What does a cyberattack-resilient organization look like? An expert discussion showed that it’s not just about compliance, but about culture, people, training, and the ability to recover after an incident. In an era of rapidly changing AI, it’s important to master braking and accelerating at the same time.
People, training, and “unobtrusive” security
Security teams tend to be unpopular because they tighten rules and restrictions that make things less convenient for users. However, open communication, training with real-world examples, and feedback after phishing tests help—where mistakes are used for learning, not for “punishment.” Users then take the principles home and better recognize sophisticated scams. As AI becomes more accessible, attacks will be faster and more precise, so the network “screws” will have to be tightened further.
The goal is for security to work reliably in the background and not disrupt work—the banker should be handling a mortgage and the head physician a patient, not computer settings. Basic cyber hygiene and habits should be taught already in schools so the next generation arrives prepared. Less stress for users and more automation in the background increase the willingness to follow the rules.
Prevention versus recovery: two sides of the same coin
Today there is no completely “unhackable” organization, so you need to invest in prevention as well as rapid service restoration. Backups make sense only if it’s verified that you can reliably restore from them and that you’re not returning into a compromised environment. The naive belief that “we have perfect backups and move on” doesn’t hold if the attacker has left backdoors in the network. Continuity plans therefore should also exist outside the compromised infrastructure, and they need to be tested regularly.
Large organizations drill coordinated scenarios; smaller ones should at least have up-to-date asset documentation and clearly designated command during a response, because improvisation will always come into play. Indicators of attack tend to be inconspicuous: unusual account behavior, suspicious verification requests, or a sudden increase in alert noise can mask the attacker’s main activity. The state is increasing resilience through legislation and support for incident response teams; for example, an accredited CERT is already operating at the Ministry of Finance with the ambition to become sector-wide. Finally, AI is changing both the pace and nature of threats, so it’s important to think about “braking systems” and “airbags”—from prevention through to recovery.