Intelligent CISO Issue 100 | Page 49

S P E C I A L R E P O R T
Prevention alone is no longer enough Understanding what really matters
Perhaps the biggest shift is one of mindset.
Justin Henkel, CISO at SolarWinds, believes organisations must stop measuring resilience by the number of attacks they prevent.
“ If you’ ve worked in cybersecurity long enough, you know no organisation is completely immune from attack,” he said:“ For me, the next generation of cyber-resilience is not about preventing every incident. It is about how quickly you can identify a problem, contain it, keep critical services running and recover with confidence.”
John Bruce, CISO at Quorum Cyber, argues that boards are beginning to recognise the same reality.
“ For years, cyber-strategy has been built around a flawed premise: that with enough investment in prevention, breaches can be stopped at the perimeter,” he said.
Instead, directors are beginning to ask a different question.
“’ How quickly can we get back up if we’ re not?’”
Bruce believes that change should redirect investment towards recovery readiness, tested backups and rapid detection rather than continually adding another preventative layer.
Joseph Rooke, Director of Risk Insights at Recorded Future’ s Insikt Group, has also seen resilience move beyond the security team.
“ Rather than asking,‘ can we stop a breach?’, CISOs are prioritising strategies and plans for keeping operations running when a breach is happening.”
As a result, cyber-resilience has become a boardroom issue spanning business continuity, insurance, supply chains, dependency mapping and contingency planning.
Tom Burton, vCISO Associate at Cyberhash, believes Artificial Intelligence makes this evolution unavoidable.
“ My preferred phrase from that report is‘ assume breach’,” he said, referencing the UK National Cyber Security Centre’ s latest annual review.
However, Burton believes organisations should go one stage further.
“ Because of the acceleration of AI, I believe that the next generation of cyber-resilience is based on an updated principle called‘ Assume breach, assume vulnerabilities’.”
Once attackers gain an initial foothold, organisations should assume they will rapidly identify and exploit every available weakness. Resilience therefore depends on segmentation, Zero Trust, contingency planning and operational visibility rather than perimeter security alone.
If attacks are inevitable, resilience starts with identifying the business services that matter most.
“ The next generation of cyber-resilience won’ t be defined by what you buy,” he said.“ It will be defined by how well you understand the services your business cannot lose, everything they depend on, and how you keep them running the day something goes wrong.”
Drawing on his experience, Manar recalled helping investigate an incident in which an organisation transferred millions of dollars to criminals following what appeared to be a legitimate executive request.
“ There was no malware or security hurdle to overcome. The attackers used the path money already travels.”
The organisation had never mapped that business process.
“ Nobody had ever mapped that path, so nobody was defending it.”
For Manar, resilience starts by identifying where the organisation would suffer most if operations stopped.
Jason Manar, CISO at Kaseya, believes too many organisations focus on technology before understanding the business processes they are trying to protect.
“ Start where the money moves, or wherever your business would bleed first.”
Security leaders should then identify every dependency supporting that critical service.
“ Build the dependency map for that one service: not just the systems, but identities, suppliers and the people who make the calls.”
Although dependency mapping is rarely straightforward, particularly in organisations with legacy technology and competing priorities, Manar believes the effort pays dividends.
“ The work is unglamorous and hard.”
The next generation of cyberresilience won’ t be defined by what you buy.
“ Resilience isn’ t a product you buy; it’ s a discipline you keep.”
WWW. INTELLIGENTCISO. COM 49