Intelligent CISO Issue 100 | Page 54

S P E C I A L R E P O R T
“ Lastly, test it.”
Executive simulations and technical exercises, Glavach argued, transform resilience from an aspiration into an operational capability.
Mike Riemer also believes continuous operations must replace reactive security.
Rather than relying on vulnerability scores alone, organisations require continuous risk prioritisation based on exploitability, threat intelligence and business impact.
Jack Thompson, Field CISO at Cynomi, believes proactive verification fundamentally changes security operations.
“ Continuous verification of your environment reduces the volume of alerts that need human eyes.”
Combined with User Behaviour Analytics, organisations can improve detection quality while reducing alert fatigue.
The message from our contributors is consistent: resilience is no longer something organisations assess annually but a capability they continuously measure, validate and improve.
As AI coding tools become widely available, software development is expanding beyond traditional engineering teams, creating new risks when inexperienced users generate production code without fully understanding secure development practices.
Dean noted that enterprise applications are increasingly custom-built, yet software quality processes have failed to keep pace with AI-assisted development.
For CISOs, that reinforces the importance of embedding security throughout the software development lifecycle rather than relying on testing at the end of a project.
“ As AI accelerates software delivery, security and software quality can no longer operate as separate disciplines.”
Clayton Peddy, CISO at ABBYY, believes organisations must also rethink where cyberresilience begins.
Rather than focusing exclusively on endpoints and networks, businesses should pay closer attention to the information entering their systems. manipulated files can contaminate fraud detection, compliance processes and business analytics before conventional security controls detect a problem.
“ The answer isn’ t simply deploying more AI,” Peddy said:“ It’ s investing in purpose-built AI designed for document intelligence and authenticity verification.”
By validating documents before they enter automated workflows, organisations create what he describes as“ a trusted foundation for every downstream security control.”
Intelligence moves beyond cybersecurity
Another clear theme emerging from our contributors is that cyber-resilience increasingly depends on understanding risks extending beyond traditional cybersecurity.
Andy Grayland, CISO at Silobreaker, believes organisations need to broaden both the scope and audience of threat intelligence.
Software resilience becomes business resilience
While much of the cyber-resilience conversation centres on attackers, identities and infrastructure, several contributors argued that organisations also need to rethink how they build, validate and trust the software and data driving every business process.
Erika Dean, CISO at Tricentis, believes Artificial Intelligence is fundamentally changing software development and creating a new balance between speed and assurance.
“ Cyber-resilience has always required the management of both internal and external risks,” she said:“ What has changed is the speed at which AI is enabling software to be created, and the difficult subsequent trade-offs between speed and assurance this creates.”
“ The next generation of cyber-resilience won’ t be defined solely by stronger perimeter defences or faster incident response. It will be defined by an organisation’ s ability to trust the data flowing into its business before automated decisions are made.”
As financial institutions and other organisations automate document processing,
Cyber-only intelligence is a cost centre. Business risk intelligence is a strategic asset.
“ The next generation of cyber-resilience will not be defined by better firewalls or faster detection. It will be defined by intelligence scope.”
Many cyberthreat intelligence programmes remain heavily focused on indicators of compromise, threat actor tactics and vulnerability data.
While valuable, Grayland argued that this provides only part of the picture.
“ Nation-state actors do not choose one domain; they operate simultaneously across cyber, physical and geopolitical space.”
Political developments, economic sanctions, supply chain disruption and geopolitical tensions frequently provide early indicators of future cyber-campaigns.
For that reason, he believes resilience depends on combining intelligence from multiple disciplines and ensuring it reaches decision-makers beyond the security team.
54 WWW. INTELLIGENTCISO. COM