Security Is No Longer Just Defense—It's How The Business Keeps Running
Maman Ibrahim is a cyber and digital risk executive, helping boards, CRO, CIO, and CISO turn risk work into decisions, delivery, and proof.
gettyThe latest penetration test found no critical vulnerabilities, and the dashboards are green. Then a supplier’s API certificate expires overnight, a core system loses its data feed and the business stops for half a day. The CISO spends the morning explaining to the board that this wasn’t technically a security incident. The board isn’t interested in the classification. It wants to know why the business stopped.
That exchange captures a shift many have felt. The question boards ask has changed. It used to be, “Are we protected?” Now it’s, “Will we keep running?” These are different questions.
Defense is one part of continuity, not a substitute for it. In this article, I’ll discuss what changed, what security must now deliver and what leaders must do differently.
Three developments have changed the landscape.
Most businesses run on the same few cloud regions, identity providers and SaaS platforms. When one fails, thousands of organizations stop at once without any attacker involved. Concentration has turned other people’s incidents into your downtime.
One useful check is to list the 10 external services your revenue cannot operate without and ask how many you could replace in a day.
Certificate lifetimes, patch windows, cryptographic retirement dates and regulatory deadlines can all disrupt operations on a fixed schedule if nobody manages them. Unlike an attacker, a deadline arrives exactly when it says it will.
I recommend asking whether anyone holds a single, dated inventory of these expiries. If not, the next outage from this source is only a matter of time.
DORA, NIS2 and the U.K.’s operational resilience regime don’t measure how many attacks you blocked. They measure whether your important business services kept running, how quickly those services recovered and whether you can demonstrate both. The regulator’s scoreboard is the availability of the services that matter, not the volume of alerts closed.
This means that if the failure surface has moved, the job definition has to move with it.
A security function that keeps the business running produces three outputs.
Someone has to own the map: which services must not stop, what each depends on and how long the business can tolerate losing it. That final number is a commercial judgment, owned by the business with security holding the pen. “Good” looks like a short list of named services, each with a tolerance in hours, signed off by the executive who owns the revenue. “Poor” looks like a continuity plan last reviewed before the current cloud estate existed.
This is not a policy document or a signed attestation. It’s evidence that recovery works because it was tested last quarter, that failover works because it was exercised against a real dependency and that access rights match the register. Good evidence is dated, repeatable and reads the same to a board, an auditor and a regulator.
Here’s a practical test you can implement: pick one critical service and ask for the record of its last full restore, including how long it took and whether that was within tolerance. If no record exists, the organization is relying on belief.
In post-incident reviews, look at where the time went. It’s often not spent on the technical fix but on establishing who is allowed to act: who can take a supplier offline, who can halt a deployment or who can accept a residual risk and sign for it. When those answers are not settled in advance, the incident waits. Security’s role now includes providing the authority and information that let the right person decide in minutes, not hours.
None of these outputs come from a control library. They come from how the organization is designed to decide.
Three changes make these outputs possible, and all sit above the security team.
A CISO whose mandate is to prevent incidents will naturally optimize for prevention metrics—and risk being judged a failure when a supplier outage occurs even though no security control was breached. A CISO whose mandate is to keep critical services running will also focus on dependencies, recovery and redundancy. Put that mandate in writing and measure it accordingly: for example, report quarterly on recovery time against the agreed tolerance for each critical service.
The authority to halt, isolate, switch or accept risk should be assigned to named people with clear thresholds before an incident occurs. A one-page decision register is enough: for each decision, identify who can make it, who serves as their deputy, what threshold triggers the decision and who must be informed. The goal is to eliminate the delay that comes from figuring out who is allowed to act while the business is already losing time.
Redundancy, supplier exit plans and rehearsed recovery all cost money, and they can look like discretionary security expenses when they are evaluated only against the security budget. Instead, quantify them against the business cost of downtime. Finance can calculate the revenue, transaction volume or operational cost at risk for each hour a critical service is unavailable. That figure should form the basis of the investment case for resilience.
Returning to the opening example, let’s say the same supplier fails differently a year later, and the business does not stop. Nothing about its defenses has changed. What has changed is that someone decided, in advance, which data feeds mattered, what to switch to when one failed and who could give the order.
Defense has not gone away, but it’s no longer sufficient on its own. Organizations should treat security as the discipline that keeps the business running, with prevention as one of its tools rather than its purpose.
Before your next board meeting, answer two questions: which of our services would stop tomorrow if a single supplier failed, and who is authorized to keep it running?
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

