This research highlights the increasing importance of cyber resilience as organisations face evolving and complex cyber threats. Examining global trends identifies significant gaps in resilience practices, particularly in fos- tering a proactive culture and improving cross-organisational collaboration. While larger organisations demonstrate stronger governance and strategic alignment, smaller entities often struggle with resource constraints and im- plementation challenges. The study emphasises the critical role of leadership, accountability, and integrating human-centric approaches alongside techno- logical advancements. Future studies should focus on validating an organisation’s application of the suggested Cyber Resilience Top 3 framework, investigating interview instru- ments in comparison with surveys and self-assessments when measuring cyber resilience, and utilising the data collected to investigate particular regions or industries. Other suggestions for future research include investigating how challenges in cyber resilience change beyond 2024 and dedicated research into improving cyber resilient cultures, communication, and the adaptation of cyber resilient paradigms within organisations. This research provides a framework modeled on OWASPS Top 10 lists in the form of The Cyber Resilience Top 3, enabling organisations to understand the current global state of cyber resilience and make targeted and educated improvements to their cyber resilience postures. This research makes three significant contributions to the discourse on organisational cyber resilience and its improvement. First, it introduces an open-source online research companion, available at
https://cyberresilience.dev/, which provides an accessible platform for explaining the key concepts of the research and their practical applications. By translating complex findings into clear, actionable insights, this compan- ion bridges the gap between academic theory and organisational practice, em- powering stakeholders to enhance their cyber resilience strategies effectively. Its open-source nature ensures broad accessibility, encourages community collaboration, and allows for continuous updates to maintain relevance in a rapidly evolving field. Second, the research presents a comprehensive framework that explores the current Cyber Resilience Top 3 challenges and offers state-of-the-art rec- ommendations for addressing these areas. This framework, as shown in Fig- ure 31, provides organisations with a structured approach to prioritizing 81 critical resilience investments, synthesizing survey data, expert insights, and best practices to guide impactful decision-making. By focusing on actionable strategies tailored to key challenges, the framework not only supports prac- titioners in addressing immediate needs but also contributes to the academic discourse by offering a model for further refinement and application across diverse contexts. Lastly, the research makes its data publicly available as an open-source resource at
https://github.com/adameddarcy/cyberresilience.dev. This open data initiative fosters transparency, reproducibility, and collaboration, enabling future researchers to validate findings, explore new questions, and apply advanced methodologies for additional insights. Practitioners can leverage the dataset to benchmark their resilience efforts against broader industry trends, while the cybersecurity community as a whole benefits from a culture of shared knowledge and cooperative progress. Together, these contributions provide meaningful tools, frameworks, and resources that not only advance theoretical understanding but also deliver actionable benefits to organisations striving to enhance their cyber resilience. In conclusion, cultivating a culture of cyber resilience is essential for fos- tering a proactive, organisation-wide approach to cybersecurity, where collec- tive awareness, accountability, and readiness become ingrained. Embracing the “Assume Breach” mentality guides decision-makers in prioritising in- vestments, adopting secure architectures, and implementing operational best practices, reducing overreliance on potentially compromised systems. Finally, effective communication is the most critical cybersecurity skill, emphasising that human collaboration and information-sharing are the cornerstones of defending against ever-evolving cyber threats.