Secure and Resilient
"Secure and resilient" describes a system's ability to both protect against adverse events, such as attacks or accidents, and to keep functioning or quickly recover when those events occur. Security emphasizes preventing and defending against threats, while resilience emphasizes withstanding, adapting to, and recovering from disruptions. The two goals are related but distinct, and a system can be relatively strong in one while weaker in the other.
As commonly used in cybersecurity and critical infrastructure contexts, security refers to controls and measures intended to protect systems and data against threats, while resilience refers to the ability to prepare for, adapt to, withstand, and recover from deliberate attacks, accidents, or naturally occurring threats or incidents (per NIST's glossary treatment of resilience and CISA's usage). In AI system contexts these terms are frequently paired to indicate both the protection of a system against compromise and its capacity to maintain or restore intended function under adverse conditions. The precise scope varies by framework and sector, and the evidence provided does not supply an AI-specific or standardized combined definition; this entry therefore generalizes from cybersecurity and infrastructure sources rather than from a single authoritative AI governance instrument. Practitioners should not treat "secure" and "resilient" as synonymous: strong preventive security does not guarantee resilience, and controls described here reduce and manage risk rather than eliminate it.
Why it matters
In AI governance and model risk contexts, treating "secure" and "resilient" as a single objective is a common and consequential error. Security concentrates on preventing and defending against threats, while resilience concentrates on continuing to function or recovering after a disruptive event occurs. A system can be relatively strong in one dimension and weak in the other: robust preventive controls do not guarantee that a system will withstand or rapidly recover from an incident, and a highly recoverable system may still be poorly defended against compromise. Distinguishing the two goals helps organizations avoid a false sense of assurance from investing heavily in prevention alone.
For AI systems specifically, the pairing signals two related concerns: protecting the system against compromise and maintaining or restoring its intended function under adverse conditions. The evidence available here draws on cybersecurity and critical infrastructure sources (such as NIST's glossary treatment of resilience and CISA's usage) rather than a single standardized AI-specific definition, so practitioners should recognize that the precise scope varies by framework and sector. This matters for governance because the applicable expectations for an AI system may be shaped by whichever cybersecurity or infrastructure framework an organization has adopted, and those frameworks do not use fully interchangeable definitions.
The practical stake is that controls described under these terms reduce and manage risk rather than eliminate it. Framing security and resilience as distinct but complementary objectives allows compliance officers, risk managers, and auditors to test each capability separately: whether threats are being prevented and defended against, and, independently, whether the organization can continue to deliver intended outcomes and recover when adverse events nonetheless occur.
Who it's relevant to
Inside Secure and Resilient
Common questions
Answers to the questions practitioners most commonly ask about Secure and Resilient.