itself
One of the clearest findings of the MSM Research study is the weakening of the traditional ‘fortress’ model of cybersecurity. Conventional security architectures have historically placed the organisational network perimeter at the centre of protection, relying on firewalls, gateways and access controls to distinguish trusted internal environments from potentially hostile external ones. The continuing migration of data and applications to cloud platforms, however, makes such a clearly defined boundary increasingly difficult to maintain. The MSM study consequently identifies data-centric security as an increasingly important response to the changing architecture of organisational information environments (MSM Research AG, 2026).
The conceptual distinction is fundamental. In a predominantly perimeter-oriented model, the central security question is:
Who or what is permitted to enter the system?
In a data-centric model, the question becomes considerably broader:
What is the data, where is it located, how sensitive is it, who should access it, for what purpose may it be used, how should it be protected and what happens to it when it crosses organisational or technological boundaries?
The second question is better aligned with distributed digital environments because the location of the network perimeter no longer necessarily corresponds to the location of the data. Information may simultaneously reside in internal infrastructure, cloud storage, SaaS applications, collaboration platforms, mobile devices and third-party environments. Security must therefore travel with the information rather than depend exclusively upon the security characteristics of the network through which the information happens to move.
This proposition is consistent with the foundational work of Hennessy et al. (2009), who conceptualise data-centric security around the classification of information according to its permissible use, appropriate handling and business value. Their argument is important because it changes the object of security governance. Rather than treating data protection as a consequence of securing the infrastructure around the data, security requirements are attached directly to the characteristics and intended use of the information itself. Data classification consequently becomes a mechanism for connecting security, privacy, business requirements and regulatory obligations.
The contemporary relevance of this approach is particularly evident in cloud environments. Ali et al. (2023) demonstrate the practical value of confidentiality-based data classification through their Classification-as-a-Service model, which dynamically differentiates the treatment of cloud data according to its security level. Their research addresses a fundamental tension in cloud security: treating all data identically can create unnecessary processing overhead, whereas failing to differentiate sensitive information can expose confidential data to disproportionate risk. Their findings therefore support the principle that security controls should be proportionate to the characteristics and protection requirements of the data rather than uniformly applied.
The MSM study provides empirical evidence that this principle is becoming operationally relevant. Fifty-seven per cent of surveyed organisations identify automated data discovery and classification as a high-priority cloud-security measure (MSM Research AG, 2026). This is significant not simply because automation is increasingly being adopted, but because discovery and classification establish the informational foundation upon which subsequent security decisions depend. An organisation cannot reliably determine what should be encrypted, restricted, monitored, retained, transferred or deleted if it does not first know what information it possesses and how that information should be treated.
The strategic importance of classification therefore extends beyond the classification technology itself. Classification is an enabling governance capability. It creates the basis for differentiated policies, controls and accountability. Highly sensitive information can be subjected to stronger access requirements and monitoring; information subject to regulatory restrictions can be managed according to jurisdictional requirements; and lower-risk information need not necessarily receive the same level of technical protection. Data-centric security consequently represents not the abandonment of conventional controls, but a more intelligent allocation of those controls according to information value and risk.
3.2 Data Visibility as a Prerequisite for Control
The MSM report repeatedly associates effective data security with visibility. Its discussion of cloud environments identifies data discovery and classification alongside Data Loss Prevention (DLP), data residency, identity-based access controls and encryption as important security measures (MSM Research AG, 2026). Taken together, these measures suggest a governance sequence:
visibility → classification → policy → control → monitoring → assurance.
The sequence matters because each stage depends, to some degree, upon the preceding one. If an organisation cannot discover its data, it cannot classify it reliably. Without classification, differentiated policies become difficult to implement. Without appropriate policies, access controls, encryption and DLP rules may be applied inconsistently. And without monitoring and assurance, organisations cannot determine whether the controls are operating as intended.
This logic extends the argument of Hennessy et al. (2009). Their conception of data-centric security links protection directly to the characteristics and permitted uses of information rather than treating security as an independent technical function. Classification is therefore not merely an administrative label attached to a file or database record. It provides the semantic information required to determine what security and privacy obligations should follow the data throughout its lifecycle.
Ali et al. (2023) reinforce this principle from a cloud-computing perspective. Their Classification-as-a-Service approach dynamically differentiates cloud data according to confidentiality requirements, illustrating how classification can become an operational input into technical security decisions. Their research is particularly relevant because cloud environments create pressure to secure large volumes of heterogeneous information without applying the same computational and control overhead to every data object.
The broader implication is that visibility becomes a condition of meaningful control. Encryption can protect information, but only if the organisation understands which information requires encryption and under what circumstances. DLP can prevent inappropriate transfer, but its effectiveness depends upon knowing what constitutes sensitive information. Identity and access management can restrict users, but appropriate authorisation depends upon understanding the sensitivity and legitimate purpose of the data being accessed.
This creates a significant difference between infrastructure-centric and data-centric security. Infrastructure-centric security asks whether a system is adequately protected. Data-centric security asks whether the information remains appropriately protected throughout its lifecycle, irrespective of where the information is processed or stored.
The distinction becomes increasingly important as organisations adopt cloud and SaaS architectures. Data may move between internal systems, public or private cloud environments, collaboration platforms, external applications and service providers. A traditional perimeter can still protect particular infrastructure components, but it provides an increasingly incomplete representation of the data environment. The relevant security boundary therefore becomes dynamic and potentially fragmented.
The MSM study consequently points towards a model in which the data object becomes a primary unit of security governance. The question is not simply whether a particular system is inside or outside the organisational perimeter, but whether the data remains subject to appropriate controls as it moves between systems, users, providers and jurisdictions.
This also helps explain why data-centric security should not be interpreted as a purely technical architecture. It requires the integration of information management, security policy, identity governance, regulatory compliance, business-process knowledge and risk management. Data classification has value precisely because it connects these domains.
3.3 Data Residency, Jurisdiction and Digital Sovereignty
The MSM study introduces a further dimension to data-centric security through its findings on data residency. Forty-seven per cent of surveyed companies report relying on the physical storage of data within Switzerland. The report interprets this continued preference for domestic storage as reflecting the Swiss regulatory and cultural environment and as an important anchor of organisational trust (MSM Research AG, 2026).
This finding is significant because it demonstrates that data security cannot be reduced to confidentiality, integrity and availability alone. The location and jurisdiction of data can themselves become governance considerations. Where data is stored may influence the legal regime applicable to that information, the regulatory obligations imposed upon the organisation, the organisation's ability to exercise control over the data and the perceived risks associated with foreign infrastructure or service providers.
The distinction between data residency and data sovereignty is important here. Data residency concerns where data is physically or geographically stored; data sovereignty concerns the legal and governmental authority that may apply to data by virtue of its location, processing or control. These concepts overlap but are not identical. Consequently, storing information within Switzerland may address certain residency or regulatory concerns without automatically eliminating all risks associated with foreign ownership, remote administration, cloud dependencies or cross-border data processing.
This issue has been recognised in the wider literature on cloud governance. Irion (2013), for example, argues that cloud computing creates particular challenges for data sovereignty because cloud infrastructures are geographically distributed, dynamic and potentially subject to multiple legal jurisdictions. Importantly, the study concludes that data-sovereignty risks cannot be addressed through technology or contractual arrangements alone; they also constitute questions of law and public policy.
The implication for organisational security is therefore broader than a simple preference for local storage. As cloud infrastructures become increasingly distributed, physical, technological, contractual and legal boundaries may no longer coincide. An organisation may know where its primary data is stored while having less certainty about where backups are maintained, where processing occurs, which subcontractors have access, where administrative functions are performed or which jurisdictional authorities could potentially obtain access.
Data-centric security must therefore incorporate a jurisdictional dimension. The relevant questions become not only what data is this? and who may access it?, but also where may it be stored or processed, under which legal regime, by which providers and with what degree of organisational control?
This is particularly relevant to highly regulated or strategically sensitive information. In such contexts, data location can become part of the organisation's risk appetite and architectural decision-making. The choice between domestic, regional and globally distributed infrastructure may therefore involve trade-offs between scalability, cost, resilience, regulatory compliance, vendor dependency and sovereignty.
At the same time, the MSM finding should not be interpreted as demonstrating that Swiss data residency is inherently more secure than foreign storage. Physical location is a governance variable, not a security guarantee. A data centre located within Switzerland can still be compromised, misconfigured or exposed through weak identity controls, insecure software or compromised suppliers. Conversely, appropriately governed infrastructure outside Switzerland may provide strong technical protection. The significance of residency lies instead in the additional dimensions of legal control, regulatory exposure, jurisdiction and trust that accompany the physical location of information.
The emerging data-centric model can therefore be understood as having at least four interconnected layers:
Data visibility — knowing what information exists and where it resides;
Data classification — determining sensitivity, value, permitted use and protection requirements;
Data control — applying differentiated access, encryption, DLP, monitoring and lifecycle controls; and
Data sovereignty — determining where information may be stored or processed and which legal and jurisdictional regimes apply.
These layers extend the traditional security model from protecting a network boundary towards governing the entire lifecycle and context of organisational information.
The significance of the MSM findings is therefore not simply that Swiss organisations are adopting automated classification or continuing to prefer domestic data storage. More fundamentally, the study illustrates the emergence of a different security logic. In a distributed digital environment, security must increasingly follow the data. The organisation must know what it holds, understand its value and sensitivity, determine how it may be used, control who and what can access it, monitor how it moves and understand the legal and jurisdictional environments through which it passes.
Data-centric security thus represents the first major transformation identified in this study. It shifts the centre of gravity of information security from the infrastructure surrounding information to the information itself. Yet this shift also exposes a limitation: organisations cannot fully control data security if the data moves through ecosystems of suppliers, cloud providers and software dependencies that lie beyond their direct organisational boundary. This observation provides the conceptual bridge to the second theme of the analysis—the emergence of ecosystem and cyber supply-chain security.
4. Theme Two: The Organisation Is Only as Secure as Its Ecosystem
4.1 Internal Security Maturity versus External Dependency Risk
The second major finding of the MSM Research study concerns a striking asymmetry between internal cybersecurity institutionalisation and external dependency management. The study reports that 79 per cent of surveyed organisations have established security-awareness measures, including regular and role-based training. Approximately two-thirds report defined security and data processes, while around half have established clear governance responsibilities involving roles such as chief information security officers and data-protection officers (MSM Research AG, 2026).
Taken together, these findings suggest that cybersecurity has become substantially institutionalised within many organisations. Security awareness is no longer treated solely as an ad hoc technical issue; it is increasingly supported by formal processes, designated responsibilities and employee-oriented controls. This represents an important development because cyber risk is partly mediated by human behaviour, organisational routines and management decisions rather than by technology alone.
Yet the apparent strength of internal governance contrasts sharply with the treatment of external dependencies. Only 14 per cent of surveyed organisations report systematically managing third-party and supply-chain risks (MSM Research AG, 2026). The resulting asymmetry is arguably the most revealing finding in the study. Organisations appear comparatively well equipped to govern security within their formal organisational boundaries, while remaining considerably less mature in governing the external relationships through which their data, systems and critical processes increasingly operate.
The problem can therefore be expressed as a governance paradox:
The organisation may be securing itself internally while remaining exposed through the ecosystem on which its operations depend.
This distinction is increasingly important because digital transformation has changed the structure of organisational dependency. Cloud providers, SaaS platforms, software vendors, managed service providers, outsourced business processes, application programming interfaces (APIs), external developers and connected operational technologies have become integral to organisational operations. Consequently, a security incident affecting another organisation can increasingly become a security, operational or continuity problem for the focal organisation.
The MSM study therefore exposes a potential maturity gap between internal security capability and ecosystem security capability. High levels of employee awareness and formal governance cannot compensate fully for weak visibility into third-party dependencies. The organisation may know how to manage its own employees and systems while having considerably less knowledge about the security architecture, software dependencies, subcontractors or operational practices of the external organisations on which it relies.
This is precisely the type of problem anticipated by the cyber supply-chain risk-management literature.
4.2 The Porous Organisation
Boyson (2014) conceptualises cyber supply-chain risk management (CSCRM) as an integrative discipline combining cybersecurity, supply-chain management and enterprise risk management. Its purpose is to establish strategic control across the end-to-end processes of both the focal organisation and its extended enterprise partners. Crucially, Boyson distinguishes CSCRM from conventional cybersecurity because the former seeks visibility and control beyond the focal organisation itself, including suppliers and other external partners.
This conceptualisation provides a strong theoretical foundation for interpreting the MSM findings. The modern organisation is not a closed technical system. It is better understood as a porous and interdependent socio-technical network whose effective operational capabilities depend partly upon entities that it does not own or directly control.
The distinction between the legal organisation and the operational organisation is therefore increasingly important. The legal entity may have a clearly defined boundary, but its dependency network does not. Critical business processes may rely on infrastructure, software, data services and expertise distributed across multiple external organisations and jurisdictions.
The effective security boundary can consequently be conceptualised as:
the organisation + its critical dependencies + the relationships connecting them.
This is a substantially broader object of governance than the traditional enterprise network.
The implications are considerable. An organisation can maintain strong internal access controls, conduct regular employee training and operate mature incident-response procedures while remaining exposed through:
cloud and SaaS providers;
managed service providers;
outsourced business processes;
software libraries and third-party components;
external developers and system integrators;
APIs and interconnected platforms;
remote maintenance arrangements;
hardware and technology suppliers; and
interconnected operational technologies.
These dependencies create risk propagation pathways. A compromise originating outside the organisation can cross contractual, technological or organisational boundaries and eventually affect the confidentiality, integrity or availability of internal systems and data.
The academic literature increasingly recognises this systemic character of supply-chain cyber risk. Research on digital supply chains argues that cyber protection must account for the interconnectedness of supply-chain actors rather than treating security as an attribute of isolated firms. More recent research similarly finds that cyber-risk management strategies need to support integration with suppliers, customers and internal functions if supply chains are to achieve greater cyber resilience and robustness.
This represents an important conceptual shift from enterprise security to ecosystem security. The relevant question is no longer simply whether the organisation has implemented appropriate controls, but whether the network of relationships upon which critical organisational functions depend is sufficiently visible, governed and resilient.
The concept of ecosystem security also changes the meaning of organisational responsibility. An organisation cannot necessarily transfer its own security obligations to a supplier merely by transferring a process or service to that supplier. Outsourcing may transfer operational activity, but it does not necessarily transfer the consequences of failure. Where a third party processes sensitive data, provides critical infrastructure or supports an essential business process, its security posture becomes relevant to the risk posture of the focal organisation.
Consequently, dependency becomes a security variable.
4.3 From Third-Party Risk to Software Supply-Chain Risk
The MSM report's discussion of software supply chains makes this argument particularly tangible. It identifies the movement of the attack surface into a digital ecosystem that is only partially visible and highlights the risk posed by compromised third-party software components. In response, it recommends greater visibility into critical dependencies and software provenance, including Software Bills of Materials (SBOMs), dependency scanning and hardened development and deployment processes (MSM Research AG, 2026).
The significance of this recommendation extends beyond the SBOM itself. An SBOM can provide visibility into the components that constitute a software product, but visibility is valuable because it enables organisations to identify dependencies, assess exposure, respond to vulnerabilities and establish accountability across the software lifecycle. The fundamental problem is therefore not simply that organisations use third-party software; it is that they may lack sufficient knowledge of what that software contains, where components originate, how they are maintained and how vulnerabilities propagate through dependent systems.
Recent academic research reinforces this shift. A contemporary review of cyber supply-chain risk management identifies system integrators, ICT service providers, manufacturers and digital-service providers as distinct categories of external dependency and argues that traditional approaches such as supplier questionnaires and ratings are increasingly insufficient on their own for identifying and mitigating supply-chain risks. The implication is that third-party assurance must become more continuous, evidence-based and technically informed.
This is particularly important for software because dependency relationships can be both deep and opaque. A single enterprise application may depend upon numerous external libraries, open-source components, development tools, cloud services and infrastructure providers. A vulnerability or compromise introduced several layers below the organisation's direct supplier can nevertheless propagate upwards into the organisation's environment.
The software supply chain therefore illustrates the limitations of a simple first-tier supplier model. Organisations need visibility not only into who they buy from, but also into what technological dependencies those suppliers themselves rely upon.
This creates a hierarchy of dependency:
organisation → supplier → supplier's technology → underlying software components → wider digital ecosystem.
The further the organisation moves through this dependency chain, the more difficult direct governance becomes. Yet the potential impact of vulnerabilities can also increase because a compromised component may be reused across multiple downstream organisations.
The resulting governance challenge is one of visibility at scale.
SBOMs, dependency scanning, secure development practices and software provenance controls can help address this challenge, but they are most effective when incorporated into a broader supply-chain governance model. This model needs to connect procurement, architecture, development, security operations, vendor management, compliance and business continuity.
4.4 Cybersecurity as a Cross-Functional Management Problem
The MSM report therefore has an important implication for organisational governance: software supply-chain security cannot be treated as a problem belonging exclusively to the CISO or information-security function. The risks created by external dependencies arise from decisions distributed across the organisation.
Procurement determines which suppliers and technologies enter the organisation.
Enterprise architecture determines how deeply external platforms become embedded in critical processes.
Software development determines how third-party components are selected, maintained and deployed.
Data protection and compliance determine whether external providers can lawfully and appropriately process particular categories of information.
Vendor management determines how suppliers are assessed, monitored and contractually governed.
Business continuity determines whether the organisation can continue operating when an external provider becomes unavailable or compromised.
Cybersecurity provides many of the technical mechanisms for identifying, assessing and mitigating these risks.
No single function therefore possesses the complete risk picture.
This is closely aligned with Boyson's (2014) conception of CSCRM, which emphasises structural in tegration between cybersecurity, supply-chain management and enterprise risk management. Boyson argues that effective supply-chain cyber risk management requires collaboration across organisational functions rather than isolated technical controls.
Bartol (2014) makes a similar point in her analysis of cyber supply-chain security practices, emphasising the need to bring together multiple professional communities, including information security, systems and software engineering, supply-chain management and process improvement. The implication is that supply-chain security is inherently interdisciplinary because the sources of risk and the mechanisms for controlling them are distributed across organisational functions.
This cross-functional character is increasingly important as supply chains become more technologically sophisticated. Recent research examining the integration of artificial-intelligence capabilities into supply-chain cyber-risk management similarly suggests that AI can support different of the cyber-risk-management process, reinforcing the need to integrate technological capabilities with established supply-chain governance processes rather than treating AI as an isolated security solution.
The result is a shift from security ownership to security interdependence. The CISO remains an important actor, but security outcomes increasingly depend upon decisions made by executives, procurement teams, architects, developers, suppliers, data-protection specialists and operational managers.
4.5 From Supplier Assurance to Ecosystem Resilience
The MSM findings ultimately suggest that third-party risk should not be treated as a narrow compliance exercise. A supplier questionnaire completed once a year may provide evidence of governance, but it does not necessarily demonstrate that a critical supplier remains secure, that its dependencies are understood or that the organisation can continue operating if that supplier fails.
A more mature approach would combine visibility, assessment, continuous monitoring, contractual governance, technical assurance, incident coordination and resilience planning. The objective should be to understand not only whether suppliers meet minimum security requirements, but also how their failure could affect critical organisational processes.
This distinction is central to the evolution from supply-chain security towards supply-chain cyber resilience. Recent research explicitly links cyber-risk-management strategies and organisational integration with the development of supply-chain resilience and robustness. The relevant management question therefore changes from:
“Is this supplier secure?”
to:
“What happens to our organisation if this dependency is compromised, disrupted or unavailable?”
The second question is strategically more useful because it connects supplier risk with business impact, recovery requirements and organisational resilience.
It also provides a direct connection to the first theme of this study. Data-centric security requires organisations to know what data they possess, how sensitive it is and how it should be controlled. Ecosystem security requires them to understand where that data travels, which external parties can access it and which dependencies support the systems through which it moves. Cyber resilience then asks whether the organisation can continue operating if one of those dependencies fails.
The three themes are therefore cumulative:
data-centric security identifies the object of protection;
ecosystem security identifies the extended environment of exposure;
cyber resilience determines the organisation's capacity to withstand failure across that environment.
The MSM study's finding that only 14 per cent of organisations systematically manage third-party and supply-chain risks is therefore more than an isolated maturity statistic. It reveals a structural challenge in contemporary digital governance: organisations may have institutionalised security within the enterprise faster than they have learned to govern the ecosystem on which the enterprise depends.
The organisation is consequently only as secure as the critical dependencies that connect it to the wider digital economy. As digital transformation deepens, the distinction between internal and external security becomes progressively less meaningful. The relevant unit of analysis is increasingly the ecosystem of technologies, organisations, people, processes and dependencies through which critical data and business services flow.
This provides the foundation for the third theme of the analysis: if organisations cannot prevent every disruption within such an interconnected ecosystem, security must increasingly be evaluated through their capacity to anticipate, absorb, contain, recover from and adapt to disruption. The question therefore moves from how secure is the organisation? to how resilient is the organisation and its ecosystem?
5. Theme Three: The Maturity Paradox and the Shift to Cyber Resilience
5.1 Perceived Maturity versus Demonstrated Capability
The third major theme emerging from the MSM Research study is the tension between security aspiration and implemented capability. The study reports that 43 per cent of respondents rate their data-security maturity as high and a further 14 per cent rate it as very high. In aggregate, therefore, 57 per cent of surveyed organisations perceive themselves to have high or very high data-security maturity (MSM Research AG, 2026).
At first sight, this suggests a relatively mature Swiss security environment. Yet this positive self-assessment sits alongside significant weaknesses in areas that are increasingly central to contemporary cyber risk. Only 14 per cent of organisations report systematically managing third-party and supply-chain risks, while only 21 per cent report systematic embedding and audit verification of regulatory requirements. Cloud Security Posture Management also remains relatively underdeveloped despite the increasing dependence on cloud technologies (MSM Research AG, 2026).
The resulting contradiction is what the MSM study describes as a maturity paradox: organisations report high levels of confidence in their security maturity while important elements of security implementation remain incomplete.
This paradox should not be interpreted simply as evidence that organisations are overestimating their capabilities. A more fundamental issue is that security maturity is difficult to measure when risk is distributed, dynamic and continually changing. Conventional maturity assessments often emphasise the presence of policies, processes, technologies and assigned responsibilities. These are important indicators of institutionalisation, but their existence does not necessarily demonstrate that an organisation can control its exposure across an interconnected digital environment or perform effectively during a major disruption.
An organisation may possess:
formal security policies;
employee-awareness programmes;
a CISO or equivalent security function;
data-classification processes;
Data Loss Prevention capabilities;
identity and access controls;
encryption;
incident-response procedures; and
business-continuity arrangements,
while remaining materially exposed through cloud misconfiguration, third-party dependencies, software supply chains, unauthorised AI use or interconnected operational technologies.
The distinction is therefore between control presence and control effectiveness.
A mature security organisation is not necessarily one that possesses the greatest number of controls. Rather, maturity should increasingly reflect the extent to which controls are appropriately designed, implemented across the relevant risk environment, integrated with one another, continuously monitored and capable of producing the intended organisational outcomes.
This distinction is particularly important in cloud environments. As infrastructure becomes distributed, security posture can change continuously through configuration changes, new services, altered permissions, software updates and changing data flows. A point-in-time assessment may therefore provide only a partial representation of actual exposure. The organisation's security posture is better understood as a dynamic state than as a fixed property.
The academic literature on cyber-resilience measurement reinforces this argument. AlHidaifi, Asghar and Ansari (2024) observe that cyber resilience has become increasingly important as expanding digital attack surfaces create new forms of exposure. Their systematic survey conceptualises resilience through an organisation's capacity to prepare for, absorb, recover from and adapt to adverse cyber events, thereby extending assessment beyond the existence of preventive controls.
More recent work by AlHidaifi, Asghar and Ansari (2026) similarly argues that cyber-resilience quantification is difficult because IT infrastructures and their risk conditions change continuously. Their probabilistic approach seeks to evaluate resilience dynamically rather than relying exclusively on static security assessments. This is important for interpreting the MSM maturity paradox because it suggests that a security score is meaningful only insofar as it captures the organisation's changing capacity to withstand and recover from disruption.
The distinction can therefore be expressed as follows:
Control maturity asks: What security capabilities does the organisation have?
Resilience maturity asks: How effectively can those capabilities protect critical organisational functions when conditions change or controls fail?
The second question is considerably more demanding.
It requires organisations to understand not only whether a control exists, but also whether it covers the relevant assets and dependencies, whether it interacts effectively with other controls, whether it is continuously maintained and whether the organisation can demonstrate its effectiveness under realistic disruption scenarios.
This suggests four dimensions of meaningful security maturity:
coverage — whether relevant assets, data, people and dependencies are included;
integration — whether technical, organisational and governance controls operate as a coherent system;
effectiveness — whether controls actually reduce exposure and support desired outcomes; and
adaptability — whether the organisation can adjust controls and responses as threats, technologies and dependencies change.
The maturity paradox identified by MSM can therefore be understood as a potential gap between formal capability and adaptive capability. An organisation may be institutionally mature while remaining operationally fragile.
5.2 From Prevention to Resilience
The implications become clearer in the MSM report's explicit recommendation to move “away from pure prevention and towards genuine cyber resilience and Zero Trust at the data level” (MSM Research AG, 2026). This represents a significant change in the underlying security objective.
A prevention-oriented model primarily asks:
How can the organisation prevent the attack?
A resilience-oriented model asks:
What happens if prevention fails?
The second question does not diminish the importance of prevention. Firewalls, identity controls, encryption, vulnerability management, secure software development and other preventive measures remain essential. Rather, resilience changes the criterion by which those controls are ultimately evaluated. Their value lies not only in reducing the probability of compromise, but also in limiting the consequences of compromise and supporting rapid organisational recovery.
This is particularly important because contemporary digital environments make complete prevention unrealistic. Shingleton and Paté-Cornell (2026) explicitly argue that preventing cyber attackers from infiltrating systems is not always feasible and develop a probabilistic method for measuring organisational resilience and the risk-reduction contribution of cybersecurity controls. Their work therefore connects conventional cybersecurity investment with the broader organisational objective of recovering from potentially catastrophic loss.
Cyber resilience consequently represents a temporal expansion of security. Conventional cybersecurity often concentrates on the period before an incident: identify vulnerabilities, deploy controls and prevent compromise. Resilience extends the security lifecycle across multiple stages:
prepare → withstand/absorb → detect and contain → recover → adapt.
AlHidaifi, Asghar and Ansari (2024) explicitly define cyber resilience in terms of the capacity to prepare for, absorb, recover from and adapt to adverse cyber events affecting business operations. The implication is that resilience is not simply an incident-response capability. It begins before the incident through preparation and continues after recovery through adaptation and learning.
This temporal dimension is particularly important for business continuity. The relevant outcome of a cyberattack is not necessarily whether an attacker gained access, but whether critical organisational functions can continue, how long disruption lasts, how effectively the organisation contains consequences and how quickly essential services can be restored.
5.3 The “Assume Breach” Principle
The MSM report's final discussion of an “Assume Breach” approach provides a practical expression of this resilience logic. Rather than assuming that security controls will prevent every compromise, the organisation is encouraged to plan on the possibility that a breach will occur and to determine in advance how quickly it can detect, contain and recover from the resulting disruption (MSM Research AG, 2026).
This changes the nature of preparedness.
An organisation adopting an Assume Breach philosophy needs to know:
which business processes are genuinely critical;
which data and systems those processes depend upon;
how long critical services can tolerate disruption;
which recovery objectives are acceptable;
which decisions must be made during a crisis;
who has authority to make those decisions;
how incidents will be contained; and
how essential operations will be restored.
The significance of this approach is that cybersecurity becomes inseparable from business continuity and executive decision-making. Technical incident response alone cannot determine which business services should be restored first, what level of disruption is acceptable or when an organisation should prioritise containment over immediate restoration. These are business decisions requiring management involvement.
This aligns closely with Neri, Niccolini and Virili's (2025) conceptualisation of organisational cyber resilience. Their systematic review brings organisational resilience and cyber resilience together and identifies complementary characteristics and temporal dimensions across the two bodies of literature. Their central contribution is an integrated conception of cyber resilience in which cybersecurity is connected to broader organisational capabilities rather than treated as a purely technical property.
Their perspective is particularly important for interpreting the MSM study because it explains why the resilience problem cannot be delegated entirely to the security function. If resilience is organisational, then senior management, operational units, business-process owners, technology teams and security specialists must collectively determine how the organisation will respond to disruption.
This also reinforces the argument developed in the previous two sections. Data-centric security identifies what needs to be protected; ecosystem security identifies the dependencies through which exposure can occur; resilience determines how the organisation will continue operating when those protections or dependencies fail.
5.4 From Security Controls to Organisational Capability
The movement towards resilience therefore represents more than the addition of disaster recovery or incident-response procedures to an existing cybersecurity programme. It changes the underlying conception of what security is intended to achieve.
Under a control-oriented model, maturity can be assessed through the presence of technologies, policies and procedures.
Under a resilience-oriented model, maturity must also be assessed through the organisation's ability to perform under stress.
This creates an important distinction between nominal capability and demonstrated capability. An organisation may have an incident-response plan, for example, but this does not establish that the plan will work during a major event. Similarly, an organisation may have a business-continuity policy without knowing whether critical dependencies can actually be replaced or restored within the required timeframe.
Resilience therefore requires testing, exercising and learning. It requires organisations to expose assumptions about their dependencies and recovery capabilities before a real crisis does so. The objective is not to predict every possible attack, but to establish whether the organisation possesses sufficient adaptive capacity when confronted with an unexpected combination of failures.
This is consistent with the emerging quantitative literature. Shingleton and Paté-Cornell (2026) argue for a probabilistic approach to measuring organisational cyber resilience and to estimating the risk-reduction effects of cybersecurity controls. Such approaches are important because they provide a potential bridge between security engineering and management decision-making: rather than treating resilience as an abstract aspiration, organisations can increasingly seek to estimate how particular controls affect the probability and consequences of disruptive events.
The implication is a move from compliance with controls towards evidence of capability.
A mature organisation should therefore be able to demonstrate not only that it has policies, technologies and responsibilities in place, but also that:
critical assets and processes have been identified;
dependencies and exposure pathways are understood;
controls are proportionate to the relevant risks;
incidents can be detected and contained;
critical services can be recovered within acceptable timeframes;
decision-making responsibilities are clear during disruption; and
lessons from incidents and exercises are incorporated into future security arrangements.
This provides a more demanding and more strategically meaningful conception of maturity than a checklist of implemented controls.
5.5 The Maturity Paradox Reconsidered
The apparent contradiction in the MSM findings can therefore be interpreted in a more constructive way. The fact that 57 per cent of organisations rate their data-security maturity as high or very high while significant weaknesses remain in supply-chain governance, regulatory assurance and cloud-security management does not necessarily mean that the organisations' self-assessments are invalid. Rather, it suggests that the meaning of maturity itself is changing.
An organisation may be mature according to a traditional control-based model while remaining immature according to an ecosystem- and resilience-based model.
This distinction is critical.
Traditional maturity asks whether the organisation has established appropriate security mechanisms.
Emerging resilience maturity asks whether those mechanisms provide effective, integrated and adaptive protection for critical organisational functions across a changing ecosystem.
The latter standard is inherently more demanding because it incorporates external dependencies, changing technology, human behaviour, organisational coordination and recovery capability.
The MSM report therefore captures a transitional stage in the evolution of organisational security. Swiss organisations appear to have moved significantly beyond the assumption that cybersecurity is simply a technical matter. Yet the uneven implementation of supply-chain governance, regulatory assurance and cloud-security capabilities suggests that the transition towards fully integrated cyber resilience remains incomplete.
The resulting challenge is not simply to increase the number of security controls. It is to connect those controls to organisational purpose and resilience outcomes.
The ultimate question becomes not whether an organisation can claim to be secure, but whether it can demonstrate that it is capable of maintaining critical operations when security assumptions are violated.
This is the central contribution of the third theme. The MSM study's maturity paradox reveals that contemporary security maturity can no longer be understood adequately through the presence of controls alone. In a distributed and continuously changing digital environment, mature security increasingly means the capacity to understand exposure, protect critical data and processes, detect compromise, absorb disruption, recover essential capabilities and adapt after failure.
The transition is therefore from security as prevention to security as organisational resilience. Prevention remains a necessary first line of defence, but resilience provides the broader organising principle through which security investments, governance arrangements and operational capabilities can be evaluated.
The three themes of this analysis consequently converge:
data-centric security determines what must be protected;
ecosystem security determines the extended environment within which protection must operate;
cyber resilience determines whether the organisation can continue to function when protection is breached or disrupted.
Together, they suggest that the future of organisational cybersecurity lies not in constructing an impenetrable digital fortress, but in developing an organisation that is visible enough to understand its exposure, controlled enough to reduce it, connected enough to govern its dependencies and resilient enough to recover when those controls inevitably fail.
6. Shadow AI: The Next Boundary Problem
Perhaps the most forward-looking aspect of the MSM report concerns artificial intelligence. Its discussion of Shadow AI extends the paper’s earlier argument that conventional organisational boundaries are becoming increasingly difficult to define and control. Whereas data-centric security shifts the object of protection from the network perimeter to the data itself, and ecosystem security recognises that organisational exposure extends beyond the formal enterprise, Shadow AI introduces a further boundary problem: organisational data and knowledge may cross into external AI systems through ordinary employee activity, often without passing through established governance mechanisms.
The MSM study identifies uncontrolled AI use as an emerging security challenge, highlighting several pathways through which exposure can occur: employees may enter confidential information into unapproved AI tools, accept AI-generated outputs without adequate verification, or use AI applications and agents outside established security policies. These risks are not limited to the technical security of AI systems themselves. Rather, they arise from the interaction between employee behaviour, organisational governance, data practices and rapidly evolving technology.
This distinction is important because Shadow AI challenges the traditional separation between authorised and unauthorised technology. Conventional IT governance assumes that technology can be governed through procurement, configuration, access management and centrally administered infrastructure. Generative and agentic AI weaken this assumption because many tools are inexpensive, easily accessible and usable through consumer-facing interfaces. Consequently, employees can adopt new capabilities more rapidly than organisations can complete formal procurement, risk assessment, security review and policy development. The resulting problem is therefore not simply unauthorised software adoption, but a growing misalignment between the pace of technological adoption and the pace of organisational governance.
Recent peer-reviewed research supports this interpretation. Silic, Silic and Kind-Trüller (2025) conceptualise Shadow AI as the unsanctioned use of AI systems outside approved governance frameworks and, based on a mixed-method study involving 140 professionals and interviews with 10 executives, identify a “governance drift zone” in which formal policies exist but fail to constrain actual employee practices. Their analysis is particularly relevant because it frames Shadow AI as a socio-technical governance failure, rather than simply as a violation of IT policy. AI adoption can therefore expose gaps between what an organisation formally permits and what employees actually do in pursuit of productivity and efficiency.
Puthal et al. (2025) similarly demonstrate that Shadow AI expands the organisational threat surface. Their review identifies risks including data and security breaches, unauthorised processing of sensitive information, compliance problems, vulnerabilities in unmonitored AI systems, model poisoning and data leakage. Importantly, the authors also recognise that AI can contribute positively to cybersecurity, for example by supporting threat detection and response. The governance challenge is therefore not whether AI should be used, but whether its use can be brought within an appropriate security and accountability framework.
Sebastian's (2026) Digital Shadow AI Risk Theory (DART) provides an even closer theoretical connection to the MSM findings. His framework identifies six interrelated dimensions of Shadow AI risk: unintentional disclosure, the trust–dependence paradox, data-sovereignty conflict, knowledge dilution, the ethical black-box problem and organisational feedback loops. Based on three cross-industry survey waves, the study finds persistent gaps in employee awareness, training and organisational controls, while perceived efficiency increases the propensity to use AI and share information with such systems. This is particularly significant for a data-centric security strategy because it suggests that the disclosure problem is partly behavioural: the more useful AI becomes in everyday knowledge work, the greater the incentive to provide it with organisational information.
This creates an important connection between data classification and AI governance. If data is the primary object of protection, then an organisation must not only know what data it holds and how sensitive that data is, but also understand where employees are permitted to process that data and under what conditions. Data classification therefore becomes an input to AI governance. Confidential or regulated information may require restrictions on which AI services can process it, what retention arrangements apply, whether data can be used for model training, and what human review is required before AI-generated outputs influence business decisions. In this sense, Shadow AI reinforces rather than displaces the data-centric security model developed earlier in the paper.
The MSM report's recommended response is therefore significant because it does not rely exclusively on prohibition. It identifies approved AI tools, employee training, data classification, technical safeguards against data leakage and AI-specific security-operations playbooks as elements of effective governance. This approach is consistent with Silic, Silic and Kind-Trüller's (2025) recommendation for mechanisms such as AI tool registries, role-specific training, internal audits and escalation procedures.
The emphasis on human responsibility is also consistent with Shneiderman's (2020) Human-Centered Artificial Intelligence framework. Rather than treating automation and human control as mutually exclusive alternatives, Shneiderman argues for systems that combine high levels of human control with high levels of computer automation, while avoiding the risks associated with excessive reliance on either humans or machines. The objective is consequently not to eliminate automation, but to design its use so that reliability, safety, trustworthiness and human responsibility are maintained.
Shadow AI can therefore be understood as a new form of organisational boundary problem. The issue is no longer simply whether an organisation can secure its own infrastructure or govern its suppliers. It must also govern how employees interact with external computational systems that can receive, transform and potentially retain organisational knowledge. This makes AI governance inseparable from data governance, cybersecurity, human behaviour and organisational accountability.
The emerging principle is consequently controlled enablement rather than prohibition. Effective governance should make legitimate AI use easier and safer, while establishing clear boundaries around sensitive data, human accountability, approved tools and unacceptable use. In this sense, the challenge posed by Shadow AI is not to restore an organisational boundary that no longer exists, but to establish governable conditions for operating across that boundary.
This extends the paper's cumulative argument: data-centric security determines what must be protected; ecosystem security determines where organisational exposure and dependency reside; and AI governance determines how emerging human–machine interactions can be controlled without preventing the productive use of AI.
This also strengthens the transition into the paper's final argument about resilience: because organisations cannot realistically eliminate every unauthorised behaviour, external dependency or technological failure, effective security increasingly depends on the ability to detect, contain, recover from and learn from inevitable control failures.
7. Data Security as a Socio-Technical Governance Problem
Taken together, the findings indicate that data security can no longer be conceptualised as a purely technical discipline. Data security increasingly cuts across data, technology, organisational structures and the wider ecosystem in which the organisation operates, requiring attention to both technical controls and organisational processes (Hennessy et al., 2009; Neri, Niccolini and Virili, 2025; Hilger, 2026). These dimensions should not be understood as separate layers of security. Rather, they form an interdependent system in which the effectiveness of a control at one level depends on the behaviour, configuration and governance of the others (Neri, Niccolini and Virili, 2025; Hilger, 2026).
At the data level, the central challenges concern understanding what information the organisation holds, how sensitive it is, where it is located and how it moves across organisational and technological boundaries. This reinforces the data-centric perspective developed earlier in the paper: effective protection begins with visibility and classification, because organisations cannot apply proportionate controls to information that they cannot adequately identify, classify or trace (Hennessy et al., 2009; Ali et al., 2023). Data classification is therefore not simply an administrative exercise but a foundation for applying differentiated security and privacy controls according to the sensitivity and context of the information (Ali et al., 2023).
At the technology level, these requirements are translated into mechanisms such as cloud security, identity and access management, encryption, data-loss prevention, automated discovery and classification, and controls over software and AI dependencies (Ali et al., 2023; Alhidaifi, Asghar and Ansari, 2024). However, technological capability does not automatically produce effective security. A technically sophisticated control environment can still be undermined by inappropriate configuration, excessive privileges, insecure dependencies or the use of technologies outside established governance arrangements (Alhidaifi, Asghar and Ansari, 2024; Hilger, 2026). The increasing dependence on cloud services and external software also means that security controls must account for dependencies beyond the immediate organisational infrastructure (Boyson, 2014; Hilger, 2026).
The organisational level introduces a further set of dependencies. Security awareness, formal processes, governance roles and accountability mechanisms determine whether technical controls are implemented and used as intended (Neri, Niccolini and Virili, 2025; Shneiderman, 2020). The MSM findings are particularly relevant here: the relatively widespread presence of security-awareness measures and defined processes suggests that many organisations have already institutionalised aspects of security governance (MSM Research AG, 2026). Yet the maturity gaps identified elsewhere in the report demonstrate that the existence of policies and responsibilities does not necessarily establish effective control (MSM Research AG, 2026). Organisational capability depends on whether governance arrangements are translated into consistent operational behaviour, monitoring and accountability (Neri, Niccolini and Virili, 2025).
The ecosystem level extends the problem beyond the formal organisational boundary. Cloud providers, SaaS platforms, managed service providers, software suppliers and other external dependencies can influence the confidentiality, integrity and availability of organisational data and critical processes (Boyson, 2014; Alhidaifi, Asghar and Ansari, 2024). These relationships also introduce legal, regulatory and geopolitical dimensions, particularly where data is processed across jurisdictions. Consequently, security cannot be established solely by securing assets that the organisation directly owns or controls. It must also account for the dependencies through which data, software, services and business processes increasingly operate (Boyson, 2014; Neri, Niccolini and Virili, 2025).
The critical point is that these levels are mutually dependent. A data-classification system provides limited protection if employees do not apply the resulting handling requirements (Ali et al., 2023; Hennessy et al., 2009). Employee awareness is insufficient if cloud configurations undermine access controls or expose sensitive information (Alhidaifi, Asghar and Ansari, 2024). Cloud security controls may still be inadequate if a supplier introduces compromised software dependencies, while supplier assurance provides limited resilience if business-continuity arrangements do not account for the potential loss or disruption of a critical provider (Boyson, 2014; Shingleton and Paté-Cornell, 2026). Similarly, formal AI policies may have little practical effect if employees can circumvent them through consumer-facing AI services, creating risks of unauthorised data disclosure, privacy breaches and governance failures (Puthal et al., 2025; Sebastian, 2026; Silic, Silic and Kind-Trüller, 2025). These are not isolated control failures; they demonstrate how weaknesses can propagate across technical, human, organisational and ecosystem boundaries (Neri, Niccolini and Virili, 2025; Hilger, 2026).
This interdependence is what makes data security fundamentally a socio-technical governance problem. Security outcomes emerge from the interaction of technologies, people, organisational processes, governance arrangements and external dependencies (Neri, Niccolini and Virili, 2025; Hilger, 2026). Consequently, strengthening one component without considering its relationship with the others can produce a false sense of security. A highly mature technical control environment, for example, may coexist with significant organisational or ecosystem vulnerabilities (Alhidaifi, Asghar and Ansari, 2024; Neri, Niccolini and Virili, 2025).
Neri, Niccolini and Virili (2025) provide an important theoretical foundation for this interpretation. Their systematic review brings together organisational resilience and cyber resilience and argues for an integrated understanding of how organisations prepare for, respond to and adapt to cyber-related disruption. A central implication is that human vulnerabilities and organisational characteristics should not be treated as secondary considerations added to an otherwise technical cybersecurity model. They are integral to understanding how cyber resilience operates at the organisational level (Neri, Niccolini and Virili, 2025).
The MSM findings are highly consistent with this proposition. The report's combination of data-classification requirements, cloud and software dependencies, employee awareness, governance structures, third-party risks and emerging AI risks illustrates that no single control domain is sufficient in isolation (MSM Research AG, 2026). Data security therefore increasingly depends on the organisation's ability to coordinate multiple forms of control across interacting socio-technical systems (Neri, Niccolini and Virili, 2025; Hilger, 2026).
This perspective also changes how security maturity should be interpreted. Maturity should not simply describe the number or sophistication of controls an organisation possesses. It should reflect the extent to which those controls are integrated, consistently applied, monitored and adapted across the organisation and its ecosystem (Alhidaifi, Asghar and Ansari, 2024; Neri, Niccolini and Virili, 2025; Shingleton and Paté-Cornell, 2026). In other words, the relevant question is not only whether a control exists, but whether the wider socio-technical system enables that control to produce the intended security outcome (Hilger, 2026).
This provides a direct connection to the paper's broader argument about cyber resilience. If security depends on interconnected technical, organisational and ecosystem conditions, then some control failures will inevitably occur. The objective of governance is therefore not to construct a perfectly controlled environment, but to develop an organisation capable of understanding its dependencies, detecting deviations, containing failures, maintaining critical operations and learning from disruption (Dupont et al., 2023; Hilger, 2026; Shingleton and Paté-Cornell, 2026). Data security consequently becomes part of a broader organisational capability for cyber resilience rather than a discrete technical function (Neri, Niccolini and Virili, 2025; Dupont et al., 2023).
8. Critical Evaluation of the MSM Study
The MSM Research report makes a valuable contribution to understanding the contemporary state of data security in Swiss organisations. Its principal strength is the provision of current empirical evidence on how organisations perceive and operationalise data-security priorities, including areas such as data classification, cloud security, governance, supply-chain risk and artificial intelligence (MSM Research AG, 2026). Particularly valuable is the report's juxtaposition of relatively high self-assessed security maturity with evidence of uneven implementation across specific control areas. This creates an important empirical basis for questioning whether perceived maturity necessarily corresponds to demonstrated security capability.
At the same time, the findings require careful methodological interpretation. The first and most important limitation concerns the self-reported nature of the assessment. The maturity results primarily capture how participating organisations assess their own security posture rather than providing an independently validated measurement of actual security capability. This distinction is important because maturity assessments are themselves subject to human judgement. Research examining practitioners' ability to assess information-security control maturity has found substantial variation in assessment accuracy and evidence of overly optimistic self-perception (Schmitz et al., 2021). This suggests that self-assessment can provide useful information about how organisations perceive their security posture while remaining an imperfect proxy for objectively demonstrated capability.
The distinction between perceived and demonstrated maturity is particularly relevant to the MSM findings. The report identifies a relatively high level of self-assessed maturity while simultaneously identifying substantial gaps in areas such as systematic third-party and supply-chain risk management, regulatory implementation and verification, and cloud-security capabilities (MSM Research AG, 2026). These findings should not necessarily be interpreted as evidence that respondents were simply overestimating their capabilities. Rather, they demonstrate that maturity is difficult to measure through perception alone, particularly when security extends across technologies, organisational processes and external dependencies. Contemporary research similarly treats cybersecurity maturity as a multidimensional construct involving multiple dimensions and factors rather than reliance on a single maturity indicator (Büyüközkan and Güler, 2025).
A second limitation concerns the sample size and representativeness of the study. The survey covers 84 Swiss companies, which provides a useful empirical snapshot but does not, by itself, establish that the results are representative of Swiss organisations as a whole (MSM Research AG, 2026). The composition of the sample matters because security priorities and capabilities may vary substantially according to organisational size, sector, regulatory exposure, technological dependence and the complexity of the organisation's ecosystem. Respondent characteristics may also influence the results: a CISO, CIO, data-protection officer, risk manager or general business respondent may have materially different perceptions of organisational security maturity. The findings should therefore be interpreted primarily as evidence of patterns among the surveyed organisations rather than as statistically generalisable estimates for the entire Swiss business population.
A third methodological consideration concerns the structure of the survey questions. Multiple responses were possible for most questions, meaning that percentages generally represent the proportion of respondents selecting a particular measure or priority rather than mutually exclusive categories (MSM Research AG, 2026). Consequently, the results should not be interpreted as a ranking in which one security measure necessarily replaces another. Instead, the survey captures the coexistence of multiple priorities within organisational security strategies. This interpretation is consistent with the multidimensional treatment of cybersecurity maturity in the academic literature, where different technical, organisational and contextual factors contribute to overall maturity rather than forming a single linear hierarchy (Büyüközkan and Güler, 2025).
A fourth limitation concerns the cross-sectional character of the study. The MSM report provides a snapshot of organisational security practices at a particular point in time (MSM Research AG, 2026). This is particularly relevant in a field characterised by rapidly changing cloud architectures, software dependencies, regulatory requirements and AI capabilities. A cross-sectional survey can identify the presence of particular practices and perceptions, but it cannot establish how security maturity develops over time or whether particular investments actually produce improvements in resilience. Nor can it establish causal relationships between organisational characteristics and security outcomes. The distinction is important because cybersecurity maturity is increasingly understood as a capability involving multiple dimensions of organisational readiness rather than simply a static inventory of implemented controls (Büyüközkan and Güler, 2025; Neri, Niccolini and Virili, 2025).
A fifth consideration is the status of the MSM report as an industry research publication rather than a peer-reviewed academic study. This does not diminish its empirical value. Industry research can provide timely evidence on emerging practices and organisational priorities that may not yet be captured in academic datasets. However, its methodological role is different from that of peer-reviewed research. The MSM report is most appropriately used in this paper as the empirical anchor for understanding current Swiss organisational practice, while the peer-reviewed literature provides the conceptual frameworks and critical perspectives through which those observations can be interpreted.
These limitations suggest that the strongest analytical approach is not to treat the MSM findings as independently conclusive, but to examine their convergence with established and emerging academic research. The apparent tension between high perceived maturity and uneven implementation is consistent with research questioning the reliability of maturity assessments based solely on human judgement (Schmitz et al., 2021). Likewise, the report's emphasis on supply-chain dependencies corresponds with the treatment of cybersecurity as an ecosystem and supply-chain problem (Boyson, 2014). Its movement from prevention toward recovery and adaptation is consistent with the cyber-resilience literature, which emphasises organisational capacities to prepare for, withstand, respond to and adapt to disruption (Dupont et al., 2023; Neri, Niccolini and Virili, 2025; Hilger, 2026). Its treatment of Shadow AI similarly reflects emerging research on the socio-technical, privacy and governance risks associated with uncontrolled organisational use of AI tools (Puthal et al., 2025; Sebastian, 2026; Silic, Silic and Kind-Trüller, 2025).
This convergence is important because it strengthens the interpretation without overstating what the MSM dataset can demonstrate. The academic literature does not independently validate every empirical percentage reported by MSM, nor does the MSM study empirically establish the theoretical propositions developed in the peer-reviewed literature. Rather, the two forms of evidence perform different functions. MSM provides contemporary empirical evidence of what Swiss organisations report doing and prioritising, while the academic literature provides the theoretical and methodological basis for understanding why these patterns matter and how their limitations should be interpreted (MSM Research AG, 2026; Neri, Niccolini and Virili, 2025; Büyüközkan and Güler, 2025).
The most defensible conclusion is therefore that the MSM study should be viewed as a valuable empirical indicator rather than a definitive measurement of Swiss cybersecurity maturity. Its significance lies particularly in the tensions it reveals: between perceived and demonstrated maturity, internal security and ecosystem exposure, technological capability and organisational governance, and prevention and resilience. These tensions provide a productive basis for the paper's broader argument that contemporary data security is evolving from a collection of technical controls into an organisational capability spanning data, technology, people, governance and external dependencies (Neri, Niccolini and Virili, 2025; Hilger, 2026).
Accordingly, the limitations of the MSM study do not invalidate its findings. Instead, they reinforce one of the paper's central conclusions: security maturity cannot be adequately understood by asking only whether organisations have implemented particular controls or whether they consider themselves mature. It must also be assessed in terms of how effectively those controls operate across organisational boundaries, how they perform under disruption, and how organisations adapt when assumptions and controls fail (Schmitz et al., 2021; Dupont et al., 2023; Hilger, 2026; Shingleton and Paté-Cornell, 2026). This is precisely where the transition from cybersecurity maturity to organisational cyber resilience becomes analytically significant (Neri, Niccolini and Virili, 2025; Hilger, 2026).
9. Implications for Management
The combined evidence has several implications for management. The central implication is that cybersecurity should no longer be managed primarily as a technical control programme. Instead, management should treat data security as an organisational capability that connects information visibility, technology, people, suppliers, AI use and business continuity (Neri, Niccolini and Virili, 2025; Hilger, 2026). The following five priorities translate the findings of the MSM study and the supporting academic literature into practical management requirements.
9.1 Establish Data Visibility Before Attempting Comprehensive Protection
Organisations cannot adequately protect information that they cannot identify, classify or trace. Data discovery and classification should therefore be treated as foundational governance capabilities rather than merely as technical security functions. The objective is not simply to create an inventory of data, but to establish sufficient visibility to determine what information is sensitive, where it resides, how it moves, who can access it and which protection requirements apply (Hennessy et al., 2009; Ali et al., 2023).
This provides the foundation for proportionate security controls. Without reliable visibility, organisations may apply strong controls to some assets while overlooking others, particularly where data is distributed across cloud services, SaaS platforms, employee devices and external providers (Ali et al., 2023; Alhidaifi, Asghar and Ansari, 2024). The data-centric approach developed earlier in this paper therefore has a direct management implication: visibility should precede protection. Data classification, discovery and flow analysis should inform access controls, encryption, data-loss prevention, retention, residency requirements and restrictions on AI processing (Hennessy et al., 2009; Ali et al., 2023; Sebastian, 2026).
The management objective should therefore be to establish a sufficiently accurate understanding of the organisation's information landscape before attempting to optimise individual security controls. This also enables security requirements to be differentiated according to data sensitivity and context rather than applied uniformly across all information assets (Ali et al., 2023).
9.2 Treat Suppliers as Part of the Security Architecture
The organisation's effective security boundary should reflect its critical dependency network rather than its legal or physical boundaries. Cloud providers, SaaS platforms, managed service providers, software suppliers and other external partners can influence the confidentiality, integrity and availability of organisational data and business processes (Boyson, 2014; Alhidaifi, Asghar and Ansari, 2024). Supplier assurance should consequently extend beyond contractual security clauses to include dependency visibility, software provenance, security testing, incident coordination and recovery planning (Boyson, 2014).
This requires management to ask not only whether a supplier satisfies predefined security requirements, but also what would happen if that supplier were compromised, unavailable or unable to provide a critical service. Cyber-resilience research reinforces the importance of examining ecosystem-level dependencies rather than evaluating individual technical components in isolation (Hilger, 2026; Neri, Niccolini and Virili, 2025). Hilger (2026), in particular, adopts a systemic perspective in which vendors, cloud providers and other ecosystem actors form part of the environment within which organisational cyber-resilience must be assessed.
Supplier governance should therefore become part of the organisation's broader security architecture. Procurement, enterprise architecture, cybersecurity, business continuity, legal and risk functions should share responsibility for identifying critical dependencies and determining how those dependencies should be monitored and managed. The objective is to move from supplier assurance to dependency resilience (Boyson, 2014; Hilger, 2026).
This also implies that supplier risk should be assessed according to business criticality rather than treated as a uniform procurement requirement. The more deeply a provider is embedded in critical data flows or business processes, the greater the need for continuous assurance, contingency planning and recovery arrangements.
9.3 Measure Security Capability Independently
The maturity paradox identified in the MSM study demonstrates the limitations of relying exclusively on self-assessment. An organisation may possess policies, procedures and formally assigned responsibilities without being able to demonstrate that those controls function effectively under realistic conditions (MSM Research AG, 2026). Management should therefore distinguish between documented control maturity and demonstrated operational capability.
Independent assessments can provide an important corrective. Penetration testing, red-team exercises, technical control validation, supplier testing and realistic crisis simulations can reveal weaknesses that questionnaire-based assessments may not identify. Such testing should not be treated as an occasional compliance exercise, but as a mechanism for generating evidence about whether security capabilities work as intended. This is particularly important given evidence that practitioners' assessments of information-security control maturity can vary substantially in accuracy and may be affected by overly optimistic self-perceptions (Schmitz et al., 2021).
The broader cybersecurity-maturity literature also supports a multidimensional approach to assessment. Rather than reducing maturity to the presence of particular controls, maturity models increasingly consider multiple organisational and technical dimensions and the extent to which capabilities operate together (Büyüközkan and Güler, 2025). Similarly, cyber-resilience research emphasises organisational capacities to prepare for, respond to and adapt to disruption rather than focusing exclusively on preventive controls (Neri, Niccolini and Virili, 2025; Hilger, 2026).
Management should therefore ask a more demanding question than whether a control has been implemented: Can the organisation demonstrate that the control works when it matters? This shifts maturity assessment from policy presence toward evidence, testing and observable performance (Schmitz et al., 2021; Shingleton and Paté-Cornell, 2026).
9.4 Govern AI Through Practical Guardrails
The emergence of Shadow AI demonstrates that AI governance cannot be based exclusively on prohibition or employee compliance. Employees may adopt AI because it provides genuine productivity benefits, while formal governance mechanisms develop more slowly. Research on Shadow AI identifies precisely this tension between organisational controls and actual employee behaviour, including risks associated with data disclosure, privacy and inadequate governance (Silic, Silic and Kind-Trüller, 2025; Puthal et al., 2025; Sebastian, 2026).
Effective AI governance should therefore establish practical guardrails for legitimate use. These should include approved AI tools, clear rules for the processing of different data classifications, employee training, monitoring for inappropriate data disclosure, defined accountability and escalation mechanisms, and security-operations procedures for AI-specific incidents (Puthal et al., 2025; Sebastian, 2026). The objective should be to make secure AI use easier than insecure workarounds.
This approach also connects AI governance directly to the data-centric security model. An organisation should not ask only whether an AI tool is approved; it should determine what categories of information the tool is permitted to process, under what conditions, with what retention and sovereignty implications, and what level of human verification is required for consequential outputs (Hennessy et al., 2009; Sebastian, 2026). A data-centric approach is particularly important because the security implications of AI adoption depend not only on the technology itself but also on the type and sensitivity of information that employees provide to it.
The management challenge is therefore one of controlled enablement. Organisations that respond to Shadow AI solely through prohibition may drive usage further outside formal visibility and governance, while unrestricted adoption can expose sensitive information and create new accountability and compliance risks (Silic, Silic and Kind-Trüller, 2025; Sebastian, 2026). Effective governance must instead create a controlled environment in which the productivity benefits of AI can be realised without abandoning security, transparency and human responsibility. This is also consistent with human-centred approaches to AI that emphasise reliability, safety, trustworthiness and meaningful human responsibility (Shneiderman, 2020).
9.5 Design for Recovery Rather Than Assuming Prevention
The final and perhaps most important implication is that organisations should design explicitly for the possibility that preventive controls will fail. The MSM report's “Assume Breach” principle provides a practical management starting point (MSM Research AG, 2026). Organisations should know which business processes are critical, which dependencies those processes rely upon, what level of disruption is tolerable, how quickly critical capabilities must be restored and which decisions must be made during a crisis.
This represents a fundamental change in management perspective. Traditional security asks how an organisation can prevent compromise; resilience-oriented management additionally asks how the organisation will continue operating when prevention fails. Shingleton and Paté-Cornell (2026) emphasise this distinction by examining cybersecurity controls in relation to cyber resilience and the management of potentially severe cyber losses. More broadly, cyber-resilience research conceptualises resilience in terms of the ability to prepare for, withstand, respond to and adapt to disruption (Dupont et al., 2023; Neri, Niccolini and Virili, 2025; Hilger, 2026).
Recovery planning should consequently incorporate technological, organisational and ecosystem dependencies. Restoring a server or recovering data does not necessarily restore the business if authentication services, suppliers, operational systems, communications or other dependencies remain unavailable. A systemic approach to cyber resilience therefore requires organisations to understand how critical functions depend upon interconnected technical and non-technical capabilities (Hilger, 2026; Neri, Niccolini and Virili, 2025).
Management should therefore integrate cyber recovery into business continuity and crisis management rather than treating it as a specialist cybersecurity activity. Critical processes should have defined recovery objectives, tested recovery procedures, identified decision-makers and rehearsed escalation paths. Exercises should also incorporate external dependencies, because a critical supplier's failure may constrain recovery even when the organisation's own systems remain technically recoverable (Boyson, 2014; Hilger, 2026).
Taken together, these five priorities suggest a broader management model for data security. Visibility establishes what must be protected; ecosystem governance establishes where dependencies and exposure reside; independent assurance establishes whether controls actually work; AI guardrails govern emerging forms of human–machine interaction; and recovery planning establishes what the organisation can do when those controls or dependencies fail.
The management implication is therefore not simply to invest in more cybersecurity controls. It is to build an organisation that can see its exposure, govern its dependencies, test its assumptions, control emerging technologies and continue operating when security controls inevitably prove imperfect (Neri, Niccolini and Virili, 2025; Hilger, 2026). This represents the practical transition from cybersecurity as a technical function to cyber resilience as an organisational management capability (Dupont et al., 2023; Neri, Niccolini and Virili, 2025; Hilger, 2026).
10. Conclusion
This paper has examined the evolution of organisational data security through the MSM Research study of 84 Swiss companies and a complementary body of peer-reviewed research. The analysis suggests that contemporary data security is undergoing a fundamental transition. The central issue is no longer simply whether an organisation has implemented appropriate technical controls, but whether it can understand, govern and remain resilient across an increasingly interconnected digital environment.
The first transformation is the movement from network-centric to data-centric security. Cloud computing, distributed infrastructures and increasingly complex digital environments weaken the assumption that a clearly defined network perimeter can provide the primary basis for protection. Data must instead become a central object of governance. Organisations need sufficient visibility to identify what information they hold, classify its sensitivity, understand where it resides and determine how it moves across organisational and technological boundaries. Data discovery and classification are therefore not merely supporting technologies; they are prerequisites for proportionate security governance.
The second transformation is the movement from enterprise security to ecosystem security. Organisations increasingly depend on cloud providers, SaaS platforms, managed services, software components and other external relationships. As a result, the effective security boundary extends beyond assets directly controlled by the organisation. The MSM finding that only a minority of surveyed organisations systematically manage third-party and supply-chain risks is therefore particularly significant. It illustrates a broader maturity gap between internal security governance and the management of external dependencies. Security must increasingly be understood as a property of an interconnected ecosystem rather than of the focal organisation alone.
The third transformation is the movement from preventive cybersecurity towards cyber resilience. The MSM study reveals an important maturity paradox: organisations may report relatively high levels of security maturity while simultaneously demonstrating gaps in supply-chain governance, cloud-security practices and systematic regulatory assurance. This should not be interpreted simply as evidence of inaccurate self-assessment. Rather, it demonstrates the difficulty of measuring security capability in an environment where risk is distributed across technologies, people, organisations and external dependencies. Recent cyber-resilience research similarly argues that prevention alone is insufficient and that organisations must develop capabilities to prepare, absorb disruption, recover and adapt.
The discussion of Shadow AI makes these transformations particularly visible. AI introduces a new boundary problem because employees can increasingly interact directly with external computational systems that may process organisational information outside established governance arrangements. The challenge is therefore not simply to classify AI as authorised or unauthorised technology. It is to establish conditions under which AI can be used productively while maintaining appropriate controls over sensitive data, accountability, human oversight and organisational risk. This supports the principle of controlled enablement rather than prohibition: governance should make legitimate AI use safer and easier while creating meaningful boundaries around data and decision-making.
Taken together, these findings demonstrate that data security is fundamentally a socio-technical governance problem. Technical controls cannot be separated from employee behaviour, organisational processes, management decisions and external dependencies. A classification system is only effective when people follow it; identity controls are only effective when infrastructure is correctly configured; supplier assurance is insufficient if critical dependencies cannot be replaced or recovered from; and AI policies are ineffective if actual employee behaviour occurs outside organisational visibility. Security outcomes therefore emerge from the interaction of technical, organisational, human and ecosystem capabilities.
The critical evaluation of the MSM study also highlights an important methodological implication. Its findings should not be interpreted as a definitive measurement of cybersecurity maturity across Switzerland. The study is based on self-reported assessments from 84 companies, and its cross-sectional design does not independently validate whether reported controls operate effectively under stress. Nevertheless, these limitations do not remove its value. The study provides a timely empirical snapshot whose importance is strengthened by its convergence with peer-reviewed research on data-centric security, cyber supply-chain risk, organisational resilience and Shadow AI. Its greatest analytical value lies in the tensions it reveals between aspiration and implementation, internal maturity and ecosystem exposure, technological capability and governance, and prevention and resilience.
The resulting management agenda is therefore broader than simply increasing investment in cybersecurity controls. Organisations should establish data visibility before attempting comprehensive protection; treat critical suppliers and software dependencies as components of the security architecture; validate security capability through independent testing and realistic exercises; govern AI through practical and enforceable guardrails; and design explicitly for recovery when preventive controls fail. These priorities correspond directly to the three transformations identified in the paper and provide a practical pathway from security control to organisational capability.
Ultimately, the central argument of this paper is that security maturity should no longer be understood primarily as the possession of controls. A mature organisation is one that can understand its information and dependencies, govern how they are used, test whether its controls actually work, and maintain critical functions when those controls or dependencies fail. Cyber resilience therefore represents not the abandonment of cybersecurity, but its organisational extension: prevention remains necessary, but it must be complemented by the capacity to withstand, recover and adapt. Recent research similarly frames cyber resilience as a mission-level and ecosystem-level capability rather than a purely technical property.
The broader transition can consequently be expressed in three questions: data-centric security asks what must be protected; ecosystem security asks where exposure and dependency reside; and cyber resilience asks what the organisation can do when protection fails. The strategic objective is therefore not to create an impenetrable digital fortress, but to build an organisation that is visible enough to understand its exposure, governed enough to control its dependencies, adaptable enough to manage emerging technologies, and resilient enough to continue functioning when inevitable failures occur.
References
Alhidaifi, S.M., Asghar, M.R. and Ansari, I.S. (2024) ‘A survey on cyber resilience: key strategies, research challenges, and future directions’, ACM Computing Surveys, 56(8), Article 196. doi: 10.1145/3649218.
Ali, M., Jung, L.T., Sodhro, A.H., Laghari, A.A., Belhaouari, S.B. and Gillani, Z. (2023) ‘A confidentiality-based data Classification-as-a-Service (C2aaS) for cloud security’, Alexandria Engineering Journal, 64, pp. 749–760. doi: 10.1016/j.aej.2022.10.056.
Boyson, S. (2014) ‘Cyber supply chain risk management: revolutionizing the strategic control of critical IT systems’, Technovation, 34(7), pp. 342–353. doi: 10.1016/j.technovation.2014.02.001.
Büyüközkan, G. and Güler, M. (2025) ‘Cybersecurity maturity model: Systematic literature review and a proposed model’, Technological Forecasting and Social Change, 213, 123996
Dupont, B., Shearing, C., Bernier, M., & Leukfeldt, E. R. (2023). The tensions of cyber-resilience: From sensemaking to practice. Computers & Security, 132, 103372.
Hennessy, S.D., Lauer, G.D., Zunic, N. and Gerber, B. (2009) ‘Data-centric security: integrating data privacy and data security’, IBM Journal of Research and Development, 53(2). doi: 10.1147/JRD.2009.5429044.
Hilger, R. P. (2026). From cybersecurity to cyber resilience: A systemic and scalable approach for improving resilience and adaptive capacity. Journal of Cybersecurity,
MSM Research AG (2026) Data Security in Switzerland: Between Aspiration and Reality: Effective Protection Starts with a Data-Centric Security Strategy. Schaffhausen: MSM Research AG. September 2026.
Neri, M., Niccolini, F. and Virili, F. (2025) ‘Organizational cyber resilience: toward an integrative conceptual framework’, Management Review Quarterly, 76, pp. 789–840. doi: 10.1007/s11301-025-00496-7.
Puthal, D., Mishra, A.K., Mohanty, S.P., Longo, A. and Yeun, C.Y. (2025) ‘Shadow AI: cyber security implications, opportunities and challenges in the unseen frontier’, SN Computer Science, 6, Article 405.
Schmitz, C., Schmid, M., Harborth, D. and Pape, S. (2021) ‘Maturity level assessments of information security controls: An empirical analysis of practitioners’ assessment capabilities’, Computers & Security, 108
Sebastian, G. (2026) ‘Digital shadow AI risk theory (DART): a framework for managing data disclosure and privacy risks of AI tools at work’, Technological Forecasting and Social Change, 229, Article 124697. doi: 10.1016/j.techfore.2026.124697.
Shneiderman, B. (2020) ‘Human-centered artificial intelligence: reliable, safe & trustworthy’, International Journal of Human–Computer Interaction, 36(6), pp. 495–504. doi: 10.1080/10447318.2020.1741118.
Silic, M. (2025) ‘From Shadow IT to Shadow AI–threats, risks and opportunities for organizations’, Strategic Change. doi: 10.1002/jsc.2682.
Silic, M., Silic, D., & Kind-Trüller, K. (2025). From Shadow IT to Shadow AI—Threats, Risks and Opportunities for Organizations. Strategic Change, 1–16.
Shingleton, J. and Paté-Cornell, E. (2026) ‘Cyber resilience: management with cybersecurity controls’, Risk Analysis, 46
Contact
Reach out via email for inquiries.
Subscribe to newsletter
info@grcadvisory.ch
© 2025. All rights reserved.