Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Cyber resilience»Cyber resilience maturity starts with the CISO (Page 8)
Cyber resilience

Cyber resilience maturity starts with the CISO

Every business needs to detect, defend, and recover from cyberattacks. However, the CISO's role in executing those priorities differs greatly among businesses; and it often depends on where the organization stands on its growth curve, argues Javier Dominguez, CISO at Commvault.
January 13, 20255 Mins Read
Resilience maturity - a tower of blocks rises to show maturity.

Check Point Research revealed that the number of global cyberattacks in Q3 2024 increased by a staggering 75% compared to 2023. At the same time, a Commvault survey found that just 13% of global organizations are considered ‘cyber mature’ despite the continuing rise in threats. Given the rapid growth and evolution in cyberattacks, these are concerning statistics.

Cyber mature organizations can recover from an attack 41% faster than those companies at the lowest end of the scale, thanks to several key resilience markers. These explain why some companies could restore data quickly and resume business as usual while others couldn’t.

Top of the priority list for organizations looking to improve their cyber resilience are security tools, which provide early warning alerts using preset runbooks, roles, and processes. Also critical is an isolated stable, clean, dark-site or secondary backup solution to store vital immutable data. Regular testing of cyber recovery procedures to keep them up-to-date is another key resilience marker. However, the onus is on the CISO to make these things happen so how does the CISO role tend to develop alongside cyber resilience maturity?

Measuring CISO maturity

CISOs exist to defend operations from cyberattacks, however, their authority can vary, with a direct impact on the overall cyber maturity of an organization. The least mature CISOs are acting on the orders of seniors while those at the other end of the scale are engaging with the board to guarantee that cybersecurity is integrated across the business. This maturity cycle can be broken into five phases:

Box-tickers

In the least developed companies, mainly small, private organizations, security leaders are rarely policy makers and usually do not have a dedicated CISO role. Instead, cybersecurity is managed by the IT department, which reports into an IT director or CIO. Daily routines, such as patching software upgrades, configuring servers, and setting up laptops act as way to also handle cybersecurity at a low level.

For these companies, other priorities, such as sales, leave cybersecurity overlooked. As a result, key safeguards like multi-factor authentication, might not be deployed because they are seen as a hindrance and annoyance. Thus, cybersecurity is downgraded to a mere check box exercise.

Introducing the CISO

As an organization expands so does its attack surface, becoming a bigger target for malicious actors. An increase in employees, customers, and suppliers, with more processes and applications, means more exploitable vulnerabilities. This is when cybersecurity begins to climb the board’s agenda and they start to consider a dedicated senior cybersecurity leader or CISO.

At this point, the role is largely a technical post with the CISO expected to spend time working with the development team rather than planning and executing a company-wide cyber strategy. This is also when compliance demands become more important with a need to deploy formal monitoring and auditing solutions. IT and security must build clear security channels with mutually agreed objectives to prevent gaps from appearing.

Beyond the technical CISO

It soon becomes clear that the CISO must have the authority to assess and implement security controls and processes across the company. While the CISO should already be responsible for defending, detecting, and recovering from attacks, they should also be able to deploy more wide-ranging procedures to protect cloud systems or ensure control via access management solutions.

While some senior executives might complain about such measures slowing down time to market, this is the point where leaders must support the CISO and the roll out of vital new cybersecurity projects.

Empowering the CISO

When a company reaches full maturity, the CISO is engaging in strategic planning with the board, inputting on cybersecurity risks, resilience, and recovery. In collaboration with the leadership, the CISO should establish the company’s risk tolerance levels and supply analysis to show any changes in the risk profile with policies in place to stay within agreed levels.

With this degree of maturity, CISOs are also consulting on the benefits and drawbacks of emerging technologies, such as AI, making cybersecurity a foundational part of strategic planning.

Security by design

For organizations at the final maturity stage, security is woven tightly into the fabric of the business, with employees expected to follow strict security processes and policies. At this point, cybersecurity is baked into the foundations of the organization, informing every aspect of business. Continuous testing and monitoring of corporate systems is par for the course and security teams are well-versed in incident response and data recovery.

Planning for maturity

Every company has its own unique IT infrastructure, security policies, and strategic objectives, depending on size, leadership, public or private status, and so forth. Therefore, calculating the progress through the cybersecurity maturity cycle is not simple. However, by understanding each stage’s characteristics, leaders can more robustly align the development of internal candidates or find the right external equivalent. This will assist in the development of cyber maturity to match the company’s risk tolerance levels and leave it well positioned to withstand the ongoing wave of attacks.


More details on Commvault’s 5 Proven Resiliency Markers of Cyber-Ready Organizations

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleSetting security levels too high is a risk in its own right. ‘Right-sizing’ cybersecurity is the way forward…
Next Article UK IoD paper looks at how business risks are expected to develop through 2025

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
A cargo ship being loaded at a port.

UK Government report explores supply chain risk and resilience

June 24, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?