

Cyber Resilience Depends on Getting the Fundamentals Right
Cyber resilience fundamentals are becoming more important as attackers find and exploit weaknesses faster. Organisations across Australia and New Zealand face more convincing phishing attacks, vishing techniques, and growing use of AI by threat actors.
Open and closed source evidence suggests certain threat actor groups are using their own access to AI models. They can use these models to identify exploitable vulnerabilities faster. AI can also help them operate at a scale that previously required significantly more human resources.
For security leaders, that speed creates pressure to invest in new technology. However, decades of incident response experience suggest another security tool is not always the answer. Often, resilience depends on getting existing cybersecurity controls to work properly.
Cyber Resilience Fundamentals Often Fail in Practice
After more than 9,000 incident investigations, LevelBlue’s responders have repeatedly seen similar weaknesses during cyber incidents.
Organisations may deploy multi-factor authentication (MFA), but attackers can bypass it through phishing or social engineering. Endpoint detection and response (EDR) may also be in place. However, incomplete coverage, alert fatigue, or weak triage can undermine its effectiveness.
Other recurring problems include missing critical logs, slow patching, and incomplete asset inventories. Organisations may also have incident response plans that teams rarely review or test.
Devon Ackerman, Global Head of Digital Forensics and Incident Response (DFIR), LevelBlue, said, “After leading and overseeing thousands of cyber investigations worldwide, LevelBlue has seen firsthand which defences actually stop attackers and which ones routinely fail. The hard-earned lesson is that resilience doesn’t come from having the longest list of security technologies. It comes from making sure the fundamentals work when an organisation is under attack.”
Compliance Does Not Automatically Deliver Cyber Resilience
Compliance and cyber resilience are not necessarily the same thing.
Frameworks provide an important foundation for governance and assurance. However, meeting a requirement does not automatically mean a security control will work effectively during an intrusion.
Implementation often makes the difference.
For example, having MFA is different from consistently enforcing phishing-resistant MFA. Organisations need that protection across remote access, administrative accounts, and other important access paths.
Similarly, having EDR does not provide complete visibility if agents do not cover the full environment. The technology also loses value if teams fail to investigate alerts effectively.
Devon Ackerman said, “Security leaders need to move the conversation from ‘do we have this control?’ to ‘does this control actually work?’ This means looking at how consistently controls are deployed, whether teams can see when something goes wrong, and what happens when those defences are put under pressure. A control that exists on paper yet isn’t properly implemented can create a false sense of confidence.”
Shadow AI Adds to the Visibility Problem
Visibility becomes harder as organisations manage increasingly complex technology environments. These can span endpoints, cloud services, operational technology, and other infrastructure.
Unsanctioned AI tools, also known as shadow AI, add another challenge. Browser extensions and autonomous agents can also access company data without necessarily appearing in traditional asset inventories.
That lack of visibility can affect the wider security program.
If an organisation does not know what assets exist, teams may struggle to identify what needs patching. They may also find it harder to restrict access or determine what an attacker affected during an incident.
AI Raises the Cost of Weak Cyber Resilience Fundamentals
AI makes addressing these gaps more urgent. It does not make established cybersecurity practices obsolete.
As attackers use AI to work faster, organisations may have less time to respond to exposed vulnerabilities and other weaknesses.
Devon Ackerman said, “There is understandably significant attention on how AI will change cybersecurity; however, it doesn’t remove the need to get the fundamentals right. In many ways, it raises the cost of getting them wrong. When attackers can identify opportunities and act faster, organisations have less room for incomplete visibility, slow remediation, or poorly enforced access controls.”
Incident Response Plans Need Regular Testing
Organisations also need to prepare for situations where preventive controls fail.
Incident response planning can become a compliance exercise when plans become outdated or overly technical. The same problem arises when organisations never rehearse them.
During a real incident, uncertainty about responsibilities, approvals, and communications can waste valuable time.
Realistic exercises can expose those gaps before a genuine crisis. Organisations that have practised their response tend to respond faster and more cohesively. Teams can spend less time waiting for access or decisions and more time containing the intrusion.
Backups Must Work When Organisations Need Them
The same approach applies to recovery.
Backups can provide an important last line of defence, particularly during ransomware incidents. However, simply having backups is not enough.
Organisations need to know whether they have isolated their backups appropriately. They also need to confirm that teams can restore them and meet the recovery timeframe the business requires.
Devon Ackerman said, “Cyber resilience is built before an incident happens. Organisations need to understand where their weaknesses are, focus their resources on the areas that can make the greatest difference, and regularly test whether their defences and response processes work in practice.
“Cybersecurity will continue to evolve, particularly as AI changes the speed and scale of threats. The fundamentals, however, remain fundamental. Getting them right gives organisations a stronger foundation to detect, contain, respond, and recover.”
