Showing posts with label resilience. Show all posts
Showing posts with label resilience. Show all posts

Tuesday, 3 March 2026

Resilient Organisations Practise Until Response Becomes Routine, Says Horizon3.ai

Dan Bird MBE, Field Chief Technology Officer (EMEA) at Horizon3.ai, highlights why cyber resilience must move beyond policy and toward continuous operational rehearsal, reinforcing insights from co-founder and CEO Snehal Antani.

Cyber resilience is often framed as a new challenge driven by modern threats, yet many of its core lessons were already solved decades ago in disaster recovery. 

According to Dan Bird MBE, Field Chief Technology Officer (EMEA) at cybersecurity company Horizon3.ai, resilient organisations succeed not through static defence models but through continuous rehearsal and validation, an approach strongly echoed by Horizon3.ai co-founder and CEO Snehal Antani.

Bird points to a growing gap between policy and real-world readiness. Horizon3.ai, regarded as one of the leading providers of offensive security, promotes an approach in which organisations test their own IT environments through continuous penetration testing to uncover potential weaknesses that cybercriminals could exploit. Rather than solely relying on passive layers of defence, organisations can safely hack themselves, fix their issues, validate their fixes, and repeat the process as often as they like.

Parallels between cyber resilience and high availability systems

Drawing on Antani’s comparison between cyber resilience and business continuity, Bird emphasises that resilience is not a theoretical concept but an operational discipline. In high availability environments, downtime is not acceptable and failures are anticipated rather than avoided. 

Systems are intentionally failed over from one data centre to another to prove recovery works, building the kind of repetition and accountability that creates “muscle memory” within teams.

This model of continuous rehearsal for real events aligns closely with offensive security principles and reflects what both Antani and Bird see as the most effective modern response to escalating cyber threats. Instead of viewing cyber resilience as a tooling or reporting exercise, Horizon3.ai argues that organisations must treat it as an operational challenge: systems fail, attackers exploit weaknesses, and businesses must recover under pressure. “Customers expect availability, and regulators demand accountability,” Bird told That's Business. 

Resilient organisations practise until action becomes routine

Bird reinforces Antani’s view that resilient organisations should assume something will go wrong and actively look for weak points before attackers do. “Resilience means rehearsing response and recovery until execution becomes routine, whereas many organisations still rely on assumptions,” he explained. “Defence and recovery plans may appear strong on paper but often fail in practice when testing is missing.”

In real incidents, he notes, operational failures and malicious activity can appear indistinguishable at first. Service restoration cannot wait for perfect attribution. 

Disaster recovery and cybersecurity converge, requiring teams that have rehearsed together rather than siloed plans that have never been exercised under pressure. The challenge, Antani has argued, is rarely tooling alone but often process and leadership.

One penetration test a year is far too little

Both leaders highlight the limits of traditional annual penetration testing in environments that change constantly. 

Risks evolve faster than yearly cycles can capture, with patches arriving weekly, configurations shifting and cloud and identity architectures continuously developing. Without regular security validation, organisations risk making decisions based on outdated assumptions.

Bird emphasises that continuous testing tied closely to change creates the feedback loops organisations need. Regular pentests following patch cycles help teams validate whether improvements actually reduce risk, moving security toward continuous improvement rather than periodic assessment.

A new phase of cybersecurity driven by artificial intelligence

As Antani has observed, cybersecurity has entered a phase where speed matters more than ever. AI-driven attacks compress timelines, meaning organisations must rely on trained muscle memory rather than reactive decision-making. 

From Bird’s perspective, the lesson is clear: “Under pressure, teams fall back on training, not expectations. Continuous rehearsal, combined with leadership commitment, determines performance.”

https://horizon3.ai

Follow them here:-

http://www.linkedin.com/company/horizon3ai

https://x.com/Horizon3ai

Thursday, 19 October 2023

Navigating the Storm: Crisis Management and Business Resilience

In today's fast-paced, fluid and unpredictable business environment, companies face a multitude of challenges that can disrupt their operations and threaten their very existence. From natural disasters to economic downturns, the need for effective crisis management and business resilience has never been more critical. 

In this blog post, we will explore the importance of crisis management and business resilience, the key principles for success, and strategies to ensure your organisation thrives in the face of adversity.

The Importance of Crisis Management

Crisis management is the process of identifying, mitigating, and responding to potential crises that can impact an organization. Whether it's a natural disaster, a cybersecurity breach, a product recall, or a global pandemic, crises can have devastating consequences. Companies that fail to manage crises effectively may face reputational damage, financial losses, and even closure.

Preparation is Key: Effective crisis management begins with preparation. Companies should develop comprehensive crisis management plans that outline the roles and responsibilities of key personnel, communication strategies, and contingency plans. Regular drills and simulations can help teams become adept at responding to various scenarios.

Communication is Critical: A well-crafted communication strategy is essential during a crisis. Transparent and timely communication with employees, customers, stakeholders, and the public is crucial for maintaining trust and minimizing the impact of the crisis.

The Role of Business Resilience

Business resilience is the ability of an organization to adapt and recover quickly from a crisis while maintaining core operations. It's about more than just surviving; it's about thriving despite adversity.

Diversification and Redundancy: Businesses that are heavily reliant on a single supplier, a single market, or a single distribution channel are more vulnerable to disruptions. Building redundancy and diversification into your supply chain and operations can enhance resilience.

Innovation and Agility: Agile companies are better equipped to pivot in response to changing circumstances. A culture of innovation and the ability to adapt to new technologies and processes can be a significant asset during a crisis.

Strategies for Ensuring Business Resilience

Risk Assessment: Understand the potential risks your business faces, both internal and external. Regular risk assessments can help identify vulnerabilities and inform your crisis management and resilience strategies.

Invest in Technology: Embrace technology to enhance your crisis management capabilities. This includes the use of data analytics, AI, and cloud computing to gather real-time information and make informed decisions during a crisis. 

One aspect that is often overlooked is what would your business do if there was a sudden power cut? If an independent power generator that switches on as soon as there is a power cut is not a possibility, an uninterruptible power unit which will give you enough time to back up vital data is a cheaper alternative. 

Employee Training: Employees are your most valuable asset during a crisis. Invest in their training to ensure they can respond effectively to various scenarios. Cross-training and upskilling can be particularly valuable.

Build Strong Relationships: Cultivate strong relationships with suppliers, customers, and stakeholders. These relationships can be instrumental in navigating a crisis, as partners are more likely to provide support during difficult times.

Continuous Improvement: Crisis management and resilience are not one-time endeavours. Continuously review and update your plans, learning from past experiences and adapting to the evolving business landscape.

Crisis management and business resilience are not optional but essential aspects of modern business. Companies that prioritise preparedness, effective communication, and the ability to adapt and recover are better equipped to not only survive crises but also emerge stronger on the other side. In an ever-changing world, businesses that invest in these principles and strategies are more likely to thrive despite the storms that come their way.

(Image courtesy of Gerd Altmann from Pixabay)