Cybersecurity has long had a name for the gap between appearance and reality: security theatre. It’s the practice of creating visible signs of protection without meaningfully reducing risk. Today, operational resilience is developing the same problem.
Many organisations believe they’re resilient because they have incident response plans, monitoring tools and recovery procedures. Those things matter, but they were largely designed for a world where disruption was predictable. A cyberattack. A hardware failure. An outage. When the objective was to restore service as quickly as possible, these measures did indeed deliver. But resilience itself has changed, and much of that confidence hasn’t changed with it.
Today’s disruptions are less likely to arrive as isolated incidents than as a steady accumulation of change. AI is reshaping applications and workflows. Employees expect to work from anywhere, often on personal devices. Digital services have become the primary customer experience rather than a supporting channel. Resilience is no longer just about recovering from failure. It’s about adapting continuously without creating new operational risk.
A Peek Behind the Confidence Curtain
This changing reality helps explain an interesting contradiction. In SolarWinds’ 2025 IT Trends Report, nine in ten respondents described their organisations as resilient. Yet confidence dropped sharply when they were asked about the capabilities modern resilience increasingly depends on. Only 38% felt prepared to support AI, 26% believed they could effectively manage bring-your-own-device environments, and fewer than half felt equipped to support increasingly distributed workforces.
The contradiction doesn’t stem from IT teams overstating their capabilities. It’s that many organisations are still measuring themselves against an outdated definition of resilience.
The survey reinforces this point. Cybersecurity remains the area where confidence is strongest, with just over half of respondents saying they feel well prepared. That’s hardly overwhelming, but it stands out because cyber threats are one of the few challenges that still fit the traditional resilience model. Organisations have spent years building playbooks, refining response processes and investing in established controls.
AI adoption, workforce flexibility, and increasingly interconnected digital environments, on the other hand, don’t fit those playbooks nearly as neatly. They demand different capabilities, different operating models and, in many cases, different ways of measuring success.
Behind the Scenes
That’s where another finding becomes particularly significant. Nearly half of respondents said they don’t use mean time to detect, acknowledge or resolve incidents as a resilience metric. Whether because these measures are difficult to capture or simply not prioritised, the result is the same: organisations lose one of the few objective ways to test whether resilience is actually improving.
Without meaningful measurement, resilience becomes something organisations assume rather than demonstrate. That is exactly how resilience theatre persists. Not through deliberate deception, but because there is no objective measure rigorous enough to expose the gap between confidence and capability.
Admission of Cost
That distinction matters because resilience is no longer just in service of keeping the lights on. It is an imperative to innovation. Every major technology initiative now carries operational consequences. Rolling out AI agents, enabling broader device choice, expanding into new markets or launching digital services all increase complexity. If leaders don’t have confidence in how those changes affect operational resilience, transformation inevitably slows. Projects become more cautious, governance becomes heavier, and opportunities take longer to reach customers, even when the underlying technology is ready.
The biggest cost therefore isn’t necessarily the next outage. It’s the innovation that never happens, and the competitive advantage that erodes, because organisations aren’t certain their foundations can support it.
Flipping the Script
This is also why resilience can’t be solved simply by adding more technology. The instinct may be to respond to change by buying additional tools, and hope that greater visibility will automatically create greater resilience. However, in practice, disconnected tools often add complexity without improving understanding. Visibility isn’t the same as clarity. A platform bought to project resilience, without the relationships and processes to back it, is simply a more expensive prop.
Instead, real resilience starts with understanding how systems, people, data and processes depend on one another. It requires identifying where operational bottlenecks exist, where ownership is unclear and where small failures have the potential to cascade across the organisation. Only then can technology address clearly defined problems instead of creating the appearance of control.
To navigate the next decade successfully, organisations need confidence that is measurable and defensible, tested against today’s operating environment rather than yesterday’s definition of resilience. Because resilience isn’t defined by how confidently an organisation says it’s prepared. It’s defined by how well that confidence stands up when conditions change.





