S P E C I A L R E P O R T
attacks occur while helping security teams prioritise the risks that matter most.
Preparing for tomorrow’ s cryptographic challenge
Although Artificial Intelligence dominates today’ s security agenda, several contributors warned that organisations must not lose sight of another major technology transition already approaching.
Jonathan Nguyen-Duy, CTO at Arqit, believes Quantum Computing will redefine resilience planning over the coming decade.
“ The next generation of cyber-resilience will be defined by whether organisations can maintain operations in the face of traditional and emerging cyberthreats, while keeping pace with new developments in quantum technology.”
Many organisations continue to struggle with cyber-fundamentals such as multi-factor authentication and Zero Trust, yet Nguyen-Duy believes they must also begin preparing for Q-Day, when quantum computers become capable of breaking current encryption standards.
“ The first investment they must make is one to improve crypto visibility and control.”
Without understanding where cryptography exists throughout their environments, organisations cannot develop effective post-quantum migration strategies.
Patricia Titus also believes Quantum Computing should already feature in resilience planning.
Looking beyond today’ s AI-powered attacks, she argued organisations should begin identifying where cryptography is used, engaging suppliers on their quantum readiness and developing long-term migration strategies before the technology matures.
Technology alone will never deliver resilience
Despite discussing Artificial Intelligence, Zero Trust, software supply chains and Quantum Computing, contributors repeatedly returned to one conclusion: cyber-resilience is ultimately a people and governance challenge.
Brad Bowers, Lead Field CISO Global at SHI, believes resilience extends well beyond an organisation’ s ability to recover from breaches.
“ It’ s important that the industry doesn’ t just define resiliency as the ability to recover from data breaches.”
Instead, organisations must continue strengthening cyber-hygiene, employee awareness, incident response planning and third-party risk management while ensuring AI itself operates transparently and under appropriate governance.
“ The future of cyber-resiliency will require a collaborative approach.”
Martin Kraemer also believes trust will become one of the defining challenges of the AI era.
“ The key to resilience is building trust into a digital workforce to behave securely.”
As organisations increasingly supervise AI agents rather than carrying out every task manually, governance models based solely on human oversight will become increasingly difficult to sustain.
“ Organisations must find holistic governance and risk management solutions to reap the benefits of AI and maintain trust with their workforce.”
Chris Cochran believes investing in people remains just as important as investing in technology.
“ Burned-out, under-resourced teams can’ t sustain resilience no matter how good the tools are.”
He argued that communication, rehearsed incident response, riskbased decision-making and continual skills development remain among the strongest indicators of a resilient organisation.
Building resilience before the crisis
Although contributors approached cyber-resilience from different perspectives, they consistently described a future where security becomes inseparable from business strategy.
Artificial Intelligence is accelerating both attack and defence. Identity is replacing the traditional network perimeter. Continuous visibility is overtaking periodic assessments. Software quality, trusted data, threat intelligence and Quantum Computing readiness are all becoming integral components of resilience planning.
Yet perhaps the strongest message is that resilience cannot be purchased as a product.
Whether discussing dependency mapping, software assurance, Zero Trust, identity governance, segmentation, threat intelligence or executive decision-making, our contributors consistently emphasised preparation over reaction.
As Jason Manar observed:“ The only choice is whether that happens now, on a whiteboard, or at 2am, mid-incident, with the wire already sent.”
The organisations that will define the next generation of cyberresilience will not necessarily be those that prevent every attack. They will be those that understand their business, continuously adapt to changing risks, rehearse for disruption and recover with confidence when the inevitable incident occurs.
Increasingly, cyber-resilience is becoming a defining measure of organisational maturity in an AI-driven world.
56 WWW. INTELLIGENTCISO. COM