The shield is assumed to fail.
We measure what happens next.
Security work has spent two decades getting good at keeping attackers out, and that work still matters — controls, hardening, detection, the discipline of knowing what you have and who can reach it. But prevention is a probability, not a guarantee. Every control you own is one configuration change, one unpatched dependency or one borrowed credential away from being irrelevant.
Resilience is what's left when that happens. It is not the same thing as having backups. It is whether the people, the runbooks and the restore paths hold up while an adversary is still inside the environment — whether identity comes back before the applications that depend on it, whether the copy you restore from is actually clean, and whether the number you quoted the board survives contact with a real incident. Most organisations have never found out. We find out on purpose, under attack conditions, and hand you the number.
