
War has not only changed the nature and scale of threats. It has forced us to take a new look at what business resilience means.
In a modern company, a critical asset is not just equipment or data. No less important is the ability to continue working when part of the digital infrastructure becomes unavailable.
The reason can be different.
It can be a cyber attack – an encryptor, theft of accounts, an attack on corporate services.
Or it can be an infrastructure incident – the destruction of a data center, a long power outage, loss of communication channels.
For a business, the result is often the same: a critical IT system is unavailable, and with it the company’s processes are stopped or complicated.
That is why the task of security today is much broader than protection against cybercriminals. It includes the ability of a business to recover and continue working after serious incidents.
Company management – and we’re not just talking about CISOs – should regularly ask themselves simple but fundamental questions:
What will happen to the business if the main data center is destroyed?
How long can the company realistically operate without critical IT systems?
Will we be able to restore key services after a complete compromise or physical loss of the main infrastructure?
Will backups remain available in such a case and will there be somewhere to restore?
Do we know which systems and business processes need to be restored first?
Some of these questions can send an unpleasant chill through the inside. And this is a good indicator of where exactly to look for weaknesses. Because the answers to these questions determine the real resilience of the company much better than the number of installed protections.
Technology remains the foundation: network segmentation, multi-factor authentication, endpoint protection, anti-phishing, security event monitoring, redundancy and geographic distribution of critical infrastructure, tamper-proof and regularly tested backups.
But technology is not enough.
You need processes, trained teams, clear response scenarios, and regular verification that the planned recovery is actually working.
A mature security system is not a system in which incidents never occur. It is a system in which even a serious incident does not lead to unacceptable business downtime.
This is, in my opinion, one of the key tasks of the CISO today: not just to protect the IT infrastructure, but to ensure its ability to withstand a crisis and recover from it.