Verder naar navigatie Doorgaan naar hoofdinhoud Ga naar de voettekst

Resilience in the AI era:

Why the fundamentals
matter more than ever

door David Brown

27 juli 2026

 

Artificial intelligence is everywhere.

Every security conference, board discussion, vendor briefing and industry report seems dominated by conversations about AI. I keep hearing that AI will revolutionise how we defend, will help transform security operations and fundamentally change how organisations manage risk. At the same time, we see headlines warning of autonomous attackers, increasingly convincing phishing campaigns and a future in which threat actors operate at machine speed.

Much of which is, of course, undoubtedly true. Frontier AI models  are creating new opportunities for innovation, increasing productivity and helping defenders analyse data at a scale that was previously unimaginable. Equally, threat actors are leveraging many of the same capabilities to improve reconnaissance, automate tasks and enhance social engineering attacks which were already successful before the enhancement from AI.

Yet amid all the noise, one reality remains unchanged. When organisations suffer significant cyber incidents, the root cause is often surprisingly familiar.  I recently saw an organisation in Europe breached with all servers, crown jewels included, exposed to the internet with single-factor authentication and incredibly poor password hygiene..

Weak identity controls, poor visibility, unmanaged exposure, ineffective decision-making and untested recovery plans continue to be a real challenge for many organisations globally. Threat actors are predominantly opportunistic and as long as we create that opportunity, AI or not, you are at risk.

Despite all the discussion about AI, the organisations that recover most effectively from cyber incidents or events are usually the ones that have mastered the fundamentals. The era of AI has not changed the foundations of cyber resilience. It has simply increased the speed, scale and consequences of getting them wrong.

 

The threat has evolved, the fundamentals have not

Yes, AI is changing how cyber attacks are conducted. Phishing emails are becoming more convincing, social engineering is becoming more scalable, malware development is becoming more accessible, and reconnaissance activities can be automated and accelerated. 30% of corporate impersonation attacks involve deepfakes according to our 2025 annual threat intelligence report.

However, attackers are still pursuing the same objectives they have always pursued, gain initial access, escalate privileges, move laterally establishing persistence and then achieve their impact.

The tools may be changing, but the lifecycle of the attacker remains remarkably consistent. Likewise, the most effective defensive measures remain largely unchanged. Strong identity controls, privileged access management, effective monitoring, network segmentation and robust operational processes continue to form the foundation of successful defence.

There is a clear danger that organisations are becoming distracted by the promise of emerging technologies while overlooking the capabilities that matter most during a real-world incident.

Cyber resilience is built through discipline and understanding both your environment and your risks.

 

Identity has become the new perimeter

For decades, organisations focused their security strategies on protecting the network perimeter. Firewalls, gateways and segmentation have very much defined the security architecture. Today, identity has become the primary focus.

The most significant cyber incidents almost always involve the abuse or manipulation of identities. Stolen credentials, token theft, Multi Factor Authentication (MFA) bypass, session hijacking and privileged account abuse are central components in a modern attack. Discussions across the cyber community increasingly reinforce the importance of identity as a key factor in preparedness and incident response.

For me, this raises an important question: Do organisations truly understand which identities matter most?

Many organisations can identify their critical systems but struggle to identify their critical identities. Which accounts could disable security capabilities? Which identities can impersonate users, modify infrastructure or disrupt operations? Which third-party identities present significant business risk? Understanding your identity exposure has become a fundamental resilience requirement. It is no longer enough to know what your critical assets are. Compromising the right identity is often far more valuable to an attacker than compromising the right device.

 

Stop chasing vulnerabilities and start understanding exposure

A common mistake within cyber security programmes is treating every vulnerability as equally important. Security teams are overwhelmed by vulnerabilities, especially given the expected exponential increase driven by AI tooling. Tens of thousands of findings, countless alerts and an endless stream of critical Common Vulnerabilities and Exposures (CVEs) can create an illusion of understanding while obscuring the risks that matter most. I regularly see customers with vulnerability tools in place and thousands of unmanaged vulnerabilities the reality is that not every critical vulnerability is critical to your organisation. It’s about risk and understanding how these vulnerabilities impact you.

A vulnerability's severity score doesn’tt automatically translate into business risk. Industry discussions have highlighted the challenge that organisations constantly live with critical vulnerabilities, making it difficult to prioritise based solely on technical severity.

It’s really important organisations focus on questions such as:

  • Is the asset business critical?
  • Is it internet facing?
  • Is there evidence of active exploitation?
  • What would happen if it were compromised?
  • How quickly could we recover?

Cyber resilience requires organisations to move beyond vulnerability management towards genuine exposure management. Frameworks such as Continuous Threat Exposure Management (CTEM) can help organisations prioritise remediation efforts by focusing on exposure and business impact rather than technical severity alone.

The goal is not to patch everything first. The goal is to understand what matters most and reduce risk where it will make the biggest difference.

 

Technology doesn't respond to incidents. People do.

Even the most sophisticated technical controls will eventually face a scenario they were not designed to prevent. When that happens, people become the most important component of resilience.

During a significant cyber incident, organisations face decisions that technology cannot make:

  • Should systems be taken offline?
  • Should operations continue?
  • When should regulators be notified?
  • What should customers be told?
  • What level of risk is acceptable?

These decisions often need to be made under pressure, with incomplete information and significant business consequences yet many organisations test technology more frequently than they test decision-making. True resilience requires confidence at every level of the organisation:

  • Technical responders
  • Incident managers
  • Crisis management teams
  • Communications and Legal
  • Senior executives
  • Board members

When an incident occurs, every individual needs to understand their role, responsibilities and authority. People need to understand what they can and cannot do in certain scenarios. Ask yourself whether your teams feel empowered to make tough decisions and have the support of management to do what they feel is best in that pressured situation.

A cliché perhaps but technology provides information and people determine outcomes.

 

Recovery is the ultimate measure of resilience

The cyber security industry spends enormous amounts of time discussing detection and response and far less attention is given to recovery.

But from my experiences helping our clients to recover is what ultimately matters from a business perspective. Most boards are familiar with measures such as Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR). Fewer organisations can confidently answer a much more important question such as: What is your true Mean Time to Recover? Not the figures set to appease senior management or the board, the actual time required to restore critical business operations following a significant cyber incident.

  • Can critical systems be rebuilt?
  • Can identities be trusted?
  • Can backups be restored?
  • Can third-party dependencies support recovery?
  • Have the recovery processes ever been tested under realistic conditions?

Many organisations have never validated these assumptions until they are forced to do so during a crisis, and the harsh reality is that recovery timelines often bear little resemblance to recovery plans. Resilience is not measured by whether an organisation experiences an incident. Resilience is measured by how quickly and effectively it can recover from one.

 

The questions that matter most

As organisations invest in AI capabilities and explore the opportunities it presents, it’s important not to lose sight of the fundamentals.

Every board and executive leadership team should be able to answer the following questions:

  • What are our most critical business services?
  • Which identities present the greatest risk?
  • Which vulnerabilities genuinely matter to our organisation?
  • How quickly can we detect compromise?
  • How effectively can we make decisions during a crisis?
  • How confident are we in our recovery capabilities?
  • Have we validated these assumptions through testing?
  • What’s our minimum viable product/service?

If the answer to any of these questions is "we don't know", AI is unlikely to be your most pressing challenge.

 

Conclusion

AI is undoubtedly reshaping both cyber attack and defence. It has and will continue to introduce new opportunities, create new risks and change the way organisations operate. But it should not distract us from the lessons that real world incidents continue to teach.

The organisations that emerge strongest will not necessarily be those with the most advanced AI capabilities. They’ll be the organisations that understand their critical assets, secure their identities, manage exposure effectively, prepare their people and prove their ability to recover.

In an industry increasingly dominated by AI headlines, resilience remains the ultimate competitive advantage and the fundamentals have never mattered more. If AI disappeared tomorrow, would you suddenly be unable to identify your critical assets, patch vulnerable systems, enforce least privilege, or monitor your environment? If not, then your greatest security opportunity isn't AI. It's operational discipline.  

David Brown

David Brown

Principal Consultant DFIR, NCC Group UK

David Brown brings 10 years of experience in Digital Forensics and Incident Response. A former Police Detective of 18 years, he is an experienced technical security consultant who leads complex investigations and helps organisations respond to and recover from significant cyber crises.

David holds a Master's Degree in Digital Forensics and Advanced Securities and is a full member of the Chartered Institute of Information Security.

 

Harness AI securely. Innovate without compromise.

Discover NCC Group’s solutions for Securing AI.

Learn more