{"id":8874,"date":"2026-07-27T07:00:00","date_gmt":"2026-07-27T07:00:00","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=8874"},"modified":"2026-07-27T07:00:00","modified_gmt":"2026-07-27T07:00:00","slug":"how-cisos-can-rise-to-the-business-resilience-challenge","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=8874","title":{"rendered":"How CISOs can rise to the business resilience challenge"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">CISOs have quietly become their organizations\u2019 de facto chief resilience officers as the role has evolved from its primary prevention roots to now include greater emphasis on incident response and business resiliency and recovery.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAny experienced CISO who\u2019s come up through the ranks of IT has that operational mindset, which is about uptime,\u201d says <a href=\"https:\/\/www.linkedin.com\/in\/johnbruggeman\/\">John Bruggeman<\/a>, consulting CISO to OnX and CBTS. \u201cThey\u2019re thinking, \u2018How do I make sure that we\u2019re not totally down and unable to perform our functions.\u2019\u201d<\/p>\n<p class=\"wp-block-paragraph\">With 30 years\u2019 experience across numerous organizations, including a 40,000-employee global firm and a 75-employee $300 million revenue business, Bruggeman has lived the challenges faced by CISOs who shoulder responsibility for cybersecurity, including owning recovery.<\/p>\n<p class=\"wp-block-paragraph\">According to Bruggeman, CISOs have always had a resiliency mindset, only now it\u2019s being called out by name, underpinning all business operations. The stakes couldn\u2019t be higher for the organization, and individual CISOs.<\/p>\n<p class=\"wp-block-paragraph\">For example, in the wake of its global outage, CrowdStrike appointed its first chief resilience officer. It was a message to customers, regulators, and investors that the company was intent on strengthening its operations.<\/p>\n<p class=\"wp-block-paragraph\">But not every organization will go so far as to introduce a new C-suite role dedicated to resiliency. For most, that work increasingly falls to the CISO, and <a href=\"https:\/\/www.csoonline.com\/article\/4188186\/cybersecurity-is-no-longer-about-protection-its-about-survival.html\">security leaders are responding<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">When he\u2019s developing <a href=\"https:\/\/www.csoonline.com\/article\/515730\/business-continuity-and-disaster-recovery-planning-the-basics.html\">business continuity plans<\/a> and business impact assessments, Bruggeman goes right to resiliency. The central question for most organizations is: If you\u2019re down, how much money are you going to lose? What\u2019s the impact to your revenue?<\/p>\n<p class=\"wp-block-paragraph\">As such, Bruggeman firmly believes terms like resilience should be emphasized in boardroom discussions as a way for CISOs to gain buy-in \u2014 and funding \u2014 for cyber operations.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIf Gartner talks about it, then the CEO is going to talk about it, and then the board is going to talk about it, and then [the CISO] can get funding for what they\u2019ve been talking about. If you have to change the word from \u2018backup\u2019 to \u2018resilient,\u2019 you\u2019ll do it in a heartbeat.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Redefining resilience beyond uptime<\/h2>\n<p class=\"wp-block-paragraph\">Traditionally, resilience has been narrowly defined in terms of uptime, but as the CISO mandate has evolved to support business operations, the definition is shifting.<\/p>\n<p class=\"wp-block-paragraph\">For <a href=\"https:\/\/www.linkedin.com\/in\/acardwell\/\">Aimee Cardwell,<\/a> consultant and CIO and CISO in residence at Transcend, resilience means more than bringing systems back online after an outage.<\/p>\n<p class=\"wp-block-paragraph\">As Cardwell sees it, resiliency should be measured as recovering from system downtime and protecting against data theft through tokenization or encryption \u2014 but those haven\u2019t always been given equal weighting. Organizations typically focus on being back up and running, but knowing where sensitive data lives and how exposed it is can\u2019t be overlooked, she says.<\/p>\n<p class=\"wp-block-paragraph\">Organizations in heavily regulated industries such as healthcare and financial services will often prioritize data protection over uptime due to potential regulatory penalties or loss of customer trust. \u201cIf you\u2019re a bank, you\u2019d rather be down for a day, or even two days, and not have a data loss than be back up in 40 minutes and have a data loss, because your brand damage suffers,\u201d Cardwell says.<\/p>\n<p class=\"wp-block-paragraph\">The equation flips for companies that don\u2019t hold especially sensitive data. Amazon, she notes, tokenizes credit card numbers, so a breach would expose only a customer\u2019s name, address, and email \u2014 not financial or health information. \u201cIt depends on where you are on that spectrum of sensitive data \u2026 where your resilience meter is,\u201d she says. \u201cIf you\u2019re Amazon, you want to be up fast, because every minute is millions of dollars.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Cardwell argues CISOs need to set explicit tolerances for data loss \u2014 what kind of data and how much of it \u2014 they are prepared to risk, not just how quickly systems come back online.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe exercises to determine their mean time to recovery, \u2026 I think having that same conversation for data loss is something that, if a CISO is not already doing that, they need to add that to the conversation,\u201d she says.<\/p>\n<p class=\"wp-block-paragraph\">The rapid adoption of AI is another stress-test for resilience that is falling to CISOs. It\u2019s amplifying the risk of hidden data exposure, turning a theoretical data\u2011loss conversation into a live operational problem.<\/p>\n<p class=\"wp-block-paragraph\">Cardwell describes a healthcare company that had 15 years of patient data breached \u2014 not through its primary systems, but through an accounting folder. As a small provider billing larger organizations, it had attached patient names, numbers, and conditions to years of invoices, all sitting unprotected in a location no one thought to secure.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWhy is there so much healthcare data in the accounting folder?\u201d she says. It\u2019s the kind of shadow data problem, she argues, no perimeter defense would have caught.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIt feels like CISOs have been pounding the table, saying, \u2018I can\u2019t protect it if I don\u2019t know where it is.\u2019 There\u2019s shadow IT, there\u2019s shadow data, and AI is magnifying that ten times,\u201d Cardwell says. \u201cThat\u2019s where much of that resilience problem is; it\u2019s almost impossible in a large enterprise to have an understanding of where all that data is and how people are using it.\u201d<\/p>\n<p class=\"wp-block-paragraph\">To contain the sprawl, Cardwell says CISOs need to champion role-based access control to protect sensitive data, yet there\u2019s a sizable gap between best practice and real-world standards.<\/p>\n<p class=\"wp-block-paragraph\">\u201cEvery CISO will tell you that role-based access control is the most important thing a company can do, and every CISO will also tell you that they\u2019ve never seen a company that does it well. And when I say well, I mean better than 70%,\u201d she says.<\/p>\n<p class=\"wp-block-paragraph\">While a chief resilience officer could take ownership of certain functions such as data retention policy, the remit would overlap with roles that already have clear boundaries elsewhere. Audit, privacy, and legal are unambiguous, but resilience collides directly with the CIO, who already owns mean time to recovery, and potentially a chief data officer, too.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIf you\u2019re the CEO, who do you go to for questions around resilience?\u201d she asks. \u201cIt gets a little complicated, unless you have clear boundaries.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Executing the resilience mindset<\/h2>\n<p class=\"wp-block-paragraph\">Resilience starts with defining the minimum viable operations for the organization, according to <a href=\"https:\/\/www.linkedin.com\/in\/billoconnell\/details\/experience\/\">Bill O\u2019Connell<\/a>, CommVault CSO. Then it\u2019s a matter of working backwards to decide what to prioritize, what to protect, and rehearsing what to bring back first when things go wrong.<\/p>\n<p class=\"wp-block-paragraph\">\u201cDefine the smallest version of the business that still works, then build your recovery priorities and drills around that,\u201d he tells CSO.<\/p>\n<p class=\"wp-block-paragraph\">A longtime cybersecurity professional who\u2019s held chief business security officer and global security operations roles, O\u2019Connell says a resilience mindset is an operational one that takes processes \u201coff the page\u201d and into practice.<\/p>\n<p class=\"wp-block-paragraph\">He knows firsthand that the most difficult part of an incident is almost always where organizations have never rehearsed those steps.<\/p>\n<p class=\"wp-block-paragraph\">\u201cI\u2019ve had all manner of disruptions happen, where you\u2019re asking: What are the key things, do I know who I need to talk to, do I know where I need to go, and do I know how to get the information? Unless you\u2019re practiced at that, it\u2019s that much more painful,\u201d he says.<\/p>\n<p class=\"wp-block-paragraph\">He warns against treating business continuity planning and disaster recovery as \u201ca Word document\u201d for auditors. Practicing \u201cwho talks to whom, where they go, and how they get information during disruption\u201d is essential.<\/p>\n<p class=\"wp-block-paragraph\">Instead O\u2019Connell advises developing a \u201cResOps\u201d approach, where organizations repeatedly test, rehearse, and improve how they recover their most important services. \u201cWe have DevOps. We have SecOps. Do we have ResOps? Do we have a process around how we make sure we\u2019re resilient?\u201d he says.<\/p>\n<p class=\"wp-block-paragraph\">O\u2019Connell also warns against overindexing on defense at the expense of resilience, though he appreciates that this mindset shift can be a difficult for many CISOs to come to grips with.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWhen you talk to CISOs, you have to be mindful, because if you say, \u2018Worry less about defense,\u2019 they get scared, because that\u2019s their job. But it\u2019s not to say, \u2018Do less there\u2019; it\u2019s just to say, \u2018You\u2019re not doing enough on recovery, on availability, and the resilience piece and you need to make sure you\u2019re balanced there,\u2019\u201d he says.<\/p>\n<p class=\"wp-block-paragraph\">For the board, O\u2019Connell frames the conversation in terms of risks, potential impact, and mitigations \u2014 an approach that requires standing side by side with business leaders, looking at the problems and opportunities they see, and then explaining how cybersecurity helps support those outcomes, he says.<\/p>\n<h2 class=\"wp-block-heading\">Advice for CISOs to strengthen the resilience mandate<\/h2>\n<p class=\"wp-block-paragraph\">Drawing on his consulting experience, Bruggeman offers practical advice for security leaders who want to turn resilience into a credible mandate.<\/p>\n<p class=\"wp-block-paragraph\">\u201cFor a CISO, they may not want to take on full responsibility for the resiliency component, but they can partner with GRC and compliance people. They both want the organization to succeed; they just have different tools in their toolkit to implement it and get the funding,\u201d he says.<\/p>\n<p class=\"wp-block-paragraph\">Executed this way, CISOs articulate cyber and operational risks; GRC\/compliance codifies and quantifies those risks; the CFO\/COO turns that into funding and organizational mandate.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIt\u2019s not so much that they\u2019re going to say, \u2018Here, you can have this problem,\u2019 but to say, \u2018Let\u2019s partner together,\u2019 because it\u2019s a shared responsibility,\u201d he says.<\/p>\n<p class=\"wp-block-paragraph\">Bruggeman is yet to see any one single chief resilience officer because responsibility sits with different portfolios, creating opportunities for CISOs to level up their stature in the C-suite.<\/p>\n<p class=\"wp-block-paragraph\">\u201cI haven\u2019t run into a single company that has a resiliency officer. The CIO has some responsibility, the CISO has some responsibility, and the COO \u2014 who really is a chief and really is an officer \u2014 has responsibility,\u201d he says. \u201cI see it more as a partnership than a single role.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>CISOs have quietly become their organizations\u2019 de facto chief resilience officers as the role has evolved from its primary prevention roots to now include greater emphasis on incident response and business resiliency and recovery. \u201cAny experienced CISO who\u2019s come up through the ranks of IT has that operational mindset, which is about uptime,\u201d says John [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":8875,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-8874","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8874"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8874"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8874\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/8875"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8874"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8874"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8874"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}