Sommerville (2015): "The ability to maintain continuity of critical services in the presence of disruptive events"
Market Reality: Companies that focus only on prevention lose $2.5M per hour during unexpected failures.
⚖️ Resilience vs Reliability vs Security
افهم
University Tool: Comparative Analysis Market Test: Choosing the Right Approach
🎮 Live Simulation: The Banking Problem (5 mins)
⏱️ Timer: 5:00
(Adapt for online/in-person; simulate with scenarios)
Scenario: You're designing Al Rajhi Bank's system
Reliability approach: 99.999% uptime servers
Security approach: Military-grade firewalls
Resilience approach: Backup systems + manual procedures
Challenge: Sophisticated attack happens anyway!
A) Reliability saves you (servers don't fail)
B) Security saves you (firewall blocks it)
C) Resilience saves you (backup systems activate)
D) Nothing helps
Why Option C? Resilience assumes failures WILL happen and prepares recovery. Reliability (A) can't prevent new attacks. Security (B) can be bypassed. Only resilience (C) ensures continuity.
Market Reality: SAMA now requires all banks to have resilience plans, not just security.
Key Differences
Aspect
Reliability
Security
Resilience
Goal
Prevent failures
Prevent attacks
Survive anything
Assumption
We can eliminate faults
We can block threats
Failures WILL happen
Focus
Technical perfection
Access control
Recovery & adaptation
Saudi Example
STC 5-nines uptime
NCA frameworks
Shamoon recovery
Islamic Principle
إتقان (Perfection)
حماية (Protection)
صبر واستعداد (Patience & Prep)
إِنَّ مَعَ الْعُسْرِ يُسْرًا
"Indeed, with hardship comes ease" - Qur'an 94:6
(Transliteration: Inna maʿa l-ʿusri yusrā)
🔄 The 4 Rs Framework
مارس
University Tool: Framework Application Market Test: Incident Response Planning
The 4 Rs in Action
👁️
Recognition
Detect problems
→
🛡️
Resistance
Reduce impact
→
🚑
Recovery
Restore critical
→
🔧
Reinstatement
Full restoration
🎭 Role Play: Apply 4 Rs to Absher Outage (4 mins)
⏱️ Timer: 4:00
(Adapt for online/in-person)
Scenario: Absher is under DDoS attack during Eid travel rush
Team Roles:
Recognition Team: How do you detect the attack?
Resistance Team: What immediate defenses activate?
Recovery Team: Which services restore first?
Reinstatement Team: How do you return to normal?
Recognition: Traffic monitoring alerts, response time degradation Resistance: Rate limiting, CDN activation, traffic filtering Recovery: Critical services (passport renewal) first, non-critical later Reinstatement: Full services restored, logs analyzed, defenses improved
Saudi Implementation Examples
System
Recognition
Resistance
Recovery
Reinstatement
SADAD
Transaction monitoring
Load balancing
Priority payments
Full service
Tawakkalna
Health alerts
Backup servers
Core permits
All features
Hajj Systems
Crowd sensors
Overflow handling
Safety first
Normal flow
Market Reality: Companies with mature 4Rs frameworks reduce incident costs by 60%.
👥 Sociotechnical Resilience
مارس
University Tool: Systems Thinking Market Test: Human-System Integration
💭 Think About It: Why Do Systems Really Fail? (3 mins)
⏱️ Timer: 3:00
Discuss with your neighbor:
When was the last time pure technology failure caused a disaster?
How many failures involve human factors?
Can we eliminate human error?
Key Insight: "People are very good at adaptation. Software is not."
Resilience requires both technical systems AND the humans who operate them.
The Human Factor
❌ Person Approach
Blame individuals for errors:
"Operator mistake"
Punishment & retraining
Same errors repeat
Islamic view: ظلم (Injustice)
✅ Systems Approach
Accept human fallibility:
Design better systems
Multiple safeguards
Learn from failures
Islamic view: رحمة وحكمة (Mercy & Wisdom)
Market Reality: 70% of security breaches involve human factors, not technical failures.
Industry Tool: Use chaos engineering (Chaos Monkey) to test human-system resilience.
🧀 Swiss Cheese Model
اتقن
University Tool: Defense in Depth Market Test: Layered Security Design
🧀 Live Demo: Build Your Defense (5 mins)
⏱️ Timer: 5:00
(Adapt for online/in-person; use paper or digital boards)
Activity: Design defense layers for a Saudi bank
Draw 5 cheese slices (defense layers)
Put holes in each (vulnerabilities)
Arrange so holes don't align
Label each layer (firewall, auth, encryption, etc.)
Swiss Cheese Visualization
Firewall
Auth
Encryption
Monitoring
→
Failure only when ALL holes align!
Applied to Saudi Systems
Layer
Defense
Vulnerability (Hole)
Backup Layer
1. Network
Firewall
Zero-day exploits
IDS/IPS
2. Application
Input validation
Logic flaws
WAF
3. Identity
Nafath 2FA
SIM swapping
Biometrics
4. Data
Encryption
Key theft
Access logs
5. Human
Training
Social engineering
Verification procedures
🤔 How many layers should you have?
A. As many as possible
B. Enough to prevent alignment, balanced with usability
C. Exactly 5 layers
D. One strong layer is enough
🏗️ Designing Resilient Systems
اتقن
University Tool: Architecture Design Market Test: Production System Building
Critical Service Identification
🎯 Prioritization Exercise: Hajj Systems (4 mins)
⏱️ Timer: 4:00
You manage Hajj digital services. Rank by criticality:
Management: "Waste of paper! Everything is digital!"
Controllers: "When system crashed in 2019, paper saved lives!"
Question: What would you decide and why?
Balanced Approach: Keep paper for critical flights, reduce for routine. Cost of paper < cost of one crash. Islamic principle: الاحتياط (precaution) is wisdom.
خُذِ الْعَفْوَ وَأْمُرْ بِالْعُرْفِ
"Take what is given freely, enjoin what is good" - Qur'an 7:199
Balance between extremes is the Islamic way
🇸🇦 Saudi's Resilience Revolution
ميز
Vision 2030: From Shamoon victim (2012) to global resilience leader
🛢️ Aramco 2.0
Zero
Production impact from cyber
35,000 PCs destroyed
Oil never stopped
2-week recovery
Now: Quantum-ready
🏙️ NEOM Resilience
100%
Self-healing infrastructure
AI-powered recovery
Predictive resilience
Zero-downtime goal
Human-AI partnership
🕋 Hajj Systems
3M+
Pilgrims protected
Crowd AI monitoring
Health tracking
Multi-language support
24/7 resilience
🏦 Financial Resilience
99.99%
SAMA uptime requirement
Real-time backup
Cyber resilience drills
48-hour recovery
Global standards
Innovation Showcase
Saudi's National Cybersecurity Authority (NCA) Essential Cybersecurity Controls (ECC) now mandates resilience planning for all critical sectors.
💼 Your Resilience Engineering Career Path
ميز
12-Month Roadmap to Excellence
Months 1-3: Foundation
Master Chapter 14 concepts
SANS resilience training
Chaos engineering basics
Months 4-6: Certifications
ISO 22301 (Business Continuity)
CISSP concentration
NCA ECC certification
Months 7-9: Real Experience
Internship at NCA/Aramco
Incident response team
Tabletop exercises
Months 10-12: Leadership
Design resilient system
Present at GISEC
Mentor junior engineers
Saudi Career Opportunities
Company
Role
Salary (SAR)
Growth
Saudi Aramco
Resilience Engineer
380,000+
Extreme
NEOM
Infrastructure Resilience Lead
420,000+
Extreme
NCA
Cyber Resilience Specialist
320,000
Very High
SAMA
Financial Resilience Analyst
290,000
High
STC
Network Resilience Engineer
280,000
High
📝 Assignment: Design Resilient National System
ميز
Design a complete resilient system for Saudi Arabia's critical infrastructure
Choose ONE National Challenge:
💳 SADAD payment network
🚗 Absher services platform
📱 Tawakkalna health system
🏥 Sehhaty medical records
✈️ GACA air traffic control
🏦 SAMA banking network
Deliverables (EMAM Framework)
Phase
Weight
Requirements
Rubric
افهم
20%
Why resilience > security, threat analysis
Clear analysis with Saudi context – 10/20; Islamic principles – 10/20
Must include: Chaos testing scenarios, recovery procedures
Bonus: Working prototype, AI-powered resilience
Tools to Use
Chaos Monkey for testing
Kubernetes for container resilience
Terraform for infrastructure as code
Prometheus for monitoring
🎯 Key Takeaways - Chapter 14 Mastery
Summary: "Resilience engineering accepts that failures are inevitable and focuses on maintaining critical services through recognition, resistance, recovery, and reinstatement" (Sommerville, 2015)
🧠 Core Concepts
• Resilience > Security
• Accept failure
• Human factors