Guerassim Nikolov – Building Cyber Resilience: Why Prevention Is No Longer Enough

This post was originally published on this site.

The evidence of the past decade has made this assumption untenable. The question for modern security leadership is not whether a serious incident will occur, but whether the organization has built the capability to absorb it, contain it, and recover from it without catastrophic operational or financial consequences.

“Prevention alone is a strategy that assumes you will always win,” says Guerassim Nikolov, entrepreneur and enterprise security advisor with more than twenty years in cybersecurity strategy. “Resilience is what you build for the assumption that eventually, you won’t. The organizations that recover well aren’t the ones with the most sophisticated defenses – they’re the ones that have practiced what happens when those defenses fail.”

The Colonial Pipeline ransomware attack of May 2021 illustrated what inadequate resilience looks like in practice. DarkSide ransomware – introduced through a compromised VPN account that lacked multi-factor authentication – encrypted critical billing and operational systems. Colonial Pipeline halted all pipeline operations as a precautionary measure, cutting off approximately 45% of the East Coast’s fuel supply for several days. The company paid a ransom of $4.4 million in Bitcoin within hours. Even after receiving the decryption key, restoring full operations took additional days, and the disruption triggered emergency declarations across seventeen states.

Free newsletters

The stories that matter to UK business, straight to your inbox.

Maersk’s experience with the NotPetya wiper malware in June 2017 is the more instructive case study on resilience execution. When NotPetya propagated through Maersk’s global network, the company was forced to rebuild its entire IT infrastructure from scratch: 45,000 PCs, 4,000 servers, and 2,500 applications reinstalled across every global location within ten days. That recovery was only possible because Maersk’s staff improvised manual processes to keep approximately 80% of shipping volume moving without any operational IT systems. The financial cost was estimated at $250–$300 million.

Nikolov cites the Maersk case as the clearest demonstration of why resilience thinking must be built in before a crisis hits. “They rebuilt an entire global IT infrastructure in ten days because they had no choice. Most organizations haven’t thought through what their version of that looks like. The time to design and rehearse that response is before you’re in it – not while your systems are down and your stakeholders are waiting for answers.”

The regulatory environment has added another layer of urgency. The SEC’s cybersecurity disclosure rules, which took effect for most large public companies in December 2023, require that material cybersecurity incidents be reported within four business days of the company determining materiality. Boards and executive teams must now be prepared to make materiality determinations quickly – often while the incident is still active – and to communicate simultaneously with regulators, investors, and the public.

Building genuine resilience requires treating it as an operational capability, not a technology configuration. The components are: tested and rehearsed incident response plans, not documents that sit in a folder; backup systems isolated from production networks so ransomware cannot encrypt them simultaneously; clearly defined decision authority for who can authorize payments, shut down systems, or invoke business continuity plans; and pre-prepared stakeholder communication templates for regulators, customers, and the media.

The organizations that recover fastest from significant incidents are not those with the most sophisticated prevention technology. They are the ones that have practiced recovery so many times that it becomes a repeatable operational process rather than a crisis improvisation. Resilience, like any capability, is built through rehearsal.

Hot this week

Topics

spot_img

Related Articles

Popular Categories

spot_imgspot_img