By Nick Haan
As we move into 2026, one thing is becoming impossible for any organization to ignore, and that is that the networks on which everything operates are still far more fragile and interconnected than many decision-makers admit. With geopolitical tensions high, state-funded attacks are becoming more OT-specific, and we can expect that 2026 will bring with it another round of high-impact, headline-grabbing incidents – the kind that disrupt energy grids, transport systems, and daily life.
So, if there’s a single lesson as we start 2026, it’s this:
Organizations can’t afford cyber security as an afterthought. Cyber resilient by design must become the norm and a principle to which we all lean into. Critical infrastructure can’t afford to bolt resilience on later; it must be built in from the blueprint. Being cyber resilient by design is no longer a nice-to-have; it’s the only way to protect increasingly fragile networks from the next wave of targeted attacks.
Security needs to be foundational, not optional, so that critical infrastructure and systems are better prepared to withstand and recover from cyber incidents. Ultimately, this will help organizations prioritise resilience and make better, long-term decisions about where to allocate resources for security.
Linked to this is another area that organizations need to think about – that the patchwork approach to remote access and vendor tooling that many adopt simply won’t scale or be effective. This is because running different tools from a multitude of vendors is creating complexity, cost, and, ultimately, weak points across already fragile networks. Instead, organizations need to increasingly prioritise functionality and security over cost, as threats rise and legislation tightens.
If I were a CISO, then I’d have made it my New Year resolution to stop adding more and to start strengthening what I already have.
Prioritise resilience, simplify the ecosystem, and eliminate the fragility that attackers are counting on. Because in 2026, resilience won’t just protect systems – it will define which organizations stay operational when the next wave hits.
The author
Nick Haan is Field CTO at Claroty






