In the face of an ever-transforming digital world, resilience has become an essential focus for the security industry (reinforced even more so by a global pandemic and entirely remote workforces). With external attacks now accepted as an inevitable reality, how an organization detects, responds, recovers, and learns from a crisis is key.
An effective cyber resilience program should include a programmatic approach to withstand disruptive cyber incidents. It should ensure continuity of operation with minimum impact to business despite an incident. It should also have a governance framework with policies, procedures, and accountability, integrated into the business strategy. This all needs to be powered by the right people and the right technology.
It is an iterative process providing the means of recovery from an attack and the first step is accepting potential failure in the first place.
What are some of the steps that organizations have taken to build cyber resilience programs and what have they learned when faced with failure?