Intelligent CISO Issue 100 | Page 50

S P E C I A L R E P O R T
Chris Cochran, Field CISO at SANS Institute, agrees that resilience depends on mastering the fundamentals.
“ The next generation of cyber-resilience will be defined by how well organisations execute on the fundamentals.”
That begins with understanding assets, identities and third-party dependencies before moving to risk-based vulnerability management and well-rehearsed incident response.
“ You cannot protect what you don’ t know you have.”
Ellen Benaim, CISO at Templafy, believes many organisations still struggle with those same fundamentals despite increasingly sophisticated threats.
“ What will define the next generation of cyberresilience isn’ t yet another new technology, but getting the basics right at the speed the threats demand.”
Maintaining accurate asset inventories, enforcing access controls and patching vulnerabilities remain difficult for many organisations, yet the shrinking window between disclosure and exploitation has made those disciplines more important than ever.
“ The cost of getting those basics wrong has gone up substantially because the time between a vulnerability existing and someone exploiting it has collapsed from weeks to hours.”
AI is accelerating both sides of the battle
While our contributors consistently stressed the importance of strong fundamentals, they also agreed that Artificial Intelligence is fundamentally changing the pace of cybersecurity.
Mike Riemer, Senior Vice President, Network Security Group and Field CISO at Ivanti, believes traditional patch management is struggling to keep pace.
“ AI is accelerating the discovery and exploitation of vulnerabilities, with threat actors now able to reverse engineer a patch within hours.”
He warned that security teams are facing what many describe as a‘ Patch Apocalypse’, with critical updates arriving faster than many organisations can deploy them.
Rather than relying on static severity ratings, Riemer argued that resilience increasingly depends on continuous visibility, risk-based prioritisation and autonomous remediation.
“ Attackers are already operating at machine speed. Defenders need the intelligence and tools to know what to fix first and the automation to act before it’ s too late.”
Attila Török, CISO at GoTo, sees a similar future.
“ The next generation of cyber-resilience will be defined by three things: machine-speed incident detection and response, patching instantly instead of in weeks or months, and true Zero Trust that is designed for breach.”
He believes organisations should automate wherever possible while ensuring Artificial Intelligence itself is introduced with appropriate governance and secure-by-design principles.
Patricia Titus, Field CISO at Abnormal AI, also views AI as both the greatest challenge and one of the strongest defensive opportunities.
“ What protected organisations yesterday won’ t be enough tomorrow.”
Rather than replacing security professionals, she believes AI should automate repetitive investigations, reduce alert fatigue and allow analysts to focus on the highest-risk threats.
“ The most resilient enterprises will be those that view AI as a force multiplier for their security teams, not a substitute for them.”
Benaim believes organisations face what she describes as an AI paradox.
“ The thing that could save you is also the thing you’ re trained to distrust.”
Security teams recognise AI’ s potential to strengthen defence, yet every deployment introduces new governance challenges. Organisations that successfully balance innovation with sensible guardrails, she argued, will gain an advantage over those waiting for perfect certainty before adopting AI.
Identity becomes the new frontline
If there is one area where contributors see cyber-resilience evolving most rapidly, it is identity.
For years, organisations concentrated on protecting networks and endpoints. Increasingly, however, attackers are bypassing traditional defences by exploiting legitimate credentials, compromised accounts and the growing population of machine identities operating across enterprise environments. As AI agents become embedded within business processes, contributors believe identity will become the defining battleground of cyber-resilience.
50 WWW. INTELLIGENTCISO. COM