Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - The All-too-real Achilles Heel Of IT
Articles

The All-too-real Achilles Heel Of IT

Flick MarchBy Flick MarchMarch 28, 2022Updated:March 28, 20225 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Cybersecurity
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Recent weeks have seen a surge in calls for cybersecurity resilience. UK organisations are now being urged by the NCSC to “bolster their defences”. And they’re not alone. In today’s digital-first ecosystem, it is critical that companies can operate – or at least remain active – 24/7. We saw these challenges at the onset of COVID as businesses were forced to – and struggled – to shift to a secure, remote, digital way of working. While many eventually made the leap, questions remain about security and resilience, particularly given that many of us now work from a cloud system.

Outages and cyber breaches have been making headlines consistently over the past 12-18 months and significantly impacted the reputation and revenue of those businesses who were named as vulnerable. But instead of focusing on the faltering of these companies which – frankly – is inevitable for any business, I’d like to suggest we focus on why our approach to disaster recovery (DR) and resilience needs a rethink.

A hybrid cloud strategy isn’t enough

CIOs spend a huge amount of time and money on cloud strategies. Their decisions can affect the entire running of the business for staff and customers alike. Yet, the way departments purchase and utilise cloud resource can significantly undermine a businesses’ resilience. Regardless of how technologically modern and secure cloud environments are, having system architecture, ownership, and accountability rife with walls, siloes, and handovers means that resilience is nearly impossible to bake in by design. Following the breadcrumbs of a system failure to its root cause can feel like a relay race between departments. 

This is the Achilles heel of any hybrid-cloud strategy; proper resilience practice not only understands  but demands a rethink. It’s no longer sufficient to have a DR department to hand off to when things go wrong; it’s truly about knowing how your system fits together, its risk appetite, and its non-negotiables for business continuity. 

But the problem of resilience – cloud or otherwise – is a legacy problem, stemming from the way the IT industry has evolved, and is sold, in a way which does not correlate to end-to-end business functions. It’s remained siloed and as a result, has compartmentalised itself for the last 30 years into dedicated disciplines: mainframe, server, network, cloud, applications, security, etc.

Key considerations for resilience

What this all ladders up to is the fact that the cloud is not an island: you cannot procure or operate within a cloud framework and expect the entire system to be secure.

Building resilience into our systems used to be simple – it used to be solely about DR – but that’s not the case any longer and several factors have changed the game. Extreme weather, civil unrest, and other unexpected, large-scale shocks all constitute resilience risks just as cyberattacks do. As a result, any resilience framework must take a holistic approach, rather than relying on DR alone.

That holistic approach is precisely why we must now think of any resilience strategy with a clear understanding of the “minimum viable organisation.”

Building resilience through minimum viable organisation

Current Enterprise IT architecture does not think in terms of business operations, but consider this: What happens when customers can no longer make a purchase? When doctors can no longer access medical data? When banks can no longer access funds? All these touchpoints are crucial elements within a process chain, yet often the various elements – the network, data centre, security, cloud operations – are viewed in isolation.

Securing only one of these elements does no good if the rest of the chain is left vulnerable. And ultimately that’s where the minimal viable organisation comes in. It challenges what is the absolute bare minimum that businesses need to secure to continue operating and providing services. Through that understanding, they can address key vulnerabilities throughout the network and orchestrate better resiliency practice.

In its siloing and compartmentalising, the technology industry has institutionalised itself into fiefdoms that compete to the detriment of business operations and resilience. Focusing on one element of a wider process, whether it be cloud, network, etc, is no longer appropriate. Rather, to achieve proper resilience businesses must break this mould.

Cybersecurity resilience in 2022 calls for a fundamental rethink of how we design, procure, and maintain our systems with business operations in mind.

Conclusion

In conclusion, building resilience within the cloud cannot be done in the cloud alone – yet without it, any hybrid strategy risks grinding to a halt. While we as employees and businesses become increasingly reliant on cloud architectures, we must always remember the multitudes of components that make up an IT network.

Continuing to rely on siloed systems or architecture will always leave a busines open to attack and weaken any resilience efforts put in place. Now is the time to assess how your IT systems interplay, what the minimum viable organisation operation looks like, and take steps to secure those elements.

When we do this, resilience programmes can protect a company’s Achilles heel.

Flick March

Flick March, UKI Security and Resiliency Practice Leader at Kyndryl

    The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

    Share. Facebook Twitter LinkedIn Email Copy Link

    Related Posts

    The Real Cost of Inconsistent Third-Party Access

    December 18, 20255 Mins Read

    What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

    August 7, 20256 Mins Read

    The Evolving Importance of Identity Governance in FinTech

    July 10, 20258 Mins Read
    ISB-Bora-Side-Bar

     
    ISB-Bora-Side-Bar
    Black ISB Logo

    Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

    X (Twitter) LinkedIn Facebook RSS

    Working With Us

    • About Us
    • Advertise With Us
    • Contact Us

    Write For Us

    • How To Contribute

    The Pages

    • Privacy Policy
    • Cookie Policy
    • AI Policy
    • Terms & Conditions
    • Copyright Notice

    Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}