Key takeaways
-
Cyber security tools are only as resilient as the infrastructure they depend on.
-
Ageing or unsupported hardware can create hidden security and recovery risks.
-
Disaster recovery testing should reflect realistic recovery volumes, workloads and time pressures.
-
Infrastructure readiness should be assessed as part of the wider cyber resilience strategy.
-
Lifecycle status, support windows and performance benchmarks provide a practical starting point for identifying resilience gaps.
Why cyber security infrastructure matters to resilience
Ask most IT leaders whether their organisation has invested in cyber security and the answer is yes. Detection tools, backup solutions, incident response retainers, employee awareness training. The budgets are real and the intent is genuine. Every one of those investments ultimately depends on the cyber security infrastructure underneath it.
But there is a question that rarely gets asked in the same conversation: is the infrastructure underneath all of that investment capable of performing when it is actually needed?
For many organisations, the answer is less clear than they would like.
Cyber security investment and cyber resilience are not the same thing. One is about preventing incidents. The other is about surviving them. And the difference often comes down to infrastructure.
The assumption most organisations are making
There is an implicit assumption in most cyber resilience frameworks: that the infrastructure is adequate. The focus goes on the processes, the tooling, the people. Infrastructure is treated as a given.
This assumption is reasonable if your estate is current. It becomes a problem when key components are ageing, unsupported, or were simply never designed for the conditions a modern cyber incident creates.
And because infrastructure gaps don't generate alerts, they stay invisible. Your monitoring tools won't flag a server that's approaching end of support. Your backup software won't warn you that your storage array's restore throughput is insufficient for a full recovery under incident conditions.
The gap only becomes visible when you need to rely on it. This is why Celerity's approach to data resilience considers recovery capability alongside the systems and infrastructure that support it.
What the data is telling us
A 50% increase in highly significant cyber incidents was reported by the NCSC in August 2025. Many involved organisations that had invested in security tools but hadn't stress-tested the infrastructure underneath them.
In 2025, a number of high-profile UK organisations suffered cyber incidents that tested their infrastructure far beyond normal operating conditions. Some faced weeks of disruption. Others saw factory shutdowns and significant revenue impact.
In most cases, these weren't organisations that lacked security investment. They're examples of what happens when an incident is severe enough to test everything, including the infrastructure layer.
According to PwC, only 2 percent of companies surveyed had implemented firm-wide cyber resilience. The gap between security investment and actual resilience is significant, and it is showing up in incident outcomes.
The organisations that recovered fastest weren't simply those with the best detection tools. They were the ones whose infrastructure held up under pressure.
Three questions worth asking about your own estate
1. Is any of your infrastructure past end of support?
Hardware past its support window stops receiving firmware security updates. If your servers or storage arrays are running end-of-support firmware, known vulnerabilities are accumulating with no route to resolution. This applies to your recovery environment as much as your production environment.
2. Does your DR test reflect real incident conditions?
Most DR tests are conducted under controlled conditions that don't replicate a real incident.
If your recovery test involves restoring a small number of systems in a low-pressure environment, you may not have tested how your storage infrastructure performs when it is restoring at scale under time pressure.
The RTO in your plan and the RTO your hardware can deliver may not be the same number. Celerity's disaster and cyber recovery services focus on tested recovery and reducing the uncertainty around whether critical systems can actually be restored.
3. When did your infrastructure team last review the estate through a resilience lens?
Infrastructure reviews typically focus on capacity and performance. A resilience-focused review asks different questions: what fails under sustained load, what is running without firmware support, what would constrain a recovery.
If that review hasn't happened recently, it is worth scheduling.
This is not an argument against your security investment
None of this is a suggestion that detection tools, backup software, or incident response planning aren't valuable. They are essential. The point is that they depend on an infrastructure layer that is capable of performing when called on.
Cyber security and infrastructure modernisation have traditionally been separate conversations with separate budgets. Increasingly, that separation is a liability. The organisations building genuine resilience are the ones treating infrastructure readiness as part of the cyber resilience picture, not a different conversation entirely.
A practical starting point
You don't need a full infrastructure refresh project to start closing this gap. You need a clear picture of where your estate stands: lifecycle status, support windows, performance benchmarks, and what the gaps mean for your recovery capability.
That data is the foundation of an honest conversation about resilience. And it's the starting point for making infrastructure decisions that support your security investment, rather than quietly undermining it.
Celerity helps UK organisations understand where their infrastructure stands and what it means for their cyber resilience posture. Its infrastructure, cyber security and data resilience capabilities can help connect conversations that have traditionally taken place separately.
Talk to an expert
Want to take the next step in assessing your cyber security infrastructure?
Download Celerity's What Boards of Directors Must Know About Ransomware to connect infrastructure readiness with the wider ransomware resilience and governance conversation.
Talk to an expert
Frequently Asked Questions
Cyber security infrastructure is the underlying combination of servers, storage, networks, cloud environments and supporting systems that security and recovery tools depend on. If this infrastructure is outdated, unsupported or unable to perform under pressure, it can affect an organisation's ability to respond to and recover from a cyber incident.
Cyber resilience depends on more than preventing an attack. Organisations also need to maintain or restore critical operations following an incident. Infrastructure performance, support status, capacity and recovery capability can all influence how quickly systems can be restored.
A useful starting point is to review hardware lifecycle status, firmware support, storage performance, recovery capacity and current RTO and RPO requirements. Celerity also recommends testing whether recovery assumptions reflect the performance of the real environment rather than relying solely on documented targets.
Not necessarily. A controlled DR test may not reproduce the scale, urgency or technical conditions of a live cyber incident. Organisations should consider whether tests cover realistic restore volumes, dependencies, recovery environments and time pressures. Celerity explores this further in its guidance on
moving from annual DR testing to continuous recovery confidence.
Not always. The first step is understanding which infrastructure creates the greatest operational or recovery risk. Organisations can then prioritise upgrades, support renewals, architecture changes or resilience measures according to business impact.