This book positions modern cyber incidents as large scale stress tests of enterprise design rather than isolated security failures. Using Colonial Pipeline and NotPetya as anchor cases, it shows how seemingly technical compromises can bring fuel distribution, logistics, and manufacturing to a standstill when digital infrastructure is flat, opaque, and weakly governed. It contrasts those baseline failures with a hypothetical, but concrete, Resilience by Design scenario in which the same intrusions occur yet remain quickly contained, preserving operational continuity and strategic control.
The narrative opens with a forensic yet accessible walk through of Colonial Pipeline and NotPetya as enterprise level shocks. In Colonial’s case, a single compromised password in an IT environment destroyed leadership’s confidence in the separation between business systems and operational technology, prompting a full pipeline shutdown that cascaded into fuel shortages and emergency government actions. In the NotPetya episode, destructive malware entering through a software update for Ukrainian tax systems rode the flat, highly connected networks of global firms, wiping out logistics and production systems at machine speed and forcing large scale rebuilds. In both stories, the decisive factor was not attacker sophistication but architectural fragility and the absence of reliable signals to guide nuanced decisions.
From this foundation, the book introduces three core capabilities that determine whether digital disturbances stay bounded or spiral into crises: signal fidelity, segmentation, and cross mapped dependencies. Signal fidelity is defined as the ability to see, in near real time, what assets exist, how they are connected, which are critical, and which are affected. Segmentation covers the structural separation of networks, identities, and data so that compromise in one zone cannot automatically endanger others. Cross mapped dependencies provide the missing bridge between digital components and the physical assets, customer channels, and supply chain nodes they support. Together, these capabilities become the primary levers for designing enterprises that can absorb cyber shocks without defaulting to blunt shutdowns or wholesale rebuilds.
The heart of the book is a side by side comparison of two worlds: the baseline scenario illustrated by Colonial and NotPetya, and a Resilience by Design scenario in which the same attacks unfold against better designed enterprises. In the baseline world, leaders ask: “Are we compromised everywhere? Do we have to shut down everything to be safe?” In the Resilience by Design world, the questions become more surgical: “Which segments show confirmed impact? Which plants, pipelines, or terminals are mapped to those segments? Which zones can we deliberately isolate, and which can continue operating under monitored conditions?” The book walks through the first hours, days, and recovery phases of each incident under this improved design, using tightly woven narrative to show how higher signal fidelity, enforced segmentation, and live dependency maps turn fear driven binary choices into calibrated containment actions.
To make these ideas actionable, the book introduces a five level digital resilience maturity model focused on the three core capabilities. At the lower levels, organizations operate with incomplete asset inventories, flat networks, and no explicit mapping between systems and critical services. At the top levels, they maintain unified visibility across IT, operational technology, and cloud for critical flows, combined with tested segmentation and living dependency maps that inform both planning and crisis response. Rather than prescribing a uniform target, the model invites leaders to define differentiated maturity goals by business flow: which value streams warrant the highest resilience investments, and where a lower level is an acceptable trade off.
The book then shifts from architecture to governance. It argues that digital resilience will decay without a corresponding evolution in how risk is owned and managed. Executives are urged to move away from treating cyber resilience as a specialist, technology centric problem and instead to assign explicit enterprise ownership of digital risk across IT, facilities, and supply chains. The proposed governance model includes a single accountable executive for digital resilience, a cross functional resilience council that aligns design decisions with business priorities, and capital planning processes that require major programs to demonstrate their impact on resilience, not just cost and productivity. These structures are paired with a concise set of outcome oriented metrics: time to establish blast radius, coverage of segmentation for operations critical environments, percentage of top tier services with current dependency maps, and frequency and quality of cross functional exercises.
Critically, the book reframes Colonial and NotPetya not simply as cautionary tales about what went wrong, but as teachable contrasts against the Resilience by Design alternative. In the baseline scenario, fragmented governance and opaque infrastructure drove leaders toward coarse actions: shut a major pipeline to avoid unknown OT risk, or rebuild tens of thousands of systems because no one could reliably distinguish clean from compromised assets. In the Resilience by Design scenario, the same attacks still succeed in breaching initial defenses, yet their impact is constrained: OT segments can be confidently isolated within defined timeframes, high value identity domains have narrow blast radius, and recovery follows standardized patterns guided by well maintained maps of business dependencies. The book uses these paired narratives to highlight how different design choices over years, not different actions on the day of crisis, determine whether incidents remain bounded.
Throughout, the analysis remains both neutral and prescriptive. It does not claim that any design can eliminate intrusions, but it is explicit about the choices boards and executives must make to prevent intrusions from collapsing their capacity to operate and govern. The closing sections crystallize these as a shortlist of design decisions: the segmentation posture for operations critical systems, the balance between centralized and segmented identity and administration, the mandated depth of dependency mapping, the integration model for critical suppliers, and the differentiated target resilience level by flow. For each decision, the book spells out trade offs along a clear line: operational simplicity and short term efficiency on one side, versus constrained blast radius and bounded outage on the other.
The final insight is concise: in a world where infrastructure is as digital as it is physical, cyber resilience is enterprise resilience. Organizations that continue to handle cyber as an isolated technical topic will periodically face Colonial or NotPetya class shocks, forced into panic driven, all or nothing responses. Those that invest in signal fidelity, segmentation, and cross mapped dependencies, and that govern digital infrastructure as mission critical architecture, will experience comparable attacks as stress tests that validate their design. If a pipeline operator or global logistics firm has these capabilities built and governed, then even a fast moving malware outbreak or targeted ransomware event becomes a bounded operational incident rather than an existential crisis. The book equips senior leaders with the concepts, language, and decision frameworks to move decisively toward that future.