CISOs are increasingly seen as essential partners in business resilience, evolving from traditional cybersecurity roles to encompass incident response and operational recovery. This shift underscores the need for a broader understanding among security leaders of their organization’s overall health and function.
According to John Bruggeman, a consulting CISO with decades of experience, today's information security officers are honing their focus on not just preventing breaches but ensuring organizational uptime and financial stability. “Any experienced CISO has that operational mindset, which is about uptime," he explains. The reality is that recovery post-incident has become just as critical to business survival as proactive security measures.
High-profile incidents, such as the global outage suffered by CrowdStrike, have pressured companies to appoint dedicated resilience officers to signify a commitment to recovery and operational continuity. While not every organization will go this route, the responsibility for resilience increasingly involves CISOs, who are integrating resilience strategies into their operational frameworks.
Rethinking Resilience in Business Operations
Historically, the concept of resilience was tied closely to system uptime. However, perspectives are shifting to encompass broader operational focuses, as pointed out by consultant Aimee Cardwell. She emphasizes that resilience is now about more than just getting systems back online; it involves securing sensitive data against breaches and managing recovery priorities. “Organizations in highly regulated sectors often prioritize data protection over uptime,” Cardwell notes. This is particularly evident in industries like healthcare and finance, where reputational damage can be as costly as the downtime itself.
In contrast, companies that handle less sensitive information might opt for quicker recovery as their primary focus. For example, Amazon tokenizes financial data, so they face a different calculus when assessing risk and resilience. As Cardwell articulates, it’s essential for CISOs to establish clear tolerances concerning data loss and recovery efforts. “Setting benchmarks for acceptable data loss should parallel discussions on system uptime,” she argues.
The rapid integration of AI technologies complicates these conversations, amplifying the risk of unnoticed data leaks potentially originating from unguarded areas within a company’s IT infrastructure. Cardwell recounts an instance where a healthcare provider neglected to protect patient data due to poor file management practices. “Why is there so much healthcare data in the accounting folder?” she muses, underscoring the risks posed by shadow data and oversight.
CISOs must thus tackle the issue of shadow IT head-on, pushing for stricter role-based access controls to safeguard sensitive information. Yet, coinciding with that ideal is the challenge that many organizations fail to adopt these practices effectively.
Implementing a Resilience Mindset
Bill O’Connell, CommVault’s CSO, stresses the importance of defining the organization’s “minimum viable operations.” He highlights that identifying core functions, prioritizing what to protect, and rehearsing response strategies are key to building a resilience framework. “Define the smallest version of the business that still works, then build your recovery priorities and drills around that,” he advises.
This hands-on approach transforms theoretical plans into actionable processes, preventing the confusion and panic during actual disruptions. O’Connell believes that practicing recovery scenarios will fortify an organization’s readiness. He argues against relegating business continuity planning to mere paperwork for audits, urging instead for a proactive culture where incident response is rehearsed regularly.
O’Connell introduces the notion of “ResOps,” a systematic approach to organizational recovery akin to how DevOps redefined software development. This proactive mindset not only requires balancing defensive strategies but also enhancing organizational resilience—a point that can be difficult for CISOs entrenched in defensive mindsets to accept. “When you talk to CISOs, they often fear the idea of downplaying defense, but it’s about finding equilibrium,” he says.
Strengthening the Resilience Mandate
To affirm their role in resilience, CISOs need to collaborate closely with Governance, Risk, and Compliance (GRC) teams. Bruggeman underscores that this partnership enables CISOs to effectively communicate cyber risks while providing GRC professionals the framework to analyze and address these risks pragmatically. “It’s not just about transferring responsibilities; instead, it’s about shared accountability,” he remarks.
While no industry standard dictates a standalone chief resilience officer, the fragmented nature of responsibilities presents an opportunity for CISOs to elevate their role within executive teams. Understanding how various offices interplay makes it easier for CISOs to influence resilience strategies effectively.
Ultimately, the task of modern CISOs extends well beyond basic cybersecurity measures. They must cultivate a mindset that integrates operational knowledge with robust recovery strategies, all while maintaining a clear dialogue with other C-suite leaders about the importance of resilience in achieving organizational success. Adapting to this expanded role is not just beneficial—it’s becoming essential for safeguarding an organization's future in a landscape marked by uncertainties and evolving threats.