In a recent parliamentary debate I discussed the critical need for cyber resilience in Scotland, drawing on my 20-year background in the IT industry. I explained that the focus has evolved from simple "disaster recovery" to "cyber resilience," emphasizing that organizations must plan for the inevitability of future attacks rather than just trying to prevent them entirely. Using the example of the Arnold Clark cyberattack in 2022, I highlight that even large organizations with