Welcome to Reimagining Cyber, the Boardroom edition. My name's Ben, and this is a special compilation featuring conversations on resilience, regulation, governance, and executive accountability. Now, throughout the year, so far, we've been gathering perspectives on how leaders think about cyber risk, and in this episode, we're going to weave some of these thoughts together. And explore why cyber resilience is an operational challenge rather than simply a security issue. What organizations are learning from the first year of Dora and why a new metric may be needed to help boards understand the real business impact of cyber incidents. One of the biggest misconceptions organizations still face is treating cyber resilience as simply another cybersecurity initiative. In episode 185, former Gartner Analyst and cybersecurity leader, Theresa Lanowitz, challenged that view directly. Arguing that resilience must be viewed as a business and operational responsibility, as she explained. And I think what we've seen over the past several years is that people tend to conflate this idea of cyber resilience with cybersecurity, because we talk about cyber resilience, it has the word cyber in front of. And people suddenly say, oh, you're talking about cybersecurity. And if you look at recent data, what that is actually saying is, is, is it's exactly true. Most organizations are not seeing cyber resilience as a whole organizational issue. They're saying cyber resilience is something that the cybersecurity team needs to worry about. And if we look at the strictest definition of cyber resilience, what we're saying there is that cyber resilience is about how the whole organization. Coalesces. When there is something that happens to the entire IT estate, how do we make it so that our customers are not impacted by this outage that we might be having or by this breach that we might be having? How do we really minimize that impact and who needs to come together? Now that definition shifts the conversation away from technology and towards organizational response, business continuity and customer outcomes. Ow it's expanded on that point by emphasizing recovery and continuity, cyber resilience, as I said, it's that idea of that whole organization coalescing when something unforeseen. A manmade disaster. A natural disaster. Some type of cyber incident happens to that entire IT estate, and how do you get that IT estate back online and working and operational as quickly as you possibly can without a great impact to your customer base. The key insight then is that resilience can't be owned by security teams alone. It requires leadership, governance, accountability, and alignment across the business. As Theresa put it, that idea of cyber resilience says it has to be a whole organizational issue. It has to be something that the board understands, the C-suite understands. So it is a leadership issue. It has to be funded and really be able to be separated from cybersecurity. So making the entire organization again, understand what cyber resilience is, and governance teams need to understand what cyber resilience is. And a lot of that goes back to a. From A KPI perspective, every leader in an organization should have some KPI associated with cybersecurity and with that cyber resilience. And if you attach those KPIs and you align cybersecurity with the line of business, you're not going to see cybersecurity be an afterthought. And you're also not going to see cyber resilience be an afterthought either. It will be a whole organizational issue. So three themes emerge. First, cyber resilience isn't the same as cybersecurity. Second, resilience is ultimately about maintaining operations. Minimizing customer impact during disruption. And third, resilience requires ownership from the boardroom to the front line, and that brings us to a regulatory moment that is attempting to formalize resilience expectations. In February, we asked the question one year after the Digital Operational Resilience Act or Dora came into force, what has actually changed? Dominic Brown from Graves Light consulting joined us to break things down. So Dora is an EU regulation designed to reduce cyber resilience risk in EU financial services. It emanated out of the rapid digital transformation of financial services during the pandemic. Unfortunately, cyber resilience didn't follow suit, so I think cyber attacks on European financial services more than doubled during the pandemic. It was a good impetus. The scope is really broad. It covers what's called ICT system stands for information communication Technology. That's any system delivering ongoing digital or data services. So I think it's probably harder to find a system that doesn't do that, does do that core to this. The requirement refers to identify their critical or important functions. The acronym is c, f, and the ICT systems that support those Cs. And you know, DORA is sort of, there's two levels of enforcement. One is level one, it's basically the rule. And level two is how to implement the rule. And SIFs is sort of the focus of the level two requirements, and we'll get into that. Dora is based on five pillars, is ICT versus governance. Incident reporting, resilience testing, third party risk management and information sharing. It has a systemic focus and this makes it unique in that it treats ICT risk as a threat to the entire. Financial system, not just to individual firms. What makes DORA significant is that it reframes cyber and technology risk as a resilience issue. Its focus extends beyond individual incidents and considers how disruptions can affect critical business functions and ultimately the financial system itself. But implementation has been challenging. One year into Enforcement. Brown says that many organizations are still working to mature their programs. Yeah. Firms are pretty slow at building out their door frameworks, right? I think it's this incredibly expensive regulation, and I think some of this is due to the fact that the level two we require, as you talked about, weren't published until mid 2025, but things like, you know, governance, maturity, subordinate, senior management. Governance of ICT risk is pretty immature. Firms have not fully identified their critical or important functions. The SIFs Cybersecurity and Resilience controls exist on paper, but in practice, and this is, you know, common from what you see in organizations in some cases generally, but not necessarily relevant to, to dora. And as a result of these difficulties, a lot of firms are asking for longer timelines to complete DORA, complete their DORAimplementations. That is. The regulators thus far have been really patient. No one's been penalized, but my sense is they're gonna expect. Meaningful progress to 2026. That patient may not last forever because the next phase of Dora is likely to focus on evidence testing and accountability. Organizations will increasingly need to demonstrate that resilience controls actually work, and that raises an important question. What happens when organizations fail to take resilience Seriously? Brown's answer was direct. I think if you willfully. Ignore implementing Dora, you're gonna suffer the consequences. Consequences are like one to 2% your annual sales, that's a ton of money, a ton of bad press and it's bad press around things you should be doing anyway, and things your customers care about, which is cyber and operational resilience. You don't wanna put your money in a bank or a private equity firm that is vulnerable and and could potentially lose that money. But I think the common thread and what I've found in compliance. The Federal Rules of Civil Procedure, British Common Law, no matter what it is, including compliance regulations, is firms need to put in a good faith effort proportional to their impact, in this case, the EU financial system, right? And they need to be adults and say, okay, this is what I need to do. This is why I need to do it, and they need to put in that good faith effort. I think if they do that, even if they fall short of implementing DOS letter, they'll be okay. Right. But you can't be blind to it and ignore it. You need to. Respected Dora's first year offers a broader lesson for executives. Resilience is no longer simply a technical objective. It's becoming a governance expectation, and increasingly, boards are being asked to demonstrate not only that risks are understood, but that organizations can continue operating when disruption occurs, which leads directly to our final conversation. If resilience matters, how should boards actually measure it? For years, cybersecurity leaders focused primarily on prevention. The goal was simple, keep attackers out. Then organizations shifted towards detection and response. Recognizing that breaches would inevitably occur in episode 199, containment or catastrophe. Doug Merritt, CEO of Aviatrix and former CEO of Splunk argued that security leaders must fundamentally rethink their approach. According to Doug, cybersecurity is entering a third era. When I think about cybersecurity, uh, prevention was the first wave. I'd call that era one. Prevention doesn't go away. Still an important thing to do, but you better shift a lot of re your resources to detect and remediate. Like you gotta assume the bad guys are in. Well, I think we're entering era three, which is the containment era, which is all about how far can a successful breach breach within your environment and how do you keep it localized? That represents a fundamental change in perspective. The question is no longer whether a breach can be prevented. The question is what happens when prevention fails? Merit uses an analogy that resonates with any board or executive team. He compares cybersecurity to the engineering principles used in critical infrastructure. For any critical system. There's 80 plus years of engineering. Um, both math and practicality. That helps make sure that you don't have catastrophic events in those critical systems. Um, thinking about nuclear reactors, think about airplanes. Think about spacecraft. Think about submarines, right? You're at depth under the ocean. If you have a significant leak in the submarine and it spreads. Then it implodes and everyone dies. That's catastrophic. So how do you not have it be a catastrophic, assuming things will go wrong, right? The whole orientation around critical systems and survivability is you gotta assume failure and then you've gotta build the right systems architecture. So failure. Is not catastrophic. That idea mirrors the essence of resilience. Organizations can't assume perfection. They must design for survivability. As threats evolve, AI accelerates attacker capabilities and digital ecosystems become increasingly interconnected. The ability to contain disruption becomes just as important as the ability to prevent it. And this is why Merit argues that boards need a new metric as he concluded. You have to assume infinite zero days, you're gonna be breached. Like breach is going to approach one for many different organizations and many different areas of this state. So then the question is, so what do we do? Like we can't give up, we still have got our job. The way I do it is you introduce a new metric. You've got the series of prevention metrics from the prevention era, and there's a whole host of those. You've got MTTD, MTTR, and MTTD as the key metrics for the second era. Blast Radius is a third, is the additional metric. That we need to introduce at the board level. So our mediative approach is we're going to, uh, have a blast radius score and have confidence that if something happens. It's only gonna travel so far, it's only gonna affect these different areas of the system. Blast Radius shifts the discussion from security activity to business impact. It asks whether an attacker can move across the enterprise, disrupt operations, impact customers access sensitive information, or materially affect revenue. In other words, it measures organizational survivability. Across all three conversations, a common theme emerges. Cyber resilience is a business discipline. Theresa Lanowitz reminds us that resilience requires the entire organization to come together during disruption. Dominic Brown shows how regulators are increasingly embedding resilience into governance and accountability frameworks, and Doug Merritt argues that resilience must ultimately be measured. By how effectively organizations contain and limit the impact of inevitable failures. Together those perspectives point to a new reality. The future of cyber leadership is not simply about protecting technology, it's about preserving operations. Protecting customers, sustaining trust, and ensuring the organization can continue to function when disruption occurs. Thanks for listening to Re-Imagining Cyber the Boardroom edition. We'll see you next time.