The long prehistory of digital vulnerability
Before cybersecurity became a recognised discipline, modern economies were already binding themselves to computer networks. From the 1960s onwards, governments, universities and large enterprises adopted networked computing for communications, research and logistics. The design ethos of early networking prioritised openness, interoperability and reliability over adversarial security. That made sense in a comparatively small community of trusted users. It proved less suitable once networks became commercial, global and politically contested.
The creation of the internet’s core protocols, and later the spread of personal computing, established the basic paradox that still shapes the field. Digitisation increased efficiency and reach, but also multiplied points of failure. Security was often retrofitted after systems had already become indispensable. In hindsight, that sequencing matters. It helps explain why cyber resilience today is concerned not merely with stopping intrusion, but with ensuring that essential services can continue when prevention fails.
Cyber resilience emerged when policymakers accepted that some intrusions are inevitable, and that continuity matters as much as protection.
1988 and the Morris Worm
The first great public shock arrived in 1988, when the Morris Worm spread across connected Unix systems and disrupted a significant share of the early internet. Though not designed for financial gain, the worm demonstrated how software flaws, weak passwords and trusted connectivity could combine to produce systemic effects. Its impact was modest by contemporary standards, but profound in symbolic terms. It showed that a networked environment could fail at speed and at scale.
The response helped institutionalise the field. The establishment of the first Computer Emergency Response Team at Carnegie Mellon University created a model for organised incident handling, information-sharing and technical coordination. That model would later be replicated nationally and sectorally across much of the world. The lesson was simple but enduring: when systems are interconnected, response cannot be improvised from scratch in the middle of a crisis.
The commercial internet and the rise of organised malicious activity
The 1990s transformed the internet from a specialist network into public infrastructure. E-mail, web services and digital commerce expanded quickly. So did malicious activity. Viruses, website defacements and denial-of-service attacks moved from curiosities to routine hazards. Financial institutions, telecoms operators and public agencies increasingly discovered that cyber risk was not only technical but operational and reputational.
At the same time, states began to recognise the strategic implications. Critical infrastructure operators were adopting industrial control systems with growing digital connectivity. The logic of efficiency encouraged centralisation and remote management; the logic of security lagged behind. By the end of the decade, a conceptual shift was underway: cyber incidents were no longer seen solely as crimes against individual machines, but as threats to the continuity of services on which broader society depended.
2001 and the securitisation of networks
Cyber resilience emerged when policymakers accepted that some intrusions are inevitable, and that continuity matters as much as protection.
The attacks of 11 September 2001 were not cyber attacks, but they changed the governance of risk across advanced economies. Governments reassessed critical infrastructure protection, emergency planning and interdependence. Digital networks, already essential to finance, transport, energy and communications, were folded more explicitly into national security frameworks. In the United States, this logic fed into the creation of new institutions and planning doctrines for homeland security and infrastructure protection.
Elsewhere too, authorities began treating cybersecurity as a whole-of-government issue rather than a niche technical matter. This period embedded a pattern that still persists: cyber policy is often built through adjacent crises. Major shocks in one domain expose hidden dependencies in another. What followed was increased attention to continuity planning, public-private coordination and the security of systems whose disruption could produce effects well beyond the digital sphere.
2007 and the Estonia wake-up call
In 2007, Estonia experienced large-scale distributed denial-of-service attacks that disrupted government, banking, media and other online services amid a broader political dispute. The episode did not destroy infrastructure, but it became a landmark because it illustrated how a highly digital society could be pressured through cyberspace. It sharpened international debate about attribution, proportionality and collective defence in the cyber domain.
For European and Atlantic policymakers, Estonia became a case study in resilience. The country’s dependence on digital public services was unusually visible, but the broader lesson applied elsewhere: states that digitise extensively must also invest in redundancy, recovery and trusted communication under stress. The incident accelerated institutional learning within alliances and national governments alike, contributing to a more strategic understanding of cyber preparedness.
As societies digitised faster, the question changed from whether attacks could happen to whether essential services could keep operating when they did.
2010 and the arrival of cyber-physical sabotage
The discovery of Stuxnet in 2010 marked another turning point. Unlike earlier malware focused on disruption, nuisance or theft, this operation demonstrated that code could be used to manipulate industrial processes with physical consequences. Analysts and policymakers had long discussed such possibilities; Stuxnet made them concrete. It exposed the vulnerability of operational technology environments that had often been considered obscure, isolated or too specialised to be primary targets.
The implications were wide-ranging. Security teams could no longer assume that information technology and industrial systems belonged to separate risk categories. Utilities, manufacturers and transport operators faced pressure to reassess segmentation, patching practices, visibility and incident response in environments where downtime itself can carry significant risk. For governments, the episode reinforced the idea that cyber power was now part of statecraft, crossing the boundaries between espionage, coercion and sabotage.
From crimeware to ransomware
Through the 2010s, financially motivated cybercrime became more professional, scalable and resilient. Payment systems, cryptocurrency and underground service models lowered barriers to entry while increasing potential returns. Ransomware evolved from opportunistic malware into a mature extortion ecosystem involving initial access brokers, data theft, double extortion and targeted disruption of organisations least able to tolerate downtime.
As societies digitised faster, the question changed from whether attacks could happen to whether essential services could keep operating when they did.
The shift mattered because ransomware attacks made resilience measurable in brutally practical terms. Could hospitals treat patients? Could local authorities deliver services? Could logistics chains continue to move goods? The answer often depended less on perimeter security than on backup integrity, network segmentation, restoration capacity and executive decision-making under uncertainty. Ransomware exposed a recurring institutional weakness: many organisations had cyber controls, but fewer had tested whether they could recover core operations quickly and credibly.
It also changed public understanding of cyber risk. Abstract concerns about data security gave way to visible interruptions in healthcare, education, energy distribution and municipal administration. Cybersecurity was becoming part of everyday governance, not just specialist practice.
2013 to 2017 and the age of strategic disclosure
The Snowden disclosures in 2013 did not reveal a vulnerability in the narrow technical sense, but they altered the politics of trust on which cybersecurity depends. They intensified debates over encryption, lawful access, supply chains, data sovereignty and the relationship between state power and private infrastructure. Trust in digital systems is not based solely on technical robustness; it also relies on legitimate governance.
Then came a cluster of highly consequential incidents that widened the aperture further. The 2015 and 2016 attacks on parts of Ukraine’s power grid demonstrated that cyber operations could disrupt electricity distribution in a live conflict environment. In 2017, WannaCry and NotPetya showed how quickly malware could produce global spillovers. WannaCry hit healthcare systems, businesses and public bodies by exploiting unpatched Windows systems. NotPetya, though initially spread through a Ukrainian tax software update, caused far broader damage across international shipping, manufacturing and professional services.
These incidents sharpened a hard lesson about interdependence. An attack aimed at one jurisdiction, sector or firm can impose costs far beyond its apparent target. Cyber resilience therefore cannot be fully local. It depends on international coordination, timely patching, software assurance, supply-chain visibility and the capacity to share information quickly across institutional boundaries.
In a tightly connected economy, cyber incidents rarely stay where they begin; resilience is therefore a shared, not merely local, property.
The regulatory turn
As the economic and societal stakes became clearer, governments moved from guidance towards regulation. The European Union’s Network and Information Security Directive, adopted in 2016, sought to improve cybersecurity capabilities, incident reporting and cooperation across member states. Subsequent reforms, including NIS2 and the Digital Operational Resilience Act, reflected a broader regulatory philosophy: markets alone were not producing sufficient preparedness in sectors whose failures could cascade.
This mattered because regulation reframed cybersecurity as a governance obligation rather than a discretionary technical investment. Boards, regulators and operators of essential services were asked to demonstrate not only that controls existed, but that risks were understood, reported and managed. Resilience increasingly meant assurance across people, processes and supply chains, not just the deployment of tools.
Other jurisdictions pursued parallel paths, though with different legal and institutional designs. Across the OECD world, one can see convergence around several principles: mandatory incident reporting, stronger oversight of critical sectors, attention to third-party risk and more explicit executive accountability. The centre of gravity shifted from voluntary best practice to supervised resilience.
In a tightly connected economy, cyber incidents rarely stay where they begin; resilience is therefore a shared, not merely local, property.
2020 and the pandemic stress test
The Covid-19 pandemic was a public health crisis, but it also became a vast cyber resilience experiment. Organisations shifted abruptly to remote work, cloud dependence deepened, and digital public services became even more critical. Attackers adapted quickly, exploiting uncertainty, overloaded staff and rapidly reconfigured networks. Yet the larger significance of the period lies in what it revealed about continuity.
Many institutions proved more adaptable than expected, but often by relying on hurried exceptions, improvised processes and concentrated third-party dependencies. The boundary between cyber resilience and broader organisational resilience became harder to separate. Identity management, endpoint visibility, secure collaboration and crisis communications all turned out to be central to institutional functioning. At the same time, software supply-chain risk received renewed scrutiny, especially after the SolarWinds compromise underscored how trusted management layers could become channels for far-reaching intrusion.
The pandemic period also strengthened the argument that resilience must be designed for prolonged strain, not just acute incidents. Capacity, staffing, vendor concentration and clear lines of authority matter as much as technical safeguards when disruption becomes sustained.
Critical infrastructure in an age of compound risk
By the early 2020s, cyber resilience had become inseparable from the protection of critical infrastructure. Energy systems were decarbonising and decentralising. Transport networks were becoming more software-defined. Water utilities, hospitals and public administrations were under pressure to modernise legacy systems while controlling costs. Each trend expanded the attack surface while increasing societal dependence on digital reliability.
The challenge is no longer simply defending assets, but governing complexity. Critical functions are delivered through ecosystems of operators, vendors, contractors and cloud services. Dependencies are layered and often imperfectly understood. A local technical issue can combine with geopolitical tension, physical disruption or misinformation to create compound crises.
This is why leading institutions increasingly stress resilience over pure prevention. The National Institute of Standards and Technology’s Cybersecurity Framework 2.0 places governance at the centre. Guidance from cybersecurity agencies in Europe, North America and elsewhere likewise emphasises risk management, business continuity, recovery planning and secure-by-design practices. In practical terms, mature resilience means knowing what must keep running, what can fail gracefully, and how to restore trust when systems have been compromised.
The decade ahead
The next phase of cybersecurity will be shaped by three converging realities. First, digital systems will continue to permeate essential services, making cyber resilience a basic condition of economic governance. Secondly, geopolitical rivalry will sustain pressure on networks through espionage, pre-positioning and coercive cyber operations below the threshold of war. Thirdly, automation and artificial intelligence are likely to accelerate both defence and attack, compressing the time available for detection and response.
None of this implies a clean technological fix. The central problem is institutional. Resilience depends on maintenance budgets, procurement standards, skilled personnel, realistic exercises, legal clarity and public trust. It also depends on accepting that some level of disruption is unavoidable. The most resilient societies will not be those that promise perfect security, but those that build redundancy, practise recovery and distribute authority intelligently when systems are under stress.
That is the deeper arc of this timeline. Cybersecurity began as a technical speciality concerned with protecting machines and data. It has become a discipline of societal endurance. In a world where digital disruption can unsettle hospitals, ports, tax systems and power grids, resilience is not a slogan. It is the practical art of ensuring that institutions can fail, recover and continue to serve the public.




