CISOs have quietly become their organizations’ de facto chief resilience officers as the role has evolved from its primary prevention roots to now include greater emphasis on incident response and business resiliency and recovery.
“Any experienced CISO who’s come up through the ranks of IT has that operational mindset, which is about uptime,” says John Bruggeman, consulting CISO to OnX and CBTS. “They’re thinking, ‘How do I make sure that we’re not totally down and unable to perform our functions.’”
With 30 years’ experience across numerous organizations, including a 40,000-employee global firm and a 75-employee $300 million revenue business, Bruggeman has lived the challenges faced by CISOs who shoulder responsibility for cybersecurity, including owning recovery.
According to Bruggeman, CISOs have always had a resiliency mindset, only now it’s being called out by name, underpinning all business operations. The stakes couldn’t be higher for the organization, and individual CISOs.
For example, in the wake of its global outage, CrowdStrike appointed its first chief resilience officer. It was a message to customers, regulators, and investors that the company was intent on strengthening its operations.
But not every organization will go so far as to introduce a new C-suite role dedicated to resiliency. For most, that work increasingly falls to the CISO, and security leaders are responding.
When he’s developing business continuity plans and business impact assessments, Bruggeman goes right to resiliency. The central question for most organizations is: If you’re down, how much money are you going to lose? What’s the impact to your revenue?
As such, Bruggeman firmly believes terms like resilience should be emphasized in boardroom discussions as a way for CISOs to gain buy-in — and funding — for cyber operations.
“If Gartner talks about it, then the CEO is going to talk about it, and then the board is going to talk about it, and then [the CISO] can get funding for what they’ve been talking about. If you have to change the word from ‘backup’ to ‘resilient,’ you’ll do it in a heartbeat.”
Redefining resilience beyond uptime
Traditionally, resilience has been narrowly defined in terms of uptime, but as the CISO mandate has evolved to support business operations, the definition is shifting.
For Aimee Cardwell, consultant and CIO and CISO in residence at Transcend, resilience means more than bringing systems back online after an outage.
As Cardwell sees it, resiliency should be measured as recovering from system downtime and protecting against data theft through tokenization or encryption — but those haven’t always been given equal weighting. Organizations typically focus on being back up and running, but knowing where sensitive data lives and how exposed it is can’t be overlooked, she says.
Organizations in heavily regulated industries such as healthcare and financial services will often prioritize data protection over uptime due to potential regulatory penalties or loss of customer trust. “If you’re a bank, you’d rather be down for a day, or even two days, and not have a data loss than be back up in 40 minutes and have a data loss, because your brand damage suffers,” Cardwell says.
The equation flips for companies that don’t hold especially sensitive data. Amazon, she notes, tokenizes credit card numbers, so a breach would expose only a customer’s name, address, and email — not financial or health information. “It depends on where you are on that spectrum of sensitive data … where your resilience meter is,” she says. “If you’re Amazon, you want to be up fast, because every minute is millions of dollars.”
Cardwell argues CISOs need to set explicit tolerances for data loss — what kind of data and how much of it — they are prepared to risk, not just how quickly systems come back online.
“The exercises to determine their mean time to recovery, … I think having that same conversation for data loss is something that, if a CISO is not already doing that, they need to add that to the conversation,” she says.
The rapid adoption of AI is another stress-test for resilience that is falling to CISOs. It’s amplifying the risk of hidden data exposure, turning a theoretical data‑loss conversation into a live operational problem.
Cardwell describes a healthcare company that had 15 years of patient data breached — not through its primary systems, but through an accounting folder. As a small provider billing larger organizations, it had attached patient names, numbers, and conditions to years of invoices, all sitting unprotected in a location no one thought to secure.
“Why is there so much healthcare data in the accounting folder?” she says. It’s the kind of shadow data problem, she argues, no perimeter defense would have caught.
“It feels like CISOs have been pounding the table, saying, ‘I can’t protect it if I don’t know where it is.’ There’s shadow IT, there’s shadow data, and AI is magnifying that ten times,” Cardwell says. “That’s where much of that resilience problem is; it’s almost impossible in a large enterprise to have an understanding of where all that data is and how people are using it.”
To contain the sprawl, Cardwell says CISOs need to champion role-based access control to protect sensitive data, yet there’s a sizable gap between best practice and real-world standards.
“Every CISO will tell you that role-based access control is the most important thing a company can do, and every CISO will also tell you that they’ve never seen a company that does it well. And when I say well, I mean better than 70%,” she says.
While a chief resilience officer could take ownership of certain functions such as data retention policy, the remit would overlap with roles that already have clear boundaries elsewhere. Audit, privacy, and legal are unambiguous, but resilience collides directly with the CIO, who already owns mean time to recovery, and potentially a chief data officer, too.
“If you’re the CEO, who do you go to for questions around resilience?” she asks. “It gets a little complicated, unless you have clear boundaries.”
Executing the resilience mindset
Resilience starts with defining the minimum viable operations for the organization, according to Bill O’Connell, CommVault CSO. Then it’s a matter of working backwards to decide what to prioritize, what to protect, and rehearsing what to bring back first when things go wrong.
“Define the smallest version of the business that still works, then build your recovery priorities and drills around that,” he tells CSO.
A longtime cybersecurity professional who’s held chief business security officer and global security operations roles, O’Connell says a resilience mindset is an operational one that takes processes “off the page” and into practice.
He knows firsthand that the most difficult part of an incident is almost always where organizations have never rehearsed those steps.
“I’ve had all manner of disruptions happen, where you’re asking: What are the key things, do I know who I need to talk to, do I know where I need to go, and do I know how to get the information? Unless you’re practiced at that, it’s that much more painful,” he says.
He warns against treating business continuity planning and disaster recovery as “a Word document” for auditors. Practicing “who talks to whom, where they go, and how they get information during disruption” is essential.
Instead O’Connell advises developing a “ResOps” approach, where organizations repeatedly test, rehearse, and improve how they recover their most important services. “We have DevOps. We have SecOps. Do we have ResOps? Do we have a process around how we make sure we’re resilient?” he says.
O’Connell also warns against overindexing on defense at the expense of resilience, though he appreciates that this mindset shift can be a difficult for many CISOs to come to grips with.
“When you talk to CISOs, you have to be mindful, because if you say, ‘Worry less about defense,’ they get scared, because that’s their job. But it’s not to say, ‘Do less there’; it’s just to say, ‘You’re not doing enough on recovery, on availability, and the resilience piece and you need to make sure you’re balanced there,’” he says.
For the board, O’Connell frames the conversation in terms of risks, potential impact, and mitigations — an approach that requires standing side by side with business leaders, looking at the problems and opportunities they see, and then explaining how cybersecurity helps support those outcomes, he says.
Advice for CISOs to strengthen the resilience mandate
Drawing on his consulting experience, Bruggeman offers practical advice for security leaders who want to turn resilience into a credible mandate.
“For a CISO, they may not want to take on full responsibility for the resiliency component, but they can partner with GRC and compliance people. They both want the organization to succeed; they just have different tools in their toolkit to implement it and get the funding,” he says.
Executed this way, CISOs articulate cyber and operational risks; GRC/compliance codifies and quantifies those risks; the CFO/COO turns that into funding and organizational mandate.
“It’s not so much that they’re going to say, ‘Here, you can have this problem,’ but to say, ‘Let’s partner together,’ because it’s a shared responsibility,” he says.
Bruggeman is yet to see any one single chief resilience officer because responsibility sits with different portfolios, creating opportunities for CISOs to level up their stature in the C-suite.
“I haven’t run into a single company that has a resiliency officer. The CIO has some responsibility, the CISO has some responsibility, and the COO — who really is a chief and really is an officer — has responsibility,” he says. “I see it more as a partnership than a single role.”