Bottom line: Organizations must redefine resilience: not only uptime, but also data protection and acceptable data loss tolerances are equally important components of business continuity.
CISOs are increasingly taking on responsibility for business resilience and recovery – a development that industry analysts such as Gartner are now actively addressing, thereby also shaping board-level discussions.
CISOs have long outgrown their original role of pure prevention. John Bruggeman, Consulting CISO at OnX and CBTS, summarizes the mindset shift: experienced CISOs with IT backgrounds think operationally in terms of availability – “How do I ensure we don’t go completely down?” With 30 years of experience in organizations of widely varying sizes (from 75 to 40,000 employees), Bruggeman knows both extremes. Resilience has always been a topic for CISOs, only now it is being explicitly named and placed at the center of attention.
The reason for this attention is real: following the global CrowdStrike outage in summer 2024, the company created the position of Chief Resilience Officer – a clear signal to customers, regulators, and investors. Not every organization will follow this example; for most, this mandate falls to the CISO. Bruggeman argues that terms like “resilience” should be strategically placed in board discussions to secure budgets. “When Gartner talks about it, so do the CEO and board – and then funding follows.” Reframing from “backup” to “resilient” pays off.
Aimee Cardwell, Consultant and CIO/CISO in Residence at Transcend, however warns against too narrow a definition. Resilience does not only mean restoring availability, but also protecting against data loss through tokenization or encryption. So far, these aspects have been weighted unequally: organizations have focused on rapid restoration to service, but often neglected the question of where sensitive data resides and how exposed it is.
The balance shifts with business type. Heavily regulated sectors such as financial services and healthcare prioritize data protection over uptime – data loss damages the brand more sustainably than two days of downtime. Organizations without particularly sensitive data (such as Amazon with tokenized credit cards) can afford to prioritize uptime: every minute of downtime costs millions. Cardwell argues that CISOs must define explicit tolerances for data loss – not only for recovery time, but also for acceptable data loss scenarios in quantity and type.
Source: www.csoonline.com · Published July 27, 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 of the EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.