Question
Why is the attack surface of modern organisations growing, making a security breach a question of "when" rather than "if"?
Answer
Digitalisation, hyper-connectivity, new technologies, complex supply chains and a shortage of skilled staff all keep expanding what attackers can reach.
Several converging drivers keep expanding the attack surface. Digitalisation and connectivity: almost everything is now digital and networked — people, machines and products — so there is far more to attack. New technologies (e.g. AI, cloud, IoT) boost efficiency but also raise susceptibility to cyberattacks. Supply chains are global and complex, giving attackers many indirect entry points into otherwise well-defended organisations. Skills shortage: forecasts suggest Switzerland alone will lack tens of thousands of IT specialists by 2030. Lack of visibility: "I can't protect what I can't see" — you cannot defend assets you don't even know you have.
Tip: The takeaway phrase is "a breach is a question of the when, not the if" — so the goal of security shifts from pure prevention to fast, competent response.
Note saved — thanks!
Question
What is cyber resilience, and why does it require good security incident management?
Answer
Cyber resilience is an organisation's ability to prepare for, withstand and quickly recover from cyberattacks so critical business operations continue despite adverse events.
Because a breach is assumed to be inevitable, resilience — not perfect prevention — becomes the strategic goal. Resilience needs both proactive measures (taken in advance to prevent incidents, or at least to detect them quickly if prevention fails) and reactive measures (taken after an incident to respond appropriately to detected events). Effective incident management processes are how an organisation actually delivers the "withstand and recover" part. Put bluntly: good incident management can be just as important to a company's security as everything else combined.
Go deeper:
Cyber resilience (Wikipedia) — resilience as continuing to deliver the intended outcome despite attacks, and how it relates to cyber security and critical infrastructure.
Note saved — thanks!