Sustainable Cyber Resilience: Why Protecting Your Data and Protecting the Planet Are the Same Job
- Aug 12
- 11 min read
A few years ago, cybersecurity and sustainability lived in completely separate parts of most organizations. One team worried about firewalls and phishing emails. Another team worried about energy bills and carbon reports. They rarely spoke to each other, sat in different meetings, and reported up through different chains of command.
That gap is closing fast, and for a very good reason. Every server that gets hacked, every device that gets thrown away with its data still inside, and every data center that runs day and night on dirty power is both a security problem and an environmental one. The two risks are tangled together, and treating them separately means missing half the picture.
This article walks through what "sustainable cyber resilience" actually means, why it's becoming a real business priority, and, most importantly, what you can actually do about it, whether you're a household, a small business, or an organization managing thousands of devices.
Cyber resilience is no longer just about keeping hackers out. It's about building digital systems that can take a hit, recover quickly, and do it all without wasting energy or materials.

1. The Scale of the Problem: Why This Matters Right Now

Cyberattacks are getting more expensive, more frequent, and harder to prevent, and the digital infrastructure we use to fight them is quietly generating a lot of environmental damage of its own.
Start with the cyber risk side. Munich Re's 2026 Global Cyber Risk and Insurance Survey, based on responses from over 9,500 executives in 20 countries, found that cyber resilience is now widely treated as a core corporate priority, but preparedness still lags badly behind concern. A striking 89% of senior executives admitted their organization's current level of protection is not adequate.¹ Meanwhile, global cybercrime costs are projected to reach roughly US$14 trillion by 2028, a figure that, if cybercrime were a country's economy, would rank it third in the world, ahead of Japan and Germany combined.¹
Allianz Commercial's 2025 resilience report adds a sharper edge to this picture. Ransomware alone accounted for around 60% of the value of large insurance claims in the first half of 2025, and the number of active ransomware groups grew by roughly 50% in a single year.³ Attackers are also shifting their attention away from large, well defended corporations and toward mid sized and smaller firms that have fewer resources to protect themselves. Ransomware was involved in 88% of data breaches at small and medium sized companies, compared with 39% at large ones.³ That matters for this article because small organizations, the very ones with the least bandwidth to fix problems twice, are exactly the ones facing both rising cyber exposure and mounting pressure to manage devices and energy responsibly.
Now add the environmental side. Global data centers consumed around 415 terawatt hours of electricity in 2024, about 1.5% of the world's total electricity use, and that number is expected to roughly double by 2030 as AI adoption accelerates.⁹ On the hardware side, the world generated 62 million tonnes of electronic waste in 2022, equivalent to throwing away over 100,000 fully loaded jumbo jets, and less than a quarter of it was properly collected and recycled.⁸ That electronic waste contains both valuable recoverable metals and, when it isn't handled properly, toxic materials that leak into soil and water.
Here's the part that connects the dots: unpatched, outdated, or poorly managed devices are both an environmental liability (they get replaced faster, discarded carelessly, or run inefficiently) and a security liability (old hardware and abandoned accounts are exactly what attackers look for). A device sitting in a drawer or a landfill with its login credentials still active isn't just clutter. It's an open door.
Cybersecurity and environmental waste are rising together, driven by the same root cause, a "buy it, use it, toss it" approach to technology that leaves both security gaps and environmental damage in its wake.
2. What "Sustainable Cyber Resilience" Actually Means

Sustainable cyber resilience means designing, running, and governing digital systems so they are secure, able to recover from disruption, and environmentally responsible at the same time, not treating those as three separate goals.
This idea has a clear practical definition drawn from industry standards work. According to a framework developed by Underwriters Laboratories (UL), a global safety science and standards organization, green or sustainable cybersecurity rests on four connected pillars:⁵
Energy efficiency. Inefficient systems draw more power, which raises both cost and the attack surface, since organizations often scale up capacity quickly without adding solid security controls to match.
Device life cycle and longevity. Hardware that gets replaced quickly means faster replacement cycles, and more devices in circulation means more chances for misconfiguration, abandoned accounts, and improper disposal.
Software efficiency. Code that runs lean and needs fewer emergency updates, balanced against the need to avoid rushed patches that accidentally introduce new vulnerabilities.
Resilient, transparent supply chains. Vulnerabilities can hide deep inside hardware or firmware components sourced from outside vendors, invisible until it's too late.
It's worth separating two related but different ideas here, because they get mixed up a lot:
Cybersecurity is about preventing attacks from succeeding in the first place.
Cyber resilience is about accepting that no security system is airtight, and building the capacity to withstand, recover from, and adapt to an attack when, not if, one gets through.⁵
Sustainable cyber resilience adds a third layer on top: making sure the systems, devices, and practices you use to achieve both of the above don't quietly generate an outsized environmental footprint of their own. It's not enough to be secure and resilient if getting there requires burning through hardware and energy at an unsustainable pace. And it's not enough to be efficient and low impact if that efficiency comes at the cost of leaving systems exposed.
Think of it as a three legged stool: prevention, recovery, and environmental responsibility. Remove any one leg and the whole approach becomes unstable.
3. Real Examples: Where Cyber Risk and Environmental Waste Meet

These aren't abstract, future problems. They're already showing up in homes, businesses, and supply chains today.
Smart home devices. Picture a family that throws away a smart speaker after it slows down. The device still has active accounts and forgotten login credentials stored on it. It ends up in a recycling bin, an attacker finds it, and a month later sensitive recordings tied to that old account are exposed, all while the manufacturing and disposal of that same device left a growing carbon footprint behind it.⁶ That single scenario is a privacy breach, a resilience failure, and an environmental problem, all caused by one careless decision made at the moment of disposal.
Data centers. Older, poorly optimized data centers tend to run inefficient cooling systems alongside legacy servers that are both expensive to run and insecure, because they're harder to keep patched. In one real consolidation project, moving workloads to a more efficient cloud provider and enforcing standard security hardening templates cut energy use significantly and reduced the number of unpatched legacy servers by roughly two thirds, lowering carbon emissions and shrinking the attack surface in a single move.⁶
IoT devices in general. Cheap, narrowly built smart devices such as cameras, doorbells, and sensors often lack long term firmware support. When a device is abandoned rather than properly decommissioned, its credentials are rarely reset, and it quietly becomes a weak link sitting on the network. Extending the useful life of devices through repair, choosing vendors with clear long term update commitments, and isolating IoT devices on a separate network all reduce risk and waste at the same time.⁶
Supply chains. A manufacturer might rely on a low cost component that depends on an outside cloud service. If that outside party has weak credential management practices, the resulting vulnerability doesn't stay contained. It travels into every product built on that component, multiplying exposure across an entire product line.⁶ This is exactly why insurers are increasingly asking about sustainability metrics alongside standard cyber hygiene questions: companies that manage energy use and device life cycles carefully also tend to be better organized generally, which in practice makes them lower risk to insure.⁶ Allianz's own claims data backs this up in a related way: supply chain and business interruption losses have become one of the fastest growing categories of large claims, as attackers realize that hitting one weak vendor can compromise dozens of downstream companies at once.³
The same neglect, not tracking devices, not planning for end of life, not vetting suppliers, creates both the cybersecurity gap and the environmental cost. Fixing one usually helps fix the other.
4. The Regulatory Push: The EU Cyber Resilience Act

Governments are starting to treat weak cybersecurity and poor device life cycle management as a single regulatory problem, and that's changing what "compliant" actually means for manufacturers.
The European Union's Cyber Resilience Act (CRA), formally Regulation (EU) 2024/2847, entered into force in December 2024 and applies in full from December 2027, with earlier obligations phasing in from mid 2026.² It sets horizontal cybersecurity requirements for essentially any product with digital elements sold in the EU, everything from smart appliances to industrial software.
Two aspects of the CRA are especially relevant to the sustainability angle:
Support periods. Manufacturers are required to think seriously about how long they will provide security updates for a product, rather than leaving it undefined. This directly discourages the sell it and forget it model that leads to devices being abandoned, insecure and unsupported, while still in active use.²
Free and open source software. The Commission's guidance dedicates significant attention to how the CRA applies to open source components, recognizing that most digital products are built on a mix of proprietary and community maintained code, and that the security of that shared code affects everyone downstream.²
ENISA's NIS360 report reinforces why this kind of regulation is arriving now rather than later. The report tracks resilience maturity across sectors that are critical to society, and it consistently finds that the sectors most exposed to disruption are also the ones with the least visibility into their own supply chains and device inventories.⁴ In other words, you can't manage what you can't see, and a lot of organizations simply don't have a clear picture of every device, vendor, and piece of software they depend on.
This regulatory direction matters for anyone thinking about sustainable cyber resilience because it formalizes something the industry has been circling for a while: a product's expected lifespan, its update policy, and its security posture are no longer separate questions. They're the same question, asked from different angles.
Rules like the CRA are pushing "how long will you support this device" to sit right next to "how secure is this device," which is exactly the mindset shift sustainable cyber resilience is built on.
5. How to Actually Build Sustainable Cyber Resilience

This is where theory turns into action. Below are concrete steps for three different audiences, because "be more resilient" means different things depending on how much infrastructure you're responsible for.
For individuals and families
Reset and wipe devices before disposal. Never hand off, sell, or recycle a device, whether it's a phone, router, smart speaker, or old laptop, without a full factory reset that clears saved credentials.⁶
Choose vendors with clear update policies. Before buying a smart device, check how long the manufacturer commits to providing firmware and security updates.⁶
Use unique passwords and a separate guest network for IoT devices. This limits how far an attacker can move if one device is compromised.⁶
Repair instead of replace where possible. Extending a device's working life reduces both electronic waste and the number of new devices you have to secure and manage.⁶
For small businesses
Ask procurement questions before buying. Push vendors on expected device lifespan, energy consumption, and update commitments as part of the purchasing decision, not as an afterthought.⁶
Prioritize patches by impact. Focus first on devices that are both widely deployed across your operation and energy hungry, and stagger updates to minimize disruption.⁶
Run resilience drills that include supply chain failure. Test what happens not just when your own systems fail, but when a key vendor's systems fail or a device reaches unexpected end of life.⁶
Use certified electronic waste and data destruction partners for disposal. A recycling partner that certifies proper data destruction protects you legally and environmentally at the same time.⁶
For larger organizations and IT and security leaders
Strengthen the fundamentals first. Identity and access management gaps remain one of the most common weaknesses behind major incidents. Allianz's 2025 data shows stolen credentials have overtaken malware as the leading way attackers gain initial access, which means getting the basics right matters more than chasing advanced tools.³
Model the financial impact of realistic scenarios, not just the probability of an attack. Ransomware, data breaches, and operational technology disruptions all have very different recovery timelines and costs. Understanding the impact side lets you prioritize investment sensibly.⁷
Map your IT and OT interdependencies before an incident forces you to. Analysis of past incidents shows a majority of operational technology disruptions actually originate as IT only events that cascade, meaning many organizations don't fully understand how their operational systems depend on IT infrastructure until it's too late.⁷
Track a small set of combined metrics that show both carbon and cyber exposure on the same dashboard, for example energy consumed per transaction, the age of your patch backlog, and the percentage of devices still covered by vendor support.⁶ Seeing both risks side by side helps leadership make trade offs consciously instead of by accident.
Run tabletop exercises regularly. A resilience culture isn't built by writing a policy document. It comes from practicing, repeatedly, what your organization would actually do on a bad day, and Allianz specifically flags tabletop exercises as one of the most effective ways to reduce the eventual cost of a claim.³ ⁷
Whatever scale you operate at, the same five actions repeat in different forms: know what devices you have, plan for their end of life, patch deliberately, test your response, and dispose of things responsibly.
6. The Circular Economy Angle: Designing Out Waste From the Start

Beyond fixing individual devices, there's a bigger shift underway: rethinking how products are designed so waste, and the security risk that comes with it, never gets created in the first place.
Most of the modern economy still runs on a linear model: extract a raw material, make a product, use it, throw it away. A circular economy tries to bend that line into a loop. Instead of discarding a product at the end of its life, it becomes the feedstock for another use, another life, another product.⁵
This is genuinely difficult to pull off, because circularity requires rethinking product design, energy use, and financing all at once.⁵ But there are already concrete examples of it working in the security and sustainability space:
Second life batteries. UL 1974 is a standard developed specifically to reassess lithium ion batteries that have finished their first life in an electric vehicle. Instead of scrapping them, they can be combined with other used batteries to build large scale energy storage systems, but because that's not what they were originally designed for, they need to be safety reassessed for the new use case first.⁵
Right to repair. Legislation increasingly allows consumers and independent repair shops to fix devices th
at manufacturers previously required you to send back to them. That extends product life significantly, but it also raises new questions about whether a device repaired with parts from an outside supplier is still as safe and secure as the original.⁵
Circularity scoring. UL has been developing a standard, UL 3600, intended to give organizations a measurable score for how circular their company, product, or facility actually is, covering areas like water use, energy use, air quality, and social impact, so that "more sustainable" becomes something you can actually measure and improve, rather than just a slogan.⁵
A circular approach to technology doesn't just reduce waste. It forces a more disciplined relationship with your devices, which naturally closes off a lot of the security gaps that come from set it and forget it hardware.
Key Takeaways
Cyber risk and environmental waste share the same root cause. Devices and systems that are neglected, poorly tracked, or disposed of carelessly create both security exposure and unnecessary environmental damage.
Sustainable cyber resilience has four practical pillars: energy efficiency, device life cycle and longevity, software efficiency, and transparent, resilient supply chains.
The gap between confidence and actual preparedness is large. The vast majority of executives surveyed globally don't consider their organization's protection adequate, even as they recognize cyber risk as a top priority, and ransomware groups are growing in number and sophistication.
Regulation is catching up. Frameworks like the EU's Cyber Resilience Act are formally linking product lifespan and update commitments to cybersecurity compliance, treating them as one issue, not two.
Practical action scales down to everyone. Wiping old devices before disposal, choosing vendors with clear update policies, isolating smart devices on separate networks, and running regular resilience drills apply whether you're managing a household or an enterprise network.
Circularity and security reinforce each other. Designing products for longer life, repairability, and safe second life use closes off many of the vulnerabilities created by rapid, careless device turnover, while also cutting electronic waste.
References
Munich Re. Global Cyber Risk and Insurance Survey 2026 (4th edition). Survey of over 9,500 respondents across 20 countries.
European Commission. Communication to the Commission, Guidance on the application of Regulation (EU) 2024/2847 (Cyber Resilience Act), C(2026) 5252 final, 27 July 2026.
Allianz Commercial. Cyber Security Resilience 2025: Claims and Risk Management Trends report.
ENISA (European Union Agency for Cybersecurity). NIS360 report, May 2026.
Underwriters Laboratories (UL). "Future of Safety Science" webinar series, Cybersecurity and Sustainability, presented by Denise Durant and Caroline Truehart.
Cyber Voices podcast, episode on green cybersecurity, hosted by Andrea Garcia.
Risk Management Show podcast, interview with David White, President and Co Founder of Axio, on cyber risk quantification and resilience frameworks.
UNITAR and ITU. Global E waste Monitor 2024.
International Energy Agency (IEA). Energy and AI report; Electricity 2026 report.




Comments