Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Cyber resilience»Cyber security can’t scale with humans anymore (Page 7)
Cyber resilience

Cyber security can’t scale with humans anymore

July 29, 20266 Mins Read
Future cyber security concept.

By Ashley Leonard

Malicious actors are already using AI to increase the speed and scale of cyber attacks, while many defenders are still relying on manual processes that simply can’t keep up.

Security teams remain overly committed to keeping humans in the loop for every decision, every alert, and every response. This approach worked when threats moved more slowly, but today it creates delays when organizations need to move faster.

Organizations must shift more operational control to automation while applying human expertise to oversight, guidance, and decision-making rather than manually carrying out every task.

Absolute Security’s latest research shows this strain clearly: 55% of CISOs experienced an attack in the past year that rendered endpoints used for remote or hybrid work inoperable, while many organizations are juggling dozens of disconnected security tools without achieving full endpoint visibility.

Legacy cyber security tools and manual strategies can no longer keep pace with an AI-driven threat landscape. Attackers are accelerating through automation, while defenders are still tied to workflows built for a slower era.

A core cyber resilience concept is that prevention alone is no longer enough. Organizations must be able to withstand disruption and continue operating even when systems are compromised.

The AI acceleration gap

Cybercriminals are no longer operating only manually. As they adopt automation and AI, their attacks are moving faster and on a greater scale, while most organizations are still relying on processes that need human intervention at every step.

61% of CISOs say the current combination of accelerating AI capabilities and changing regulations is making it harder to protect their organizations. While attackers move faster, the gap between what they can do and how quickly defenders can respond continues to widen.

Many modern threats are designed not just to breach systems, but to disrupt operations and weaken the security controls meant to stop them. The recent Stryker incident in Ireland is a clear example of this, as attackers managed to turn organizational security tools against the organization itself, exposing just how fragile environments reliant on manual processes can be under pressure.

Even when organizations have the right tools in place, those tools may not remain effective when systems are under strain.

Closing this gap means moving away from reactive defence and towards more autonomous, self-directed but well-governed systems, that can respond in real time and keep working without waiting for human input.

Why manual security fails

Today’s security teams are confronted with an impossible mixture of overwhelming complexity and uncertainty.

Nearly half of organizations lack visibility into how AI is being used inside their own environments, creating a growing shadow AI problem. Even more concerning, a significant majority of CISOs believe this lack of visibility will ultimately lead to a data breach.

This is not only about defenders giving up more operational control to automation, but also about recognizing that CISOs have blind spots within their own organizations.

Unmonitored AI use introduces risks such as malicious ‘skills’ in LLMs and prompt injection that can quietly bypass established controls. These behaviours often blend into everyday activity, making them harder to detect without stronger automated oversight.

At the same time, security teams are overwhelmed by the sheer volume of alerts and the complexity of disconnected security tools, leaving organizations vulnerable.

Automation as defence

If attackers are scaling through automation, defenders must do the same. Stopping threats is no longer the only concern; it is also about ensuring that systems remain operational and can recover quickly when incidents occur.

This is driving a change in priorities, with 65% of CISOs now prioritising cyber resilience over traditional prevention and detection strategies, emphasising a fundamental shift in how security effectiveness is measured.

As organizations adapt to this shift, it is becoming clear that today’s environments carry an inherent instability. The sense of control that security teams once had is now an illusion. Weaknesses can appear faster than human processes can react and, once they do, attackers often move before teams have a chance to respond.

Understanding this shift moves the focus from prevention to operational reliability and rapid recovery. As a result, maintaining continuity increasingly depends on automated systems that can respond and recover at machine speed.

Today, resilience is not only about preventing an attack, but also about how quickly systems can be restored and operations resumed, making automated recovery a critical capability.

Yet, nearly 20% of enterprise devices still can’t be reliably protected, updated, or recovered during disruption. That level of exposure is unacceptable in a world where attackers move at machine speed.

Built for failure

A resilient organization is one that assumes that failure is inevitable. In today’s environment of AI-driven attacks and constant disruption, cyber resilience must become a strategic priority rather than a secondary consideration. It can no longer remain just another industry buzzword, but must instead become a strategic imperative.

Organizations relying on manual processes risk being outpaced not just by attacks, but by the complexity of their own systems.

As AI accelerates both the speed and sophistication of threats, resilience must evolve as well, shifting towards intelligent capabilities that can adapt and recover at machine speed.

To prepare for the inevitable, organizations should apply concepts such as antifragility, chaos engineering, and Chaos Monkey testing when planning and testing for system-wide failure, rather than isolated incidents. This means considering scenarios where multiple tools fail, endpoints go offline, or visibility is lost.

Building resilience at a systemic level strengthens overall cyber readiness, enabling organizations to recover quickly and minimise downtime, even during significant disruptions.

Resilience becomes both a defensive strategy and a competitive advantage, moving the focus from preventing every attack to keeping the organization running under pressure.

Recovery is just as critical as prevention. It requires more than technology and demands close collaboration with DevOps and SRE teams to understand what truly keeps the organization running.

Practices such as chaos engineering, pioneered by Netflix, offer valuable inspiration by testing environments against real-world failure scenarios.

By proactively simulating outages and attacks, teams build the muscle memory needed for rapid and effective recovery, a core requirement in an era where attackers move at machine speed.

In the end, resilience is what gives an organization the ability to stay operational during disruption.

The author

Ashley Leonard is SVP of Product Management at Absolute Security.

Africa Asia Asia Pacific Australasia Europe Middle East North America UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleInternational cyber agencies publish guidance for isolating critical infrastructure systems during times of crisis
Next Article Do the Wildberries attacks expand the threatscape for global retailers?

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

July 9, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?