From Static Defenses To Dynamic Systems

Cybersecurity today isn’t just about prevention – it’s about ensuring continuity and recovery in the face of inevitable breaches or outages. Take a moment to look at your organization: If your systems went down, how long would it take for you to be fully operating again?

Building a truly resilient defense requires multi-layered strategies that protect against evolving threats and ensure systems can endure.

This past summer, CrowdStrike learned the hard way that its systems were not resilient enough. One small mistake in an update pushed out to users caused systems to crash across the globe, halting operations for airports, banks and more. 

This incident highlights how a single error can cascade through interconnected systems and underscores the need for cybersecurity leaders to map and manage dependencies proactively today. While CrowdStrike resolved the issue quickly, the ripple effect left many customers struggling to restore operations for weeks. Conducting regular recovery timeline tests – both for internal systems and those dependent on them – could have significantly reduced downtime and disruption for their customers.

Resilience goes beyond defense though, too; it’s about planning for worst-case scenarios and ensuring systems bounce back stronger. In 2025, hyper-vigilant proactivity and resilience will be essential for effective cybersecurity strategies across the world.

Human Error Remains The Achilles’ Heel

Attackers are increasingly exploiting the gaps between technical defenses and human behavior, making human error one of the greatest vulnerabilities in cybersecurity. Advanced training must continue to evolve alongside attackers' tactics to combat this – moving beyond simple simulation exercises. Incorporating adaptive training environments that use AI to generate evolving attack scenarios for instance ensures employees regularly face novel threats.

The more exposure they have to these dynamic challenges, the better equipped they will be to better protect their organization.

Meaningful metrics matter too. Tracking phishing training participation rates isn’t enough anymore. Instead, measuring post-training improvement rates, like how often employees correctly identify and report phishing attempts, is much more impactful. Additionally, analyzing response times – how quickly employees report incidents and how fast teams mitigate them – provides valuable insights into real-world preparedness and confirms that employees can successfully avert more advanced threats like APTs. 

Proactive System Analysis 

The interdependencies in today’s digital systems mean failures in one area can cascade across an entire organization. As the CrowdStrike incident demonstrated, organizations fall short when critical dependencies go unnoticed until a failure occurs. To prevent this, cybersecurity teams must move beyond siloed testing and adopt proactive system analysis.

Siloed testing overlooks how systems as a whole interact under real-world pressure. To build greater resilience, organizations need to map their interdependencies dynamically by asking themselves questions like “Which of our systems rely on others and how will any failures propagate as a result of an attack on one?” Continuous “war game” simulations can help stress-test resilience, exposing weak links before they become points of failure and allowing organizations to build fail-safes directly into system design. 

Rethinking Ransomware-Resistant Backups As A Strategic Asset

Backups are often treated as an afterthought when they should be seen as a cornerstone of any ransomware strategy, as they’re critical for restoring operations quickly in the event of an attack. Offline and air-gapped backups are essential to ensure isolation from compromised systems and unauthorized access. Automating integrity checks also ensures backups remain uncorrupted and accessible under pressure.

Simulating recovery through drills prepares teams for worst-case scenarios. Every minute counts, and end-to-end scenarios can highlight interdependencies or bottlenecks that slow recovery.

Organizations shouldn’t assume that backups are a silver bullet, however. The only way backups remain effective is through proper recovery workflow testing and the right processes and team support in place to restore operations quickly.

Ethical Considerations In AI & Decentralized Systems

The risks of unchecked AI are immense and as the technology becomes a core cybersecurity tool, organizations must grapple with ethical and operational questions about its use to uphold resilience in 2025 and beyond.

To minimize risk, organizations should first establish clear governance frameworks to ensure transparency in decision-making. This reduces the risk of the AI performing unintended actions and helps limit the impact of adversarial attacks. Next, they should implement oversight mechanisms for high-stakes actions and identify those responsible for intervening when the AI makes an error. Finally, they need to stay ahead of compliance challenges by aligning AI practices with emerging regulations and legal frameworks. 

When integrating AI into cybersecurity systems, it will be essential to ensure that AI-driven decisions are explainable rather than relying on black-box models.

Organizations should also assess the human impact of AI errors. Mistakes in automated decision-making can have far-reaching consequences, so balancing automation with human oversight is key to ethical AI deployment.

Resilience As The Ccornerstone Of Cybersecurity In 2025

Resilience isn’t just about enduring threats – it’s about maintaining the ability to operate and recover under any circumstances. Building dynamic systems requires multi-layered strategies, including adaptive training, AI-driven defenses, proactive system analysis, and robust backup solutions. Continuous testing and refinement ensures systems can keep pace with evolving threats.

By adopting these practices, cybersecurity leaders can shift from static defense to truly resilient systems, capable of mitigating risks and ensuring long-term operational strength in 2025 and beyond.

Engin Kirda is a program co-chair of ACM’s CCS and Professor at Northeastern University

Image: Andrii Yalanskyi

You Might Also Read:

Are Any Of Your Suppliers A Security Risk Waiting To Happen?:


If you like this website and use the comprehensive 7,000-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

 

« Medusa Ransomware Attacks Focus On Critical Infrastructure
Guidance Is Coming, But Hackers Aren’t Waiting »

CyberSecurity Jobsite
Check Point

Directory of Suppliers

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Tines

Tines

The Tines security automation platform helps security teams automate manual tasks, making them more effective and efficient.

EC-Council

EC-Council

EC-Council is a member-based organization that certifies individuals in various e-business and information security skills.

OASIS Open

OASIS Open

OASIS Open is where individuals, organizations, and governments come together to solve some of the world’s biggest technical challenges through the development of open code and open standards.

Inspired eLearning

Inspired eLearning

Inspired eLearning deliver solutions that help clients nurture and enhance workforce skills, protect themselves against cyberattacks and regulatory violations.

Georgia Cyber Center

Georgia Cyber Center

Georgia Cyber Center is dedicated to training the next generation of professionals through education and real-world practice while also supporting innovation in new technologies for online defenses.

Air Informatics

Air Informatics

Air Informatics LLC provides security, information management, analytics and informatics for IT and wirelessly enabled airplanes and operations.

Balbix

Balbix

Balbix BreachControl™ is the industry’s first system to leverage specialized AI to provide comprehensive and continuous predictive assessment of breach risk.

ODSC

ODSC

ODSC is a security systems integrator that provides services and expertise in identity management and access.

SecureMe2

SecureMe2

SecureMe2 ‘s mission is to make organizations more responsive to digital threats by deploying smart technology in a highly accessible way.

International Accreditation Forum (IAF)

International Accreditation Forum (IAF)

The IAF is the world association of Conformity Assessment Accreditation Bodies. Its primary function is to develop a single worldwide programme of conformity assessment.

Intrinsyc Technologies

Intrinsyc Technologies

Intrinsyc provides product development services and Edge Computing modules that are helping to take the Internet of Things products to the next level.

SecondWrite

SecondWrite

SecondWrite’s next-generation malware detection engine delivers a combination of automatic deep code inspection and accurate scoring of zero-day malware.

Emtec

Emtec

Emtec’s cyber security team provides advisory, assessment, & managed security services that help you build the cyber security policies, toolsets & best practices to elevate your cyber security posture

Imprivata

Imprivata

Imprivata is the digital identity company for life- and mission-critical industries, redefining how organizations solve complex workflow, security, and compliance challenges.

Spera Security

Spera Security

Spera helps identity security professionals effectively and confidently measure, prioritize and reduce identity risk to better protect the organization from identity-based attacks.

TeamT5

TeamT5

TeamT5 Inc. is a leading cybersecurity company dedicated to cyber threat research and solutions.

Future Crime Research Foundation (FCRF)

Future Crime Research Foundation (FCRF)

FCRF is a Non-Profit NGO specializing in Research in Cyber Security, Digital Crime, Fraud Risk Management, Cyber Laws and Cyber Forensics.