The world of cyber is pivoting
The world of cyber is pivoting
Why cyber resilience must move at the speed of business
Time has become a defining factor in cybersecurity. Organisations can launch services, connect partners and deploy AI capabilities faster than ever. The same technologies can help attackers find weaknesses, tailor social engineering and move through digital environments at pace.
The purpose of cybersecurity remains clear: protect people, data, systems and critical operations. What must change is the way organisations deliver that protection. Cyber teams need to participate in business decisions from the outset, understand where exposure is changing and act quickly enough to support growth.
That is a different role from reviewing a technology initiative just before launch. By then, choices about data, access, suppliers and system design may already be difficult to change. Bringing cyber expertise into the early stages of transformation allows organisations to pursue innovation with a clearer understanding of its risks.
AI changes the attack surface and the clock
Cloud services connected ecosystems and AI have made new capabilities easier to deploy. They have also increased the number of human and machine identities with access to applications and sensitive data. Service accounts, interfaces, suppliers and autonomous agents may each become a route through which an organisation is exposed.
AI adds another dimension: speed. It can assist attackers with research, targeting and convincing social engineering. Defenders can use it to analyse alerts, prioritise exposure and accelerate well-understood response actions. Both sides can move faster, making the time between identifying a weakness and acting on it more consequential.
This calls for a cyber operating model that works continuously. Automation can help detect and contain threats when the evidence is strong and delay would increase harm. People must remain accountable for decisions that affect safety, critical services or significant business outcomes. The aim is to combine machine-speed analysis with human judgment and context.
Measure exposure, not just activity
Many cyber programmes report the number of vulnerabilities found, alerts reviewed, patches applied or policies published. These measures describe work completed, but they do not necessarily show whether the organisation could withstand a serious disruption.
Leaders need a sharper view of exposure. Which vulnerabilities are likely to be exploited? Which identities have more access than they need? Where does reliance on a third party create a concentration risk? How quickly could the organisation detect an incident, contain it, recover and explain what happened?
Answering those questions requires regular testing and evidence that controls work in practice. In BDO’s view, this means connecting Active Insights, Active Protect and Active Assure: understanding what matters and where exposure is changing; protecting the organisation through responsive operations; and continually testing whether controls and recovery plans deliver the intended outcomes.
It also means moving from periodic assessment towards continuous exposure management. Cyber teams can then direct attention to the assets, identities, data and services where an incident would have the greatest effect.
Identity and data are central to resilience
As AI agents interact with applications and data, organisations need to know who and what has access. A reliable inventory of human and machine identities, clear data ownership and disciplined authorisation are essential.
The questions are practical: What data does the organisation hold? How sensitive is it? Which people, services and agents can reach it? Is that access still necessary? Would a change in behaviour be detected?
These are also questions of trust. Boards, customers, employees and regulators increasingly expect organisations to demonstrate that digital services are secure, supervised and resilient. Trust depends on evidence of how systems operate, how decisions are governed and how the organisation responds when something goes wrong.
Turn the shift into action
Leaders can begin with five priorities:
Cybersecurity has become a business capability for confident growth. Its operating model must keep pace with the organisation it protects.
Time has become a defining factor in cybersecurity. Organisations can launch services, connect partners and deploy AI capabilities faster than ever. The same technologies can help attackers find weaknesses, tailor social engineering and move through digital environments at pace.
The purpose of cybersecurity remains clear: protect people, data, systems and critical operations. What must change is the way organisations deliver that protection. Cyber teams need to participate in business decisions from the outset, understand where exposure is changing and act quickly enough to support growth.
That is a different role from reviewing a technology initiative just before launch. By then, choices about data, access, suppliers and system design may already be difficult to change. Bringing cyber expertise into the early stages of transformation allows organisations to pursue innovation with a clearer understanding of its risks.
AI changes the attack surface and the clock
Cloud services connected ecosystems and AI have made new capabilities easier to deploy. They have also increased the number of human and machine identities with access to applications and sensitive data. Service accounts, interfaces, suppliers and autonomous agents may each become a route through which an organisation is exposed.
AI adds another dimension: speed. It can assist attackers with research, targeting and convincing social engineering. Defenders can use it to analyse alerts, prioritise exposure and accelerate well-understood response actions. Both sides can move faster, making the time between identifying a weakness and acting on it more consequential.
This calls for a cyber operating model that works continuously. Automation can help detect and contain threats when the evidence is strong and delay would increase harm. People must remain accountable for decisions that affect safety, critical services or significant business outcomes. The aim is to combine machine-speed analysis with human judgment and context.
Measure exposure, not just activity
Many cyber programmes report the number of vulnerabilities found, alerts reviewed, patches applied or policies published. These measures describe work completed, but they do not necessarily show whether the organisation could withstand a serious disruption.
Leaders need a sharper view of exposure. Which vulnerabilities are likely to be exploited? Which identities have more access than they need? Where does reliance on a third party create a concentration risk? How quickly could the organisation detect an incident, contain it, recover and explain what happened?
Answering those questions requires regular testing and evidence that controls work in practice. In BDO’s view, this means connecting Active Insights, Active Protect and Active Assure: understanding what matters and where exposure is changing; protecting the organisation through responsive operations; and continually testing whether controls and recovery plans deliver the intended outcomes.
It also means moving from periodic assessment towards continuous exposure management. Cyber teams can then direct attention to the assets, identities, data and services where an incident would have the greatest effect.
Identity and data are central to resilience
As AI agents interact with applications and data, organisations need to know who and what has access. A reliable inventory of human and machine identities, clear data ownership and disciplined authorisation are essential.
The questions are practical: What data does the organisation hold? How sensitive is it? Which people, services and agents can reach it? Is that access still necessary? Would a change in behaviour be detected?
These are also questions of trust. Boards, customers, employees and regulators increasingly expect organisations to demonstrate that digital services are secure, supervised and resilient. Trust depends on evidence of how systems operate, how decisions are governed and how the organisation responds when something goes wrong.
Turn the shift into action
Leaders can begin with five priorities:
- Focus on what matters most. Identify the business services, sensitive data, identities, AI use cases and third parties whose compromise would have the greatest consequences.
- Modernise cyber operations. Replace slow hand-offs and isolated reviews with clearer visibility into exposure, faster investigation and response actions supported by evidence.
- Govern consequential decisions. Assign ownership and decision rights for AI, automation and data access. Set clear boundaries for automated action and retain human oversight where the impact is material.
- Prove resilience. Give executives and boards a view of what is exposed, what is changing, how quickly the organisation can respond and whether controls perform as intended. It is not a matter of if but more likely when an attempt will be made and it is vital to be able to respond and recover.
- Practise under pressure. Test scenarios involving disrupted services, compromised AI systems and third-party failure. Rehearse containment, recovery and communication before a crisis occurs.
Cybersecurity has become a business capability for confident growth. Its operating model must keep pace with the organisation it protects.