Trust is built into almost everything an enterprise does. An employee signs into an account and the system accepts that they are who they say they are. A finance platform receives data and treats it as accurate. An automated workflow gets an instruction and carries it out. A supplier connects to a shared system, an application calls an API, an AI tool makes a recommendation and another system acts on it.

Most of the time, nobody stops to question these interactions. They can't. If every identity, transaction, data point and digital relationship had to be investigated from scratch before anything could happen, modern businesses would barely function. Trust is what lets them move.

em360tech image

But that also changes what happens when trust fails. A compromised account or unreliable system isn't only a problem because something has gone wrong. The harder question is what else the organisation can safely continue believing. That uncertainty can travel much further than the original failure.

The First Consequence Of Trust Failure Is Uncertainty

When a normal application fails, it's usually pretty obvious. It throws an error. It crashes. It slows down. It refuses to load, usually when you're presenting something to people with job titles that make the room tense. A trust failure can be harder to deal with because the system may still appear to work. 

The account is active. The data is there. The transaction went through. The application is online. The automated process completed exactly as expected. The problem is that the organisation no longer knows whether it can rely on the result. Consider what happens when an employee account is compromised. 

Blocking that account may deal with the immediate access problem, but it doesn't answer everything else. 

  • Which actions performed through the account were legitimate? 
  • Which changes can still be trusted? 
  • Did the user approve those transactions? 
  • Did anything created, downloaded or altered during that period affect another system?

The same problem applies beyond identity. If data integrity is called into question, every decision made from that data becomes harder to assess. If an automated system behaves unexpectedly, teams need to establish whether its previous outputs remain reliable. 

If a trusted supplier is compromised, organisations have to work out which connections and interactions may have been affected. This is where availability and trustworthiness start to separate. A system can be technically available without being safe to use normally. 

Restoring access doesn't automatically restore confidence in what happened before, during or after the failure. And businesses behave very differently when they're no longer certain what they can trust.

Uncertainty Creates Operational Friction

Most digital transformation is designed to remove friction. Organisations automate approvals so people don't have to review every routine decision. They connect systems so information can move without being entered twice. They use single sign-on so employees don't repeatedly prove their identity. 

They give suppliers controlled access to shared platforms and build workflows that act automatically when certain conditions are met. Every one of those efficiencies depends on an assumption somewhere. The identity is legitimate. The data is accurate. The instruction is authorised. The integration is behaving as expected. 

Take away confidence in one of those assumptions and some of the efficiency has to disappear with it. Processes that normally run automatically may need human review. Transactions may need additional approval. Access may be restricted while identities are checked. 

Teams may fall back to manual processes while they establish which systems are safe to use. That work can spread quickly. The UK Government's Cyber Security Breaches Survey 2025/2026 found that 30% of businesses that identified a breach or attack experienced a wider impact. 

Sixteen per cent needed additional staff time to deal with the incident or inform customers and stakeholders, while 11% said employees were prevented from carrying out their normal work. Four per cent were temporarily unable to provide goods or services to customers.

Those figures help show why operational resilience can't simply mean getting a system back online. Sometimes the system isn't the only thing holding up normal operations. The organisation also needs enough confidence in its identities, information, processes and dependencies to start trusting them again. Until then, caution has an operational cost.

Operational Friction Becomes Business Exposure

Once normal processes start slowing down or stopping altogether, the consequences become easier to see outside security. Employees lose productive time. Orders aren't processed. Customers can't use services. Recovery work absorbs resources that would've been spent elsewhere. Revenue can be delayed or lost.

The UK Government's latest survey shows some movement here too. The proportion of businesses reporting lost revenue or share value after a breach or attack increased from 2% in 2024/2025 to 5% in 2025/2026. Reported reputational damage rose from 1% to 3%. Verizon's inaugural 2026 Breach Impact Study gives us another way to see the scale of the problem. 

Verizon and CyberAcuView analysed nearly 70,000 US cyber insurance claims, including more than 38,000 with recorded losses paid to policyholders. Across the historical dataset, half of paid-out claims had an estimated financial impact above $83,000. The top 10% exceeded $920,000, while the most extreme 2.5% exceeded $5 million. 

Verizon also warns that its figures don't include uninsured losses, reputational damage or other costs outside the claim, meaning they should be read as a potential floor rather than a complete measure of economic impact. Perhaps more revealing is what sits inside those losses. 

Business interruption had the highest median among the loss types Verizon analysed, at around $90,000. Its share of known loss types also rose from 21% in 2023 to 32% in 2024. That makes the relationship between security and business risk much clearer. The financial consequence isn't limited to fixing the thing that failed. 

It's also tied to what the business couldn't safely do while dealing with the failure. PwC's 2026 Global Digital Trust Insights points to a similar resilience problem from the other direction. Its survey of 3,887 business and technology executives across 72 countries found that only 6% considered their organisations very capable of withstanding cyber attacks across all the vulnerabilities surveyed. 

Yet only 24% were spending significantly more on proactive measures than reactive work such as incident response, fines and recovery. There is, however, another complication. Increasingly, the system an organisation loses confidence in may not belong to the organisation at all.

Enterprise Trust Extends Beyond The Enterprise

A modern enterprise can control its own environment reasonably well and still depend on a long list of things it doesn't control. Cloud providers host critical workloads. SaaS platforms run business processes. Payment providers handle transactions. Software vendors push updates. Logistics companies move physical goods. 

Suppliers connect into shared systems, while APIs and data services connect applications that may belong to entirely different organisations. The technical boundary of the enterprise and the operating boundary of the business are no longer the same thing. 

Allianz's Risk Barometer 2026, based on responses from 3,338 risk experts across 97 countries and territories, ranked cyber incidents as the world's biggest business risk for the fifth consecutive year. Business interruption, including supply chain disruption, ranked third. Allianz connects the two, pointing to growing reliance on third parties for critical data and digital services as a source of cyber and operational exposure.

Verizon's insurance data makes that relationship even more tangible. In 2024, it began tracking contingent business interruption, where an organisation's operations are disrupted because a third party goes down, as a separate loss category. It already represented 13% of known loss types that year. 

Across supply chain and third-party incidents in the study, business interruption accounted for half of known loss amounts. The 2025 Jaguar Land Rover cyberattack showed what this can look like outside a dataset. According to the World Economic Forum's Global Cybersecurity Outlook 2026, the attack halted JLR's global production for five weeks and affected more than 5,000 suppliers. 

JLR faced £196 million in cyber-related costs, while the wider UK economy absorbed an estimated £1.9 billion in losses. The important part isn't simply that one company suffered a large cyberattack. It's how quickly the consequences stopped belonging to one company. A business can inherit disruption from a supplier, just as its own problems can become someone else's. 

It can also inherit uncertainty. If a critical partner has been compromised, the organisation may need to reconsider connections, transactions or data it would've accepted without question the day before. This is why third-party risk is becoming so closely tied to enterprise resilience. 

Organisations aren't only trusting their own controls. They're building critical business processes around other organisations remaining dependable too.

Some Trust Takes Longer To Restore Than Systems

There is usually a point in recovery when the technology starts coming back. Accounts are restored. Applications reopen. Connections resume. Employees regain access. From a technical perspective, things may start looking normal again. But normal operation depends on more than availability. 

Security teams may be satisfied that an account has been secured before finance is comfortable accepting certain transactions. Employees may regain access before customers feel comfortable returning to a service. A supplier may reconnect before risk teams are ready to treat the relationship exactly as they did before.

Different groups also need different reasons to regain confidence. A technical team may want evidence that a vulnerability has been removed. A regulator may want proof of controls and accountability. Executives may need assurance that operations can resume without creating further exposure. Customers are unlikely to inspect any of those things themselves. 

They experience trust through something much simpler: whether the organisation behaves reliably. That makes trust recovery different from technical recovery. The distinction is easy to miss because technical restoration gives an organisation something concrete to measure. A service is either available or it isn't. Confidence is messier. 

It has to be rebuilt across groups with different concerns, different tolerances for uncertainty and different relationships with the organisation. The UK Government's 2025/2026 survey found customer complaints among 4% of businesses that had identified a breach or attack, while 3% reported reputational damage. 

Those percentages are relatively small across the whole sample, but they represent consequences that can't be fixed simply by restoring a server or resetting a password. And once recovery starts involving customers, partners, regulators, finance teams and operational leaders, the question of who owns the problem becomes much harder to answer.

Trust Failure Changes Who Has To Make Decisions

Are you enjoying the content so far?

Security teams can investigate what happened. They can contain compromised systems, assess technical exposure and help establish when an environment is safe again. They can't decide every consequence that follows. If a manufacturing process needs to restart while an investigation is still underway, somebody has to decide how much uncertainty the business is prepared to accept. 

If supplier access has been restricted, procurement and operations may need to decide which relationships are critical enough to restore first. If customers have been affected, legal, communications and customer teams become part of the response. Finance may need to assess losses. 

Executives may have to make continuity decisions. Regulators may require evidence that changes the order in which recovery work happens. The security incident may be the reason everyone is in the room, but the decisions are no longer purely security decisions. The World Economic Forum's 2026 research gives us an interesting clue about what more resilient organisations do differently. 

Ninety-nine per cent of respondents from organisations classified as highly cyber-resilient reported board involvement in cybersecurity. Those organisations were also more likely to involve security in procurement, assess supplier security, map ecosystem exposure and run incident exercises with partners.

That doesn't mean every security decision belongs at board level. It suggests something more useful: resilience improves when the organisation understands that different parts of the business own different pieces of the consequence. The harder governance question is therefore not simply who owns cybersecurity. 

It's who is authorised to make decisions when the organisation can't be completely certain that a system, identity, supplier or piece of information is trustworthy, but the business still needs to operate.

Resilience Depends On Knowing What The Business Can Still Trust

Most resilience planning begins with failure. 

  • What happens if this application goes down? 
  • How quickly can we restore that service? 
  • What's the backup? Where does the workload move? 
  • How long can the business operate without it?

Those are still important questions. But trust failure introduces another one. What happens if the system is available, but we aren't yet confident enough to use it normally? That changes the problem because the answer isn't always restoration. Sometimes the organisation needs to operate safely while confidence is incomplete.

Doing that requires a clearer understanding of which assumptions the business depends on. 

  • Which identities can approve critical actions? 
  • Which data feeds influence automated decisions? 
  • Which suppliers can interrupt essential services? 
  • Which systems can affect other systems without human review? 
  • Which processes become unsafe when the information flowing through them can no longer be accepted at face value?

The aim isn't to eliminate trust. Quite the opposite. Businesses need trust because constant verification would make many digital processes painfully slow or impossible to operate at scale. The challenge is knowing where trust has become so important that losing it would force the organisation to change how it works.

That is increasingly part of enterprise resilience. A resilient organisation doesn't only know how to restore technology after something breaks. It knows enough about its dependencies to establish what remains dependable, what needs additional verification and which operations can continue safely while uncertainty is being resolved.

As automation grows and more decisions move between connected systems without constant human involvement, that ability will become harder to separate from business continuity itself.

Final Thoughts: Trust Has Become An Enterprise Dependency

Trust tends to disappear into the background when it's working. Employees sign in. Systems exchange information. Suppliers connect. Automated workflows make thousands of small decisions. Nobody stops every few minutes to prove that each part of the process still deserves to be trusted, because the business couldn't operate that way.

That efficiency comes with a trade-off. The more an organisation depends on trusted identities, data, systems and relationships, the more it has riding on those assumptions remaining reliable. When one fails, the consequence isn't defined only by how difficult the original problem is to fix. It's also shaped by how much of the business has learned to depend on it.

That is why digital trust is becoming an enterprise resilience issue as much as a security one. The next challenge isn't to build an organisation that never experiences a failure of trust. No security programme, supplier strategy or technology architecture can promise that. It's to build one that understands its dependencies well enough to keep making sound decisions when something it normally trusts can no longer be taken for granted.

As those dependencies change, EM360Tech will continue examining what they mean for the technology, security and business leaders responsible for keeping increasingly connected enterprises running.