Subnet Blog

When Cyber Risk Becomes Operational Risk

Written by Ben Luks | 7 September 2026, 02:43:35 Z

Cybersecurity is often discussed as a technology problem. But for organisations that depend on technology to run physical operations, a cyber incident rarely stays inside IT.

If employees lose access to critical systems, a warehouse cannot process orders, a production environment is disrupted, field teams cannot access the information they need or connectivity between sites is affected, cybersecurity quickly becomes an operational issue.

That changes the question leaders need to ask. It is no longer simply “How secure are we?” It is also: “If a cyber incident affects our operations, how well prepared are we to respond and keep the business moving?”

Cyber Risk Doesn't Stay Inside IT

Modern operational businesses rely on an increasingly interconnected technology environment.

ERP platforms, production and warehouse systems, finance applications, field-service platforms, cloud services, customer portals, operational technology and third-party systems can all play a role in keeping day-to-day operations running.

That creates enormous efficiency, but it also means a cyber incident affecting technology can have consequences far beyond the IT team. Depending on the organisation, those consequences might include:

  • Employees losing access to critical applications
  • Production or fulfilment processes being interrupted
  • Orders being delayed
  • Sites or field teams losing connectivity
  • Customer or supplier information becoming unavailable
  • Manual processes needing to be activated
  • Financial transactions or invoicing being delayed
  • Sensitive information being exposed
  • Contractual, regulatory or insurance obligations being triggered

The important point for leaders is that cyber risk and operational risk are increasingly connected. The original question of whether an organisation can prevent a cyber incident therefore needs to be accompanied by another: what happens to the operation if prevention fails?

A Cyber Incident Can Become a Business Continuity Event

Not every cyber incident will stop the business. But when an affected system is operationally critical, the impact can spread quickly. Imagine an ERP platform becomes unavailable. IT may immediately begin investigating the cause, isolating affected systems and working toward recovery.

But elsewhere in the organisation, different questions emerge. Can orders still be processed? Can employees access the information they need? Can the warehouse continue operating? Can field teams complete scheduled work? Can customers be updated? Are there reliable manual alternatives?

These aren't cybersecurity questions. They're business continuity questions.

This is why cybersecurity shouldn't sit entirely with IT. Technical teams may lead the response to the incident itself, but operational leaders need to understand what technology disruption means for the parts of the business they are responsible for.

Resilience Matters as Much as Prevention

Strong cybersecurity controls remain essential. But no organisation can eliminate cyber risk entirely. That means resilience needs to sit alongside prevention.

A resilient organisation understands which systems are genuinely critical, how long different parts of the business can function without them and what needs to happen if those systems become unavailable.

That includes technical capabilities such as tested backups and recovery processes, but technology is only part of the equation. The organisation also needs an incident response plan that involves the right people from IT, operations and leadership.

If a cyber incident affects a critical operational system, decisions may need to be made quickly. Should the affected environment be shut down? Can parts of the operation safely continue? When should customers or suppliers be informed? Who has authority to make those decisions? Those responsibilities are much easier to establish before an incident than during one.

Have Your Recovery Plans Been Tested Against Operational Reality?

A recovery plan can look perfectly reasonable on paper. The real test is whether it reflects how the organisation actually operates. IT may know how long restoring a system should take. But does the operational team know what it will do while that system is unavailable?

A manual workaround might technically exist, for example, but that doesn't necessarily mean it will work at normal operating volumes. Employees may know how to complete one or two transactions manually, but could they sustain that process for an entire day?

Similarly, restoring a system doesn't always mean operations immediately return to normal. There may be transactions to reconcile, orders to re-enter, data to validate or backlogs to clear.

This is why recovery planning should involve the people who actually run the affected processes. Technical recovery and operational recovery are not always the same thing.

Third Parties Can Become Operational Dependencies

Cyber risk doesn't stop at the organisation's perimeter either. Operational businesses increasingly rely on software providers, cloud platforms, suppliers, logistics partners, contractors and other third parties to deliver important services.

Those relationships can create dependencies that aren't always obvious until something goes wrong. A cyber incident affecting a critical supplier or technology provider may interrupt operations even when the organisation's own systems haven't been directly compromised.

Leaders therefore need to understand which third parties are genuinely critical to the operation. What access do they have? What systems or processes depend on them? What happens if their service becomes unavailable? Is there an alternative way of operating?

Managing third-party cyber risk isn't simply about asking suppliers to complete security questionnaires. It's also about understanding where external dependencies create operational exposure.

Cybersecurity Investment Should Follow Business Risk

One of the challenges leaders face with cybersecurity is deciding where investment should be prioritised. The answer shouldn't simply be to buy more security technology. A better starting point is understanding what matters most to the operation.

Which systems would create the greatest disruption if they became unavailable? Which processes have no practical alternative? Where would a prolonged outage have the biggest financial or customer impact? Which environments contain particularly sensitive information?

Those questions allow cybersecurity investment to be linked to business risk and operational resilience, rather than treating every system as equally important.

It also creates a more useful conversation between IT and leadership. Instead of discussing cybersecurity entirely in terms of products, vulnerabilities or technical controls, organisations can discuss what they are protecting, why it matters and what level of risk the business is prepared to accept.

That reflects one of the strongest principles from the original Manufacturing article: security investment should be connected to risk reduction and business continuity, not controls for their own sake.

Cyber Resilience Requires Leadership

Technology can reduce cyber risk, but resilience also depends on people making good decisions. Executive and operational leaders have an important role to play.

That doesn't mean leaders need to understand every technical detail of the organisation's security environment. It means they need enough visibility to understand the potential business impact and enough preparation to act when an incident affects operations.

It also means building a culture where IT, operations and leadership work together rather than treating cybersecurity as somebody else's responsibility.

The original article makes this collaboration a core component of cyber resilience, including leadership accountability, workforce awareness and cooperation between IT and operations.

Five Questions Leaders Should Ask

You don't need to become a cybersecurity specialist to have a useful conversation about cyber risk. Start with five operational questions:

1. Which technology systems are genuinely critical to keeping our operations running?

Not simply which systems are important to IT — which ones would materially affect the business if they became unavailable?

2. What would the business actually do if one of those systems was unavailable for a day?

Are there tested manual alternatives, and can they realistically cope with normal operating volumes?

3. Who makes operational decisions during a cyber incident?

IT may manage the technical response, but who decides whether operations continue, customers are contacted or parts of the environment are shut down?

4. Which suppliers or technology providers could disrupt our operations if they experienced a cyber incident?

Understanding external dependencies is just as important as understanding internal ones.

5. Have we tested recovery with the people who actually run the operation?

A technical recovery plan isn't enough if the broader business doesn't know how to respond.

These questions are deliberately different from asking whether the organisation has antivirus, MFA or a particular security product. They help leadership understand whether the business itself is prepared.

Cyber Resilience Is Operational Resilience

Cybersecurity will always require technical expertise. But as technology becomes more deeply embedded in everyday operations, the consequences of a cyber incident increasingly belong to the broader business.

The organisations best prepared for disruption will be those that understand their critical dependencies, connect cybersecurity investment to business risk, involve operational leaders in incident planning and test whether recovery strategies work outside the IT department.

Because when a cyber incident can interrupt production, fulfilment, customer service or the ability of employees to do their jobs, cyber risk has already become operational risk.