Building resilience: Cybersecurity, AI and crisis management | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Digital Content Editor, Eve Goode speaks exclusively with Tom Exelby, Head of Cyber Security at Red Helix about cybersecurity, AI and crisis management.

You spent 15 years in the British Army, including bomb disposal and strategic planning with NATO operations. What lessons from that experience have been most valuable in your career in cybersecurity? 

The longer I spend out of the Army the more I realise how closely military experiences maps to cybersecurity. Three elements really stick out and are currently shaping my career in cybersecurity.

The first is risk management under uncertainty.

Military operators are taught to think and act decisively under pressure without having complete information upon which to base their decisions.

This is exactly the situation an organisation is in when it is dealing with an incident, so being able to advise on how to thrive in this kind of situation has been really useful.  

The second is complex programme management.

Military strategic planning is about coordinating multiple moving parts and competing priorities toward one objective.

Cybersecurity within a modern organisation is just as complex, a web of people, process and technology, and third parties, all changing at once.

Being comfortable structuring that complexity has been invaluable.

The third, and the one people often underestimate, is the interpersonal side.

The Army puts you in front of very diverse range of situations, teams and stakeholders, often under pressure.

This forces you to learn how to lead and communicate across a wide spectrum.

That’s remarkably like cybersecurity, where you move between technical teams, boards who need risk explained in business terms and customers in the middle of a crisis.

The ability to read the room and build trust quickly has been as valuable as any technical skill.

How can businesses balance strong cybersecurity with the need to innovate and grow? 

Innovation and security must not be seen as competing priorities, they are the same priority looked at from two angles.

You cannot grow sustainably on weak foundations, and trying to do so usually costs more time and money later than building it in from the start.

The difference shows up in how organisations adopt new technology.

If security is bolted on after the fact, every new project risks a redesign, a compliance gap or an incident that forces a pause. If it’s built in from the outset, the business can move faster with fewer surprises.

AI is the clearest example right now. It’s transforming how businesses operate, automating work, improving decision making, enabling new services.

But without governance, access controls and user awareness, that value flips into risk: sensitive data ends up in external models, confidential information leaks or decisions get made on AI outputs nobody has verified.

The businesses seeing durable growth are not the ones moving fastest, they are the ones that got the governance and risk management right from day one.

Security isn’t a brake on innovation, it’s what gives a business the confidence to adopt new technology without betting the company on it.

What can organisations learn from military approaches to crisis management when responding to a cyber-attack? 

Military training is all about dealing with uncertainty and responding to incidents.

It trains relentlessly for crisis, and three parts of that transfer directly to cyber-incident response.

The first is rehearsal. Militaries don’t improvise their response, they drill it until it’s second nature.

Most organisations have an incident response plan on paper, but few have tested it under pressure and an untested plan tends to fail exactly when it matters most.

The second is clear command and control.

In a crisis, everyone needs to know what their role is and what decisions they own.

Too often in business this is unclear when an incident hits, costing time and giving the adversary the upper hand.

The third is communication skills.

The military trains people to share what’s known, what isn’t and what’s being done, rather than waiting for a full picture.

Organisations that stay silent until everything is confirmed usually lose trust with customers and regulators faster than the incident itself would have cost them.

A cyber-crisis tests leadership as much as it tests technology.

The organisations that come through it well are the ones where people already knew their role and trusted the plan, because they’d been through it before, even if only in a drill.

With AI making cyber-attacks more sophisticated, what advice would you give to businesses that are looking to adapt their approach to cyber-defence? 

AI is changing the speed, scale and sophistication of attacks and businesses need to think about whether their security operates fast enough to keep up.

If attackers are moving at machine speed, defence must as well.

Crucially, security fundamentals don’t change, however they need to be applied faster and more accurately and across every domain, including AI itself.

Identity and cloud remain the areas businesses most often neglect, and they’re exactly where attackers are finding the easiest way in.

Detection and response need consistent coverage there, not just on the traditional endpoint.

That speed and coverage only matter if businesses accept the premise behind them: it’s a case of when they face an incident, not if.

Resilience, the ability to detect fast, respond fast and recover, must be built in from the start, not bolted on after the first breach proves the point.

Where businesses get caught out is chasing the latest tool rather than getting the basics right at the speed the threat now demands.

Getting the board to understand the return on investment in cybersecurity, not just the cost, is what unlocks the right level of investment in the right places, rather than a scramble for the newest solution after the fact.

The businesses best placed to deal with AI-enabled threats aren’t the ones with the most tools, they’re the ones who’ve got the basics covered, at machine speed, built for resilience rather than hope.

What’s one thing that you would suggest businesses change within the next year to improve their cyber-resilience?

This answer is deliberately short.

I would recommend that every business runs an incident response exercise.

Not a policy review, an actual exercise. This could be the difference between a business surviving an attack or failing because of one.

Most businesses have a plan on paper that’s never been tested under real pressure with the right people making real decisions.

That’s exactly where they fail when an incident hits.

The exercise is only half the value.

What matters just as much is what happens after: capture the lessons honestly, make the changes and use it to raise awareness right across the business, not just in the security team.

——————————————————-


Click Here For The Original Source.