Cyber security has become one of the most audited and regulated areas of enterprise technology. However, simply passing an audit or achieving certification is not the same as proving that systems, people and processes can withstand a genuine outage or cyber incident. Here, Nathan Charles, head of customer experience at cyber resilience specialist OryxAlign, explains why organisations need to look beyond compliance to build genuine operational resilience.
Manufacturing businesses invest significant time and resource into meeting the requirements of ISO 19650-5 and the National Protective Security Authority’s ‘Built it Secure’ approach. However, while these frameworks provide valuable structure and demonstrate a credible baseline of security maturity, it is very possible for certified firms to still lose control of sensitive data.
For example, in late 2025 Jaguar Land Rover reported heavy losses covering a three month period where it was impacted by a serious cyber-attack. The attack forced the manufacturer to shut down its computer networks, leaving it unable to operate its highly-automated production line for nearly two months. The lesson from incidents like these is that simply being able to report a high degree of cyber security spend and compliance with industry standards is not a guarantee of protection against attacks.
Compliance frameworks like ISO 19650-5 set a recognised baseline, create accountability and give boards and customers a way to benchmark security maturity. The risk lies in what happens post-certification.
For many organisations, passing an audit becomes the objective in itself, rather than a step towards genuine cyber resilience. Certification and self-assessment exercises capture a snapshot of security controls at a single point in time, under conditions that are largely predictable. They rarely test what happens when those controls are placed under real pressure, such as a ransomware attack that spreads faster than the incident response plan anticipated, a misconfigured update that takes core systems offline, or a supplier outage with knock-on effects nobody had mapped.
When the paperwork doesn’t match reality
The gap between documented compliance and operational reality is well evidenced. The UK Government’s Cyber Security Breaches Survey 2025/2026 found that 43 per cent of UK businesses reported experiencing a cyber security breach or attack in the past twelve months. This is despite most organisations already having basic technical measures, such as malware protection, firewalls and access controls, in place.
According to the IBM 2026 X-Force Threat Intelligence Index, manufacturing was the most-attacked industry globally for the fifth consecutive year and accounted for 27.7 per cent of recorded incidents in 2025. Notable cyber-attacks in the last year or so include those on engineering contractor Morrisroe, the Construction Industry Council and Bouygues UK.
Regulators are recognising the gap too
Encouragingly, this is not a case of compliance frameworks being wrong; it reflects how regulators and standard-setters are actively evolving what they expect organisations to demonstrate. The National Cyber Security Centre (NCSC) has developed its Principles Based Assurance approach specifically to move away from assessment against fixed, compliance-driven control sets, in favour of a risk-based approach.
Notably, the EU’s Digital Operational Resilience Act requires financial entities to test their cyber resilience through scenario-based exercises rather than rely on point-in-time compliance reviews. Across sectors and geographies, there is a consistent direction of travel where demonstrated cyber resilience, not paperwork, is the real measure of readiness.
From checklist to stress test for cyber resilience
For organisations that want to close this gap, the starting point is treating cyber resilience as something that is tested and proven, not assumed because a framework has been satisfied. That means running scenario-based exercises that simulate severe but plausible disruption, such as the loss of a critical supplier, a ransomware incident or a major cloud outage, and observing how systems, teams and decision-making actually hold up under pressure.
Compliance frameworks and regulatory obligations remain an essential part of managing cyber risk, and organisations should not disregard them. But they represent a floor, not a ceiling. Genuine operational cyber resilience is proven under pressure, not certified on paper. Organisations that build a culture of continuous testing, honest assumption-challenging and cross-functional ownership will be far better placed to keep critical services running when, not if, disruption occurs.
To learn how OryxAlign helps organisations map digital dependencies and strengthen cyber resilience, visit www.oryxalign.com.
Read other recent news: https://industrial-compliance.co.uk/category/news/

