← Latest papers
💻 computer science

Breach to Resilience: A Conceptual Review of Multi-case Global Cyberattacks

This paper presents a conceptual narrative review of literature from 2020 to 2025 on multi-case global cyberattacks, highlighting the limitations of traditional security models and proposing a new four-tier framework to advance the understanding and implementation of cyber resilience.

Original authors: Emmanuel Olufemi Igbekele, Grace Funmilayo Smith, Olumide Victor Adams

Published 2026-06-29
📖 5 min read🧠 Deep dive

Original authors: Emmanuel Olufemi Igbekele, Grace Funmilayo Smith, Olumide Victor Adams

Original paper licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine your organization is a bustling city. For a long time, the city's security plan was simple: build a high, impenetrable wall around the perimeter and hope no one gets in. This is what the paper calls the "traditional security model."

However, the authors of this paper argue that the world has changed. The city is now connected by invisible digital bridges, and the "bad guys" have learned how to sneak in through the back door, the sewer, or even by pretending to be a delivery driver. The high wall isn't enough anymore.

Here is a simple breakdown of what this paper says, using everyday analogies:

The Big Problem: The "Unbreakable Wall" Myth

The paper starts by saying that trying to stop every single cyberattack is like trying to stop every single raindrop from hitting the ground. It's impossible. Even the best-protected cities (organizations) eventually get breached.

The authors say we need to stop obsessing over "prevention only" and start focusing on Cyber Resilience.

  • The Old Way: "If we build a strong enough wall, nothing bad will happen."
  • The New Way (Resilience): "Bad things will happen. The goal isn't to stop the storm; it's to make sure the city keeps running, the lights stay on, and we can clean up the mess quickly when the storm hits."

The Four-Step "City Survival" Plan

The paper proposes a new way to think about security, broken down into four stages. Think of this as a survival guide for a city under attack:

  1. Preparedness (The Emergency Kit):

    • The Analogy: Before a hurricane hits, you don't just hope for the best. You check your flashlights, fill your gas tanks, and have a plan for where everyone will go.
    • The Paper's Point: Organizations need to expect attacks and have a plan ready before the alarm rings.
  2. Detection and Response (The Sirens and the Firefighters):

    • The Analogy: When a fire starts, you need to smell the smoke immediately (detection) and have firefighters ready to act right away (response).
    • The Paper's Point: We need to spot the attack early and make quick decisions. The paper notes that currently, we are often too slow to spot "zero-day" attacks (brand new, unknown threats).
  3. Resistance (The Firebreaks):

    • The Analogy: If a fire starts in one building, you want firewalls (physical barriers) to stop it from burning down the whole neighborhood.
    • The Paper's Point: This is about limiting the damage. If a hacker gets in, how do we stop them from taking over the whole system? The paper mentions that "Zero Trust" (a strategy where you don't trust anyone inside the network either) is hard to install in old, "legacy" systems.
  4. Recovery and Adaptation (The Rebuild and Learn):

    • The Analogy: After the storm passes, how fast can you get the city back to normal? And more importantly, did you learn anything? Did you realize your drainage system was weak, so you fix it so the next flood won't be as bad?
    • The Paper's Point: This is the part the paper says is missing. Most organizations are good at fighting the fire, but bad at rebuilding and learning from it. They don't have good plans for how to keep working while they are under attack, or how to use the experience to get stronger.

What the Paper Found (The "Gap")

The authors looked at 17 recent studies (from 2020 to 2025) to see what experts are saying. They found a big imbalance:

  • What everyone is talking about: How to prepare, how to detect, and how to resist. (Like talking a lot about building walls and fire trucks).
  • What everyone is ignoring: How to recover and adapt. (Like having no plan for what to do after the fire is out).

The Missing Puzzle Piece:
The paper argues that current research is like a puzzle with a huge hole in the middle. We have pieces for the "before" and "during" phases, but we are missing the pieces for the "after."

Furthermore, the paper points out that we treat humans and technology as two separate things. It's like having a great robot firefighter but forgetting to train the human captain on how to talk to the robot. The paper says we need to figure out how humans and AI (Artificial Intelligence) can work together as a team, not as separate entities.

The Conclusion: A Call for a "Unified Map"

The main takeaway is that we don't need more scattered advice. We need a single, unified map (a framework) that covers all four stages: Preparedness, Detection, Resistance, and Recovery.

Currently, the advice is scattered. Some experts talk about big companies, others talk about small businesses, and few talk about how to help small businesses grow into big ones without losing their security. The paper concludes that until we have a complete plan that includes learning and adapting after an attack, our cities (organizations) will remain vulnerable.

In short: Stop trying to build a wall that can never be breached. Instead, build a city that can take a hit, keep functioning, and get back up stronger than before.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →