Cyber resilience as a business compass: how to survive the day after an attack

Cyber resilience as a business compass: how to survive the day after an attack

  • 28/Jul/2026
  • ForgeNEX by ForgeNEX
  • AI

Cybersecurity is no longer just about preventing attacks, but about ensuring that the business can continue to operate even when defenses fail. This paradigm shift has turned cyber resilience into the lifeblood of organizations. As experts consulted by CSO España point out, the key question is no longer "Can they attack us?" but "How long will it take us to recover?" In a landscape dominated by ransomware, generative artificial intelligence, and interdependent supply chains, the ability to restore operations, recover data, and preserve trust has become a strategic indicator as relevant as prevention.

la-resiliencia-cibernetica-ya-es-el-pulso-vital-de-0.jpg

The new starting point: from recovery to operational continuity

Doris Seedorf, CEO of Softtek for Spain, sets the framework: "As we analyzed in our White Paper CIO Agenda: 2026 Edition, resilience in cybersecurity is understood as an end-to-end business continuity strategy." It is no longer enough to restore data; the company must be able to continue operating and providing critical services during an attack, minimizing financial and reputational impact. "This change is mandatory because current threats actively destroy traditional backups and paralyze entire operational chains," adds Seedorf.

This comprehensive approach resonates with the need for tools that enable efficient time and resource management, such as time tracking and clocking to accurately record time spent on each project, which is critical in post-incident recovery.

Automation and machine speed: responding to offensive AI

Carlos Baquero, Head of Business Development and Presales at Serval Networks, argues that the massive adoption of generative AI has transformed cybersecurity by automating and accelerating offensive attacks at "machine speed." "Complex tasks such as vulnerability reconnaissance and social engineering are now faster and cheaper. Faced with this threat, traditional manual procedures are insufficient," he explains. Therefore, cyber resilience demands an automated response of equal speed, based on proven playbooks to isolate assets, block threats, and restore priority services. "This automation does not seek to replace human specialists, but to free them from repetitive tasks and optimize response times," he adds.

Baquero also highlights the second inflection point: regulatory, driven by the DORA regulation, applicable from January 2025. This regulation makes digital operational resilience a verifiable obligation for the financial sector, requiring ICT risk management, incident notification, periodic testing, and third-party oversight. "Under this framework, traditional disaster recovery is insufficient. A cyberattack can simultaneously compromise systems, identities, data, and backups," he warns.

la-resiliencia-cibernetica-ya-es-el-pulso-vital-de-1.jpg

Resilience as a cross-cutting capability: beyond IT

Andrés Mendoza, Technical Director for Southern Europe and Latin America at ManageEngine, explains that over three years the concept of cyber resilience has evolved: "Now it's not just about 'bringing systems back up,' but about maintaining essential functions while absorbing the impact, recovering activity with guarantees, and learning from the attack to strengthen the environment." Disaster recovery remains key, but it's only one part: "Resilience starts earlier, with visibility of critical assets, prevention, early detection, containment, and response coordination."

Mendoza warns that this vision is not fully implemented in Spain: according to his study Operational Resilience in 2026, only 35% of organizations in Spain have a formal methodology to measure their resilience, and barely 30% address it regularly at the management level. "The problem is not a lack of tools; what is missing is a common framework that allows knowing and measuring whether all elements would actually work in a coordinated manner during a crisis," he states.

This need for integration and coordination aligns with solutions like internal chat and boards for real-time communication between teams, essential during incident management.

The geopolitical context and identity as a new battlefield

Eutimio Fernández, Regional Sales Director for Iberia at Thales Cybersecurity Products, points out that attacks are not solely aimed at economic gain, but also at destabilizing critical infrastructures and public administrations. The emergence of AI is reshaping business infrastructure, shifting focus from performance to control. "That is why resilience has ceased to be a purely technical issue and has become a structural principle of the business."

According to Thales data, identity-related threats now account for more than three-quarters of all security breaches, and credential theft remains the predominant attack vector in 67% of organizations that have suffered incidents in cloud infrastructure. "Today, only 34% of companies know exactly where all their data is stored, and therefore 66% do not have it adequately protected," adds Fernández.

Differences between surviving and succumbing: preparation and simulation

Alessandro Armenia, Director of Cybersecurity at ReeVo, states: "An IT outage becomes a serious problem when the company does not have a plan. A prepared organization, with defined and tested procedures, can recover in minutes; those that are not prepared risk losing hours, days, and in some cases, their reputation."

José de la Cruz, Technical Director of TrendIA Iberia, agrees: "Organizations that know which services are critical, have clear procedures, conduct periodic drills, and have technologies that allow them to securely recover data are the ones that best respond to cyberattacks." Incident management is not only a technological challenge but also an organizational and business one.

Benjamín Zamora, Presales Engineer at Infinigate Iberia, adds that the most resilient organizations know their critical assets and dependencies, have clearly defined responsibilities, and have rehearsed their procedures. "In short, they do not improvise on the day of the incident: they have already practiced how to continue operating under attack."

la-resiliencia-cibernetica-ya-es-el-pulso-vital-de-2.jpg

Common mistakes: slow patching, lack of automation, and fragmentation

Eva Puerta, CISO of Check Point Software, identifies the most critical error: the exposure dwell time. "Companies continue to operate under the traditional scheme of identifying a vulnerability, opening a ticket, and waiting days or weeks for the systems team to apply the patch. With attackers generating exploits in less than an hour, traditional patching cycles are broken." Another major flaw is the lack of automation in incident mitigation: "Many companies spend too much time analyzing alerts and too little executing automated containment actions."

Álvaro Fernández, Sales Director of Sophos Iberia, highlights overconfidence in multi-factor authentication: in Spain, 92% of incidents with compromised credentials already had some form of MFA. It is also common to prioritize prevention of technical vulnerabilities when malicious email and phishing have surpassed vulnerabilities as the main root cause of ransomware attacks. "Another recurring mistake is treating security as a set of disconnected tools. A typical company uses more than 45 different security products, multiplying dashboards, costs, and manual work," he adds.

This fragmentation problem can be mitigated with integrated platforms such as advanced Microsoft Azure solutions, which offer innovation and scalability to centralize security management.

Metrics that matter: beyond technical indicators

Víctor Calvo, Head of Communications and Security SNOC at fibratel, urges boards of directors to measure resilience with indicators linked to business impact. "It is important to know how long the organization takes to detect an incident, contain it, and recover critical services, but also the actual availability of those services, the degree of response automation, the percentage of successful verified restorations, and the coverage of continuous monitoring." Resilience is not demonstrated with a document, but by verifying that the organization can continue operating during an incident.

DORA and NIS2 regulations: compliance as a compass, not a formality

Javier Jurado, Business Development Director at Exclusive Networks Iberia, explains that these regulations are turning resilience into a capability that must be tangibly demonstrated. DORA requires the financial sector to manage ICT risk, conduct advanced resilience testing, and oversee providers; NIS2 reinforces this logic in critical sectors, transferring legal and operational responsibility to management bodies. "Resilience ceases to be a technical issue and becomes an essential part of corporate governance."

Jurado warns that legal compliance should not be a mere documentary exercise: "Regulations should serve as a compass, but they can never become a simple bureaucratic formality. Compliance does not replace resilience, as resilience only exists when protection measures work effectively under pressure."

In this journey, the channel and value-added distributors play a decisive role by connecting technologies, specialized knowledge, and services capable of covering the entire security cycle. "Gone are the days when isolated solutions were simply accumulated, giving way to the phase of building a coherent architecture that allows the organization to maintain its pulse and navigate even in the midst of the worst crisis," he concludes.

The evolution towards cyber resilience also requires a cultural and talent shift, as analyzed in the article Talent vs. Technology: How Europe can close the gap in the AI era, and the experience of companies like Syvalue shows that specialization and trust are key to innovating in this field.


Original source: ComputerWorld. Analysis and adaptation by ForgeNEX.

Share: