How can organisations build cyber-resilience in an era where AI is transforming both cyberattacks and cyberdefence?

How can organisations build cyber-resilience in an era where AI is transforming both cyberattacks and cyberdefence?

Cybersecurity leaders are increasingly rethinking resilience strategies as Artificial Intelligence transforms both the speed and sophistication of cyberattacks and cyberdefence. Fraser Hutchison, Vice President and Managing Director – UK & Ireland at Cohesity; Kris Voorspoels, Director of Products & Solutions at OPSWAT; and Shailesh Athalye, Senior Vice President, Product Management at Qualys, explain how organisations can strengthen cyber-resilience through trusted recovery, secure AI architectures and AI-driven vulnerability management.

Artificial Intelligence is reshaping cybersecurity at unprecedented speed. While organisations are embracing AI to improve efficiency, automate operations and accelerate innovation, cybercriminals are exploiting the same technologies to launch more sophisticated attacks, automate reconnaissance, generate convincing phishing campaigns and identify vulnerabilities faster than ever before. As a result, the challenge facing security leaders is no longer simply how to defend against cyberattacks, but how to build organisations capable of withstanding and recovering from them.

Meeting that challenge requires a fundamental shift in thinking. Cyber-resilience is becoming just as important as prevention, with organisations placing greater emphasis on trusted recovery, resilient architectures, intelligent vulnerability management and the secure adoption of AI itself. Rather than viewing AI solely as another technology to deploy, security leaders are increasingly considering how it can strengthen defence while ensuring it does not introduce unacceptable levels of risk.

In this feature, three experts share their perspectives on how organisations can build cyber-resilience in the AI era, offering practical advice on trusted recovery, secure AI architectures and the intelligent prioritisation of cyber-risk.

Fraser Hutchison, Vice President and Managing Director – UK & Ireland, Cohesity

Fraser Hutchison, Vice President and Managing Director – UK & Ireland, Cohesity

Building cyber-resilience through an AI-powered Minimum Viable Company

AI is changing the economics of cyber-risk. Attackers are using it to automate reconnaissance, create more convincing social engineering, accelerate vulnerability discovery and adapt campaigns at machine speed. Defenders should also use it to improve detection, prioritise alerts, investigate incidents and speed up responses. The outcome is not dictated simply by a technology race. It is a resilience contest.

Start with the business, not the technology

Organisations that recover fastest in this new AI era do not begin by asking how to restore everything. They ask what must keep operating for the organisation to survive. This is the value of defining a Minimum Viable Company: the smallest combination of services, people, processes, data, systems, suppliers and decision paths required to continue operating safely during a crisis.

Five priorities for AI-era business resilience

First, map critical services to business value. AI further compresses attacker timelines, with agentic tools able to support reconnaissance, lateral movement and elements of extortion with less human input, so recovery priorities must be clear before an incident. Leaders should know what must function in the first 24 hours, 72 hours and the first week, and which systems, identities, data sets and third parties those services depend on. 

Second, protect the trusted foundation. Identity, privileged access, networking, DNS, security tooling and secure communications form the control plane for recovery. If these foundations are compromised, organisations may restore systems quickly but still be unable to trust them. Zero Trust principles, strong access controls, and secure-by-design practices matter more as attackers use AI to move faster and test more routes into the environment.

Third, protect recovery from agentic attacks. Organisations need immutable, isolated recovery points that attackers cannot alter or delete, supported by AI-driven anomaly detection within the data estate, not only at the network edge. Traditional perimeter defences and periodic backups are no longer enough on their own.

Fourth, secure AI agents as critical assets. AI can strengthen recovery by scanning backup snapshots for malware, classifying sensitive data, and helping teams see what happened, what was affected, and what can safely return online. But as AI agents interact with infrastructure and business data, they must themselves be carefully considered in the overall prioritisation of critical business processes, and therefore protected, monitored, and, if necessary, rolled back to a known-good state.

Fifth, rehearse recovery under realistic conditions. A plan that has not been tested is only a theory. Organisations should run simulations that assume compromised identities, unavailable systems, uncertain data integrity and incomplete information.

Restore what matters, in a state you can trust

AI will keep changing both attack and defence, but the organisations that withstand that shift will be those that combine strong fundamentals, trusted recovery foundations, controlled use of defensive AI, and repeated validation under pressure. 

Cyber-recovery is different from Disaster Recovery. No longer is restoring everything at once, as quickly as possible, the best approach. It is about restoring what matters most, quickly, safely, and in a state the business can trust, without attacker persistence, poisoned configurations, or compromised credentials that will cause extended business disruption.

Kris Voorspoels – Director of Products & Solutions at OPSWAT

Kris Voorspoels – Director of Products & Solutions at OPSWAT

Every board is asking the same question: ‘How are we using AI to stay competitive?’ For CISOs and IT leaders in sectors such as defence, critical infrastructure and financial services, however, there is an equally important consideration: how can organisations embrace AI without increasing their risk profile?

The answer increasingly lies in architecture. Hardware-enforced one-way mechanisms, such as data diodes, are emerging as a critical control for enabling AI safely. Unlike software controls, a data diode physically enforces one-way data transfer, allowing information to move into an AI environment while making reverse flow impossible, regardless of software behaviour, misconfiguration or compromise. This allows organisations to feed AI systems the information they need without creating a pathway for sensitive data or derived outputs to leave the environment.

AI is following the cloud journey

This shift mirrors the evolution of cloud computing. Critical industries were initially reluctant to adopt the public cloud until private, sovereign and hybrid cloud architectures enabled them to modernise while retaining control.

AI is now following a similar path. Many organisations are deploying Agentic AI locally or within tightly controlled environments rather than sending sensitive information to external platforms. However, local deployment alone does not guarantee security. AI systems still rely on continuous feeds of logs, telemetry, sensor data, threat intelligence and operational information. Feeding those systems inevitably creates new data pathways.

Eliminating architectural ambiguity

Traditional controls such as firewalls, segmentation and access policies are designed to regulate these pathways, but they remain software-enforced. Misconfigurations occur, APIs expose more than intended and complex environments make absolute certainty difficult.

As AI becomes more autonomous, any bidirectional connection creates the potential for unintended outbound data movement. The risk is not only external attackers or malicious insiders but architectural ambiguity itself.

Data diodes remove that uncertainty. By enforcing one-way data transfer in hardware, they eliminate the possibility of reverse flow rather than relying on policies or application behaviour to maintain it. AI systems can ingest threat intelligence, operational telemetry or lower-trust network data, but they cannot transmit anything back across that boundary. There are no firewall rules to interpret and no policies to maintain. The restriction is absolute.

As AI adoption accelerates, organisations that succeed will not be those that block innovation or pursue it without restraint. They will be those that redesign their architectures from the outset, ensuring intelligence can flow in while risk is structurally designed out.

Shailesh Athalye, Senior Vice President, Product Management, Qualys

Shailesh Athalye, Senior Vice President, Product Management, Qualys

When Anthropic partnered with other tech leaders under Project Glasswing to release Claude Mythos as an autonomous discovery tool for vulnerabilities, it could operate at speeds that even experienced human analysts would find impossible. We can be certain that CVE disclosures are about to surge and add to an already long backlog. However, just because a tool identifies a vulnerability doesn’t mean it poses a risk in your environment.

The light at the end

Applying fixes takes time. Organisations do not have unlimited resources to patch everything. The good news is, you don’t have to patch everything. Instead, organisations need to employ hyper-prioritisation, determined by a combination of threat, business and asset context.

The next vital step is exploit validation. Even if you have a known exploitable vulnerability that exists in a business-critical asset, it might not be exploitable in your unique environment given existing security controls. Therefore, it’s crucial to validate exploitability against compensating controls, and do so at machine speed.

Here’s where AI can come in to help cyberdefenders move at scale and speed. AI-backed adversaries will not wait while we examine the problem from multiple angles. Defenders must eliminate legacy workflows of handoffs between detection, triage, ticketing, human investigation and change management. We must move from discovery to context-aware prioritisation to effective remediation. The lag between confirmed discovery of a business risk and its resolution is the only metric that should matter in today’s threat landscape.

Finally, now that we have narrowed down the deluge of exposures to the sub-one percent that actually need to be fixed, organisations need to be judicious about which of these can be patched autonomously and which need to be mitigated in other ways. Autonomous remediation is the only way to combat the influx of exposures from AI.

Trust is earned

Given the scepticism around autonomous remediation, we must build a trust infrastructure that makes autonomy safe enough for enterprise-scale operation by testing the reliability of patches before they are autonomously deployed. Organisations can do so by allowing AI agents to trace the attack path in the live environment without disrupting production. There are also other options for mitigations, such as for zero-days when either the patch is not yet available or patching is operationally impractical.

It is also worth discussing how best practices in AI-powered vulnerability management extend to custom applications and all the IDEs, APIs and other tools and services used in their construction. No matter how a software flaw is found, the organisation must be able to detect it in a production environment, validate its business risk and mitigate it just as quickly as it would a critical third-party vulnerability. Increasingly, enterprises are relying on the Risk Operations Center (ROC) model to deliver AI-powered risk management. I see this operationalisation as the defining cybersecurity challenge of 2026.

AI-driven discovery of software vulnerabilities is an undeniable leap forward. But in dealing with what comes after discovery, we must prioritise with context, not legacy scoring systems. Design your risk management approach and workflow around what makes sense to your unique business and AI will take its place as a valued tool and a game changer for cybersecurity.

The age of managing vulnerabilities at human speed has ended. The real question is: ‘How fast can you embrace and trust autonomous remediation?’

Browse our latest issue

Intelligent CISO Middle East

View Magazine Archive