Embracing the Inevitable: Why Cybersecurity Resilience Is the New Norm

Search for a command to run...

No comments yet. Be the first to comment.
As cybersecurity practitioners or regular internet users we often come across malicious websites that should be responsibly reported. Notifying security vendors of such cases can help protect not just ourselves but also others from phishing, malware,...

Introduction In recent years, cyber insurance has emerged as an essential tool for businesses to manage and mitigate the financial impact of cyberattacks. As cyber threats continue to evolve and grow in complexity, the insurance industry must adapt i...

Introduction In today's digital age, the security of information and systems is of paramount importance for businesses and organizations. With cyber threats constantly evolving, it's crucial to stay ahead of the game. One effective strategy to combat...

Introduction The dark web, a mysterious and often misunderstood part of the internet, has gained significant attention in recent years due to its association with cybercrime, illicit activities, and hidden services. Despite its ominous reputation, th...

The notion that cybersecurity breaches can be wholly prevented is both outdated and impractical. Despite increasing budgets and staffing in the field of cybersecurity, attacks continue to occur, often with devastating consequences. According to prevailing wisdom, pouring more money into defensive measures should ideally reduce the likelihood of a breach. However, reality paints a different picture. In this blog post, we'll delve into why a shift from a purely defensive strategy to one focused on resilience is essential. We'll also explore actionable steps for security and risk management leaders to adopt in building a cyber-resilient organisation.
It's high time we confront the harsh truth: we're not winning the cybersecurity arms race. For every defensive measure put in place, hackers, sometimes backed by nation-states, find innovative ways to exploit vulnerabilities.
For example, despite being well-funded and having robust defensive measures, organisations like Maersk, Merck, and Colonial Pipeline still fell victim to significant cyberattacks. These incidents not only had cyber consequences but also extended the threat to operational and physical environments.
In simple terms, "unassailable lead" describes the advantage that hackers currently possess over existing cybersecurity practices. Organisations continue to invest heavily in defences, but these investments often yield poor returns.
Given that breaches are bound to occur, organisations need to adopt a new perspective—building resilience. Instead of a defensive strategy that aims to prevent all successful attacks, a resilience strategy prepares an organisation to absorb the shock of an attack, adapt, and recover.
Given the insights from recent findings, the following are recommended courses of action:
Reallocate Resources to Resilience: Instead of pumping more money into ever-expanding defensive measures, redirect those funds toward building a resilient infrastructure and a resilient organisation.
Apply Lessons from Normal Accident Theory (NAT): NAT posits that in complex systems, accidents are inevitable. By adopting "mindfulness" approaches seen in Highly Reliable Organisations (HROs), companies can prepare for and manage these inevitable incidents more effectively.
Hire Experienced Leaders: Look for cybersecurity experts who have firsthand experience dealing with breaches. Their experience is invaluable in building a resilient organisation.
Integrate with Business Continuity Plans: Cybersecurity should not exist in a vacuum. Integrate it with other organisational plans like disaster recovery and business continuity to create a comprehensive resilience strategy.
While the instinct to defend is natural, our current cyber landscape requires a more nuanced approach. Resilience doesn't mean giving up on defence; it means preparing for the inevitable and being equipped to recover and learn from it. It's about creating real business value by being prepared for what we can't prevent.
By making cybersecurity resilience the cornerstone of your organisation's strategy, you not only prepare for the inevitable but you're turning challenges into opportunities for strengthening your security posture.