Cyber Resilience Without a Seat at the Table
Earlier in this series
Global cybersecurity runs on membership. Information-sharing bodies, CERT cooperation networks, standards committees, vendor ecosystems, framework clubs — the whole architecture assumes you are inside it.
This series began with the observation that isolated states build resilience differently. Twenty-odd pieces later, I want to close the governance pillar by facing the question underneath all of it: what does cyber resilience actually consist of when a state is excluded — when it cannot join the bodies, buy from the vendors, or adopt the frameworks written by and for the members?
I come at this from an unusual seat. I have worked inside the member world — enterprise SOC work in Estonia, a startup in an EU innovation ecosystem — and I have lived and worked under exclusion, running a practice through sanctions-era constraints and national-scale disruptions. Both sides of the line are real to me. Neither is theoretical.
What exclusion concretely removes
It is worth being unsentimental and specific. An excluded state loses, roughly in order of visibility:
The vendor relationship. Not just products, but everything wrapped around them: support contracts, official patch channels, license renewals, cloud services, and the informal early warnings vendors give customers. As reported around recent sanctions regimes, major providers have withdrawn from entire markets within weeks. Security tooling then arrives, if at all, through unofficial channels — which is itself a supply-chain risk, because software of unverifiable provenance is exactly how compromise travels.
The sharing networks. Incident-response cooperation runs on trust communities — CERT-to-CERT relationships, sharing groups, coordination bodies. Excluded teams sit partially or wholly outside these, so indicators, warnings, and coordinated-response channels reach them late or never. During a global incident, they read about the threat in public reporting like everyone's grandmother, then face it with whatever they have.
The standards rooms. Frameworks encode their drafters' assumptions — a theme I worked through in the CIIP comparison earlier in this series. States absent from the drafting inherit instruments that assume institutions, markets, and memberships they do not have.
The talent market's center of gravity. Certifications, conferences, payment rails for freelance work, even exam registration can be blocked or awkward. Skills still develop — often impressively — but through harder, lonelier routes.
What resilience looks like anyway
Here is what two decades of watching, and some years of living it, suggest excluded states and their practitioners actually do. I described the architectural half of this in the opening piece; this is the institutional half.
They substitute, permanently. Domestic services replace foreign ones — not as industrial policy but as load-bearing infrastructure, built on emergency timelines. In the sovereignty-versus-isolation taxonomy I put this precisely: these states are not buying options, they are replacing lost ones. The substitutes are often rougher than what they replace, and they are also, crucially, there.
They go open-source by necessity. When commercial tooling is unavailable, open-source security software becomes the national stack: monitoring, detection, network security, the lot. This produces a quietly interesting side effect — deep, unglamorous engineering competence, because there is no vendor to call and no managed service to hide behind. Everything must be understood to be run.
They over-invest in the fundamentals. The four-item foundation I described in Minimum Viable Cyber Governance — accountable agency, readable strategy, recurring money, legal basis — matters more under exclusion, not less, because there is no external scaffolding to compensate for its absence. No framework club will paper over a missing institution. Excluded states that manage adequately are the ones that got these foundations right; no amount of engineering talent rescues the ones that did not.
They build parallel relationships. Excluded from one trust community, states build others — bilateral CERT ties, regional arrangements, relationships among the similarly excluded. These networks are thinner and slower than the main ones, but they are not nothing, and they are growing. What fuller regional cooperation could look like is a question I will take up as this series closes.
They plan for the dark. Having lived through connectivity loss — the subject of my shutdown piece — institutions under exclusion internalize an assumption member-states rarely test: the outside may become unreachable. Continuity planning that treats international connectivity as optional is standard practice, not paranoia.
The honest costs
I refuse to romanticize this. Resilience under exclusion is real, and it is expensive in ways that compound.
Everything is slower and rougher. Substitutes lag their originals. Blindness to fast-moving global threats is partial but genuine; late warning means late response. Unofficial procurement channels import risk with every download. Talented people leave, and each departure makes the next more likely. And the duplicated infrastructure — everything built twice, once for normal times and once for the dark — is deadweight a connected state never pays.
Exclusion produces toughness, and toughness is not the same as strength. A state can be remarkably hard to kill and still be poor, tired, and behind.
Why the members should care
The governance argument I want to leave the pillar on is this: exclusion is a policy with externalities, and the externalities flow back.
A state outside patch channels and threat-sharing networks does not stop being connected to the rest of us at the technical layer. Its unpatched systems get compromised and become infrastructure for attacks on everyone. Its defenders, unable to coordinate through official channels, cannot help contain global incidents even when willing. Gaps in the world's collective visibility are gaps in everyone's defense. Malware, as I said at the start of this series, does not check passports.
None of this is an argument about whether any particular exclusion is justified — that is a question for other people and other forums, and I keep my writing on the systems side of that line. It is an argument about accounting. The security costs of exclusion are currently booked entirely to the excluded, and that ledger is wrong. Some of the costs land on the excluders, with interest, through the shared network.
Closing the loop
I opened this pillar asking why isolated states build resilience differently. The answer, assembled across the series, is that resilience is relative to what you can count on. Member-states can count on markets, allies, frameworks, and warning networks, so their resilience is a portfolio of external options. Excluded states can count on almost nothing external, so their resilience is internal by construction: substitution, self-sufficiency, foundations, and the assumption of the dark.
Neither model is the future I would choose. The interesting question — the one I want to end the series on — is whether there is a third model: cooperation structures that do not require a seat at the existing table. That is where I go next.