By Tarquin Folliss OBE
We are living in a time of rapid technological change, where cybersecurity is no longer just about building strong defences but about developing organizational resilience. The concept of ‘secure’ is evolving as the threat landscape shifts, forcing organizations to adapt and innovate. In 2024, cybersecurity is no longer defined by the ability to prevent attacks but to respond, recover, and adapt to adversity.
The last five years have been turbulent for the cybersecurity sector. The COVID-19 pandemic forced a massive shift to remote working, expanding the attack surface as millions of workers transitioned from secure office networks to potentially vulnerable home setups. This shift brought new challenges, making it harder for IT teams to maintain control over network security and pushing organizations to rethink their strategies. The pandemic accelerated digital transformation which exposed new vulnerabilities that cybercriminals have been quick to exploit.
In 2024 the cybersecurity landscape has continued to evolve, shaped by several factors: emerging technology, particularly the rapid proliferation of AI-driven threats, increasing geopolitical tensions, and a persistent shortage of skilled cybersecurity professionals. Resilience has become the buzzword to meet these challenges, but what does resilience mean for cybersecurity specifically? How can organizations prepare themselves to manage adversity and change?
The evolving face of cyber threats
As mentioned above, the pandemic caused a shift to remote working that could only have been accomplished with technology. It brought into sharp relief the extent to which organizations are reliant on IT. IT is no longer a function within businesses but the critical component and defending it has become paramount. The scourge of ransomware and the rise of online fraud remind us of the consequences should we fail to do so. In the post-pandemic world we face new challenges which require us to become even more resilient.
One of the most significant developments over the last 18 months has been the emergence of artificial intelligence (AI) in the public consciousness and its potential impact on cyber threats.
AI is becoming something of a double-edged sword in cybersecurity. it offers the tantalising potential to manage the increasing burden of information swamping cybersecurity teams, enhancing defences through predictive analytics, automated threat detection and advanced incident response. Cybercriminals have been quick to leverage AI’s potential too, to launch more sophisticated attacks that can evade traditional security measures. AI-enabled malware that can identify vulnerabilities and exploit them at speed, better targeted phishing campaigns, and deepfake technology are just a few examples of how cyber threats are becoming more complex and harder to detect.
To mitigate these emerging threats, organizations need to develop resilience strategies enabling them to adapt and respond quickly to a cyber event. Organizations must invest in AI-driven security capabilities and other technologies to keep pace with the evolving threat landscape but will also have to devote resources in time and effort to prepare themselves and their people to identify those threats and respond effectively when an event occurs. A proactive approach to threat intelligence, continuous monitoring, and rapid response capabilities are effective tools in the armoury but resilience is first and foremost about people: fostering a culture of learning and adaptation, where an organization’s workforce as well as its cybersecurity teams are constantly updating their knowledge and skills to stay ahead of adversaries.
Geopolitical threats and cybersecurity
Geopolitical tensions are also reshaping the current cybersecurity landscape. Offensive cyber has always been a tool of statecraft, with nation-states using cyber operations to achieve strategic objectives. Cyberspace’s inbuilt ambiguities make it the perfect grey zone between open conflict and peace as adversaries have been quick to recognise. They have exploited it to mount aggressive influence operations and to disrupt critical infrastructure as well as doubling down on traditional espionage and intellectual property theft. Cyberspace is now firmly a domain of warfare where the risk of miscalculation and escalation is ever present.
In this context, the threat landscape has become more complex and resilience goes beyond technical defences. For governments, it requires a comprehensive strategy that includes diplomacy, defence, security, and legislation. The public and private sectors must work together to develop frameworks for cyber resilience that address the complexities of geopolitically motivated attacks. This may involve strengthening international cooperation, establishing norms of behaviour in cyberspace, and building alliances to deter malicious actors.
For organizations, resilience in the face of geopolitical cyber threats means ensuring that contingency plans are in place with which they are familiar and have practiced. This includes conducting regular risk assessments, investing in appropriate cyber insurance, and building redundancy into critical systems. It also means staying informed about the geopolitical landscape and understanding how it could impact their cybersecurity posture.
The ongoing ‘people’ crisis in cybersecurity
One of the most pressing challenges is the persistent shortage of skilled cybersecurity professionals. This is not a new problem, but it has been exacerbated by the increasing complexity of the threat landscape. The demand for cybersecurity talent continues to outstrip supply, leaving organizations vulnerable to attacks due to understaffed and overworked security teams.
Resilience in this context means rethinking how organizations approach talent management in cybersecurity. This involves investing in training and development programs to upskill existing employees, creating pathways for new talent to enter the field and crucially developing career pathways to retain that talent. Organizations must also embrace diversity and inclusion, recognising that a diverse workforce brings a broader range of perspectives and problem-solving approaches.
Resilient organizations will leverage technology to augment human skills. Automation, AI, and machine learning will help alleviate some of the burdens on cybersecurity teams by handling routine tasks and enabling faster decision-making. However, technology alone is only part of solution. Resilient organizations focus on building a strong culture, led from the top, which empowers employees at all levels to take ownership of security and encourages communication across the whole enterprise.
Building a resilient cybersecurity future
If, in 2024, resilience is the cornerstone of cybersecurity, then culture is the foundation. It is about more than just surviving in the face of adversity; it is about thriving in the face of challenges. Organizations that prioritise and invest time and resources in resilience are better equipped to navigate a shifting threat landscape, respond quickly to incidents, and emerge stronger on the other side.
To build resilience, it is incumbent on the leadership of the organization to set the tone by promoting the right business culture and leading from the front. From this, a comprehensive approach to cybersecurity is achieved, integrating security into every aspect of the business, from the boardroom to the frontline. This requires hard work and continuous investment in the cyber trinity of technology, processes, and people, as well as a commitment to innovation and adaptability.
Resilience demands a mindset shift. Instead of viewing cybersecurity as a defensive measure, organizations should see it as an enabler of growth and innovation. By building resilient systems, processes, and teams, organizations can take calculated risks, explore new opportunities, and manage change.
Conclusion
Resilience defines our approach to cybersecurity in 2024. Agile and adaptable organizations are better equipped to face the challenges posed by AI-driven threats, geopolitical tensions, and talent shortages. Developing a culture that focuses on business resilience, they can not only withstand adversity but also thrive in an increasingly complex and interconnected world. The future of our prosperity depends on it.
The author
Tarquin Folliss OBE is Vice Chairman of SASIG Events, the networking and thought-leadership cybersecurity forum. He is also an International Cyber Expo Advisory Council Member.






