UNDERSTANDING DIGITAL RESILIENCE

Foresight and Navigation through Cyber Heavy Weather

Days
Hours
Minutes
Seconds
In 2025, a single cyber attack shut down a carmaker’s plants in five countries, cost the UK economy an estimated £1.9 billion, and pulled the British government into an unprecedented loan guarantee to limit growing damage to suppliers and customers.
 
Digital storms have wide ranging sources and impacts. Geopolitical conflicts pursued through digital disruptions of critical services, AI finding software vulnerabilities enabling attacks faster than human teams can patch, and supply chains that snap under pressure can all combine into a polycrisis causing global chaos. Organizations that effectively respond to such crises understand the drivers of digital risk, analyze potential threatening situations, and prepare before these storms arrive.
 
Understanding Digital Resilience gives leaders a framework for that preparation, built on four steps. The authors build upon proven planning methodologies from military wargames to corporate scenario analysis to horizon scanning. Analyzing real world cyber attacks as well as scenarios portraying plausible future polycrisis possibilities, the book illustrates how organizations can build digital resilience capacity.

You cannot stop the storms.
You can decide how to prepare, survive and thrive.​

Expert perspectives on Strategic Cyber Foresight

Real Scenario Walkthrough

On the evening of Friday, September 19, 2025, a cyber attack disrupted Collins Aerospace, a U.S.-based aviation technology vendor and subsidiary of RTX (formerly Raytheon Technologies). The attack hit Collins systems supporting MUSE (Multi-User System Environment), software that airlines use for electronic check-in, baggage drops, and boarding.

The disruption affected major European airports. On September 22, the EU’s cybersecurity agency, ENISA, confirmed that a ransomware incident caused the outage, though it did not name a perpetrator. Security researchers have since linked the intrusion to HardBit ransomware, and reports describe a phishing lure disguised as an RTX firmware update as the likely entry point, with more than 1,000 computers affected. The weekend travel disruption contributed to at least 217 flight cancelations and an estimated loss of millions of euros for affected airports and airlines.

Step 1: Insight

It’s early 2024, and you are the CEO of a company that owns an affected European airport. You are thinking about how to remain digitally resilient and consider the risk drivers that could bring a digital storm to your enterprise. How did your current technology dependencies create single points of failure? What unique cyber risk drivers apply specifically to your industry?

Understand your risk drivers

Technology

Check-in, bag drop, and gate assignments had been consolidated onto shared MUSE software used by many airlines and airports across Europe, creating a high concentration risk.

Cyber

According to external reports, Collins had outdated internet-facing systems, end-of-life VPN devices, and weak/valid credential exposure, along with potential prior data theft from a BianLian ransomware attack in 2023.

Geopolitical

Aviation and cyber regulation are fragmented — the EU’s NIS2 and the UK’s rules diverge from the lighter U.S. approach, leaving one vendor to answer to competing compliance regimes. Meanwhile, Russia has carried out repeated cyber campaigns against Western logistics providers and technology companies, including airports and air traffic management systems.

Step 2: Preparation

Develop “severe but plausible” scenarios that combine multiple risk drivers with your industry and company profile. How do the strands of technological, geopolitical, supply chain, and regulatory challenges combine to impact your airport’s operations?

Scenario planning for digital storms

You understand that when a shared vendor like MUSE goes dark, there will be delays, cancelations, and chaos. At some airports, passengers may stand in long lines while staff switch to pen and paper — manually verifying passenger information, writing baggage tags by hand, and checking bags. Gate changes would need to be coordinated through two-way radios rather than digitally.

Scenario planning turns those improvised workarounds into prepared ones. Working through this storm in advance identifies preparation steps that you can take now:

Explore alternative vendors and redundancies that would allow for critical processes even when MUSE goes dark.

Backup procedures prepared, practiced, and in place, such as leveraging radio and call signs for gate changes.

A business continuity plan with specific vendor outages and a recovery playbook for the failure of a key supplier.

Step 3: Execution

It’s September 2025, and the digital storm has arrived: check-in and baggage systems are down at your airport, flights are delayed or canceled, and lines of frustrated passengers swarm airline desks.

 

Airports couldn’t work on the repair because the software ran on Collins’ networks. However, Collins’ parent company, RTX, later told the SEC that MUSE runs on customer-specific networks kept separate from RTX’s own enterprise systems. Either way, the airports waited. Reporting also described Collins machines being reinfected after cleanup, which stretched the recovery out.

Apply the action steps to weather the digital storms

Execution puts your strategic preparation in place and response plans in action. It requires a navigator to own the practice of strategic foresight inside the organization. This navigator should be appointed before the crisis occurs.

Operations knew check-in ran through one platform. Procurement held the contract. Cybersecurity teams knew ransomware was hitting aviation suppliers. The navigator thought through these factors, put the pieces together, and pushed for an updated business continuity plan that included executing the workarounds established.

Step 4: Evolution

It’s now mid-2026. The digital storm has passed: RTX filed with the SEC on September 26, 2025, confirmed ransomware, and said it expected no material impact on the business. What did you and your organization learn from the digital storm, and how are the lessons being implemented?

Debrief the storm and identify actionable learning for future storms

Organizations should use a post-incident review to test whether their response plan actually held up under pressure, or whether confusion and improvisation carried the response instead. Potential lessons learned include:

Our check-in depends on one vendor with no substitute. This means we should establish an agreed number of desks able to run offline and test them.

Standalone check-in laptops, iPads, basic mobile tools, and manual operations with pen and paper helped us get by. Should we integrate those processes into staff training exercises?

We had no way to get status from the vendor while we were down, meaning we should add outage reporting terms at the next contract renewal.

Heathrow experienced ”minimal” disruptions and no cancelations related to the incident, whereas Brussels asked airlines to cancel nearly 140 flights. We should assess the differences in operations between the airports to strengthen resiliency.

Scenario Conclusion

Understanding Digital Resilience: Foresight and Navigation through Cyber Heavy Weather provides readers with the framework to respond to incidents like the Collins Aerospace while providing real-world and polycrisis scenarios to strengthen your toolset for effective strategic foresight.

Reach out to icr@nextpeak.net to learn more.

BEYOND THE BOOK

Sign up for updates

Fill out the form to get connected and receive updates straight to your inbox. Unsubscribe at any time.

icr@nextpeak.net