Summary
- Cyber resilience depends on people, governance, and culture as much as technical controls.
- Point-in-time audits and annual vendor checks leave organisations exposed to fast-changing risk.
- Investment should prioritise continuous visibility, supply chain resilience, and security-aware teams.
Walk into any security conference this year and the conversation sounds the same wherever you stand. AI. Automation. Next-generation tooling. Every vendor stand promises the platform that will finally get you ahead of the threat. And I understand the appeal, I sit on the buying side of that conversation too, and these tools genuinely have value.
But I’ve sat in enough incident rooms at 2am to know that the breaches which do the most damage are rarely the ones a better tool would have stopped. They’re the ones where somebody clicked, somebody trusted, or somebody assumed a partner had it covered.
The next generation of cyber resilience won’t be defined by who has the shiniest stack. It will be defined by who takes people, governance and culture as seriously as they take technology.
The human element hasn’t gone away, it’s evolved
The Verizon 2026 Data Breach Investigations Report puts the human element in 62% of confirmed breaches. I’m not surprised by that number, and I don’t think anyone still working the floor of a SOC would be either.
What I do think is wrong is how the industry still talks about it. “Humans are the weakest link” needs to be retired for good. In my experience, the organisations that get breached hardest aren’t the ones with careless staff, they’re the ones where nobody made it easy, safe or rewarding for a person to say “something feels off about this.”
People are not a vulnerability to be fixed. They are the first line of defence, and often the only barrier a determined attacker needs to overcome. When organisations recognise people as a critical security control and invest in them with the same priority as any technical control, the effectiveness and resilience of the entire security programme changes dramatically.
Your supply chain is now your attack surface
Ernst & Young’s disclosure this year where an unauthorised party got in through a third-party IT support platform and walked out with client tax and investment documents, is the story I keep coming back to. Not because it’s unusual, but because it’s exactly the kind of access nobody puts on the risk register. Nobody runs a tabletop exercise on the support desk.
That’s the pattern I see again and again advising boards: enormous energy poured into hardening the front door, and a fire escape round the back that hasn’t been checked in two years because it belongs to somebody else’s IT estate, not yours.
Verizon’s data shows third-party involvement in breaches has roughly doubled in a single year, and honestly, having watched procurement and security teams operate in silo rather than together for most of my career, I’m more surprised it isn’t higher. A vendor risk register that gets updated once a year at renewal isn’t governance. It’s checkbox paperwork.
Point-in-time assurance is not resilience
This is where I think most organisations are still getting it wrong, and it’s the argument I find myself making most often in the boardroom. A clean audit report or a passed penetration test gives you a snapshot in time, not a state of ongoing health. Risk, control effectiveness and vendor exposure all shift week to week, sometimes day to day.
I’d rather have honest, continuous visibility of where I’m exposed right now than a polished report telling me I was fine three months ago. Resilience is a live picture, not a certificate on the wall.
Where I’d spend the next pound
If you’re a CISO staring at next year’s budget, here’s where I’d start, in order, and it’s a deliberately practical, pragmatic order.
First, continuous risk visibility. Build the capability to see control effectiveness and emerging exposure in near real time, not just at renewal or audit season.
Second, supply chain resilience. Continuous monitoring of third parties, cloud providers and technology partners needs its own budget line and its own named owner, not a clause in someone else’s contract review.
Third and this is the one I’d never cut, whatever the pressure on budget: your people. Security awareness has to graduate from an annual compliance module into a genuine culture, one where reporting a mistake is rewarded rather than punished, where security is everybody’s job, and where the board asks sharp questions instead of nodding along to a green dashboard.
Technology gives you capability. Governance gives you direction. But it’s people who create resilience. I’ve yet to see an organisation talk itself out of a breach with a tool it bought after the fact. I’ve seen plenty talk themselves out of one because someone on the front line trusted their instincts and picked up the phone.
Fund all three, in that order when budgets are tight, and you’ll be building resilience rather than shopping for it.





