
In this accompanio expert interview, Sebastian Bittig, Director of Cyber Defense at r-tec, explains what causes these issues, how companies should take a holistic view of their security architecture, and why true cyber resilience cannot simply be purchased. Bittig has been working with security architectures for about 15 years and combines strategic consulting with operational experience in managed services and incident response.
Key Takeaways
- High security investments do not automatically translate to high resilience. What matters is not the number of solutions deployed, but how they work together.
- The resilience gap often arises from legacy and fragmented security landscapes. Individual systems and teams function on their own but are not integrated into a unified system.
- Prevention remains the foundation of IT security, but it cannot prevent every attack. What cannot be prevented must be reliably detected and then quickly addressed.
- Detection forms the crucial link between prevention and response. Insights gained from attacks should also feed back into prevention.
- Response is the real-world test of a company’s cyber resilience. It is only during a security incident that it becomes clear whether processes, responsibilities, systems, and people actually function as intended.
- Resilience is not just a technical task. Processes, responsibilities, communication, and collaboration between teams and service providers are equally crucial.
- Resilience can be measured and trained. Metrics such as time to respond and mean time to recover, as well as practical emergency drills, show how quickly a company can respond to an attack and regain operational capability.
- The journey from a tool stack to a comprehensive system takes time. Companies should proceed step by step, integrate existing solutions, and clearly define responsibilities and processes.
Cyber Resilience: Why Security Investments Alone Are Not Enough
Many companies today invest substantial sums in their IT security. Nevertheless, this does not automatically result in a higher level of cyber resilience. The reason: A significant gap can arise between investing in individual security measures and their actual effectiveness.
Sebastian Bittig refers to this gap as the “resilience gap.” It arises in particular when companies have established many security measures but these do not function as a cohesive system.
Whether a company is truly resilient often only becomes apparent when an actual security incident occurs. That’s when it becomes clear whether detection, communication, and response are working—or whether there are gaps between the individual security areas.
The resilience gap often arises from security landscapes that have evolved over time
A typical problem for many companies is a security architecture that has evolved over the years. New solutions are added as new requirements arise or new threats emerge. What is often missing, however, is a holistic view of the entire system.
“Many years ago, companies started with antivirus software. Gradually, additional solutions were added. In many cases, no consideration was given from the outset to how the individual systems interact with one another and what information needs to be exchanged between them.” — Sebastian Bittig, Director of Cyber Defense at r-tec (part of the accompio Group)
This is how security silos arise: Individual solutions may work reliably from a technical standpoint, but they do not automatically pass their findings on to the next link in the security chain.
In an emergency, this can become a major problem. Information must be compiled manually, responsibilities are unclear, or relevant clues are identified too late. Above all, this costs one thing: time.
And time is a critical factor during an ongoing cyberattack.
Prevention, detection, and response must function as an integrated system
Three functioning individual areas do not, by themselves, make for a resilient company.
The key lies in the interplay between prevention, detection, and response. All three areas must exchange information, build on one another, and work together toward a common goal: to prevent a security incident whenever possible, detect it early, contain it quickly, and restore business operations as swiftly as possible.
This requires more than just individual security tools.
The Cyber Resilience Assessment tests precisely these factors. According to Bittig, a functioning security architecture consists of the interplay between technology, processes, and people. The systems in use must communicate with one another, data flows must function properly, and responsibilities must be clearly defined.
Cyber resilience is also an organizational issue
The resilience gap is therefore not exclusively a technical problem. A company’s organizational structure also plays a crucial role.
An investment in a security solution must be accompanied by organizational measures. Processes must be defined, responsibilities established, and accountabilities regularly reviewed.
The situation becomes particularly critical when information or contact persons are no longer up to date. Bittig reports on a ransomware incident in which an attack was detected by the SIEM system in use, but the response nevertheless stalled.
The reason was not a lack of technical detection. Rather, the customer’s primary contact was no longer reachable, the stored contact information was out of date, and there were no adequate on-call arrangements for the weekend.
This example illustrates that a detected security event does not necessarily mean the security incident has been resolved.
Only when detection leads to a defined and rapid response does true resilience emerge.
How can cyber resilience be measured?
Resilience is not an abstract goal; rather, it can be assessed using concrete metrics and exercises.
Relevant metrics include, for example:
- Time to Respond: How quickly does a company respond to a detected security incident?
- Mean Time to Recover: How long does it take to restore the affected systems and processes and regain operational capability?
Both metrics provide important insights into how well the response processes actually work.
However, the focus should not be exclusively on technical metrics. Ultimately, the outcome is what matters: How quickly is an attack detected? How quickly can the company respond? And how quickly is normal operations restored?
Practical Example: When a Detected Attack Becomes a Problem Anyway
A particularly illustrative example from Bittig’s experience is a ransomware incident at a new client.
The company already had a managed service in place and had good audit reports. Technically, the detection system was also working: The SIEM system in use detected the attack, and the responsible service provider notified the client.
Nevertheless, the response initially failed to gain sufficient momentum.
The critical weak point lay in the organization: The designated primary contact was no longer with the company. Furthermore, no one was available over the weekend, and the provider’s on-call procedures were not sufficiently defined.
Technically, the attack had been detected. Nevertheless, the overall system was unable to respond effectively.
Clearly defined processes, up-to-date contact persons, and established authorities would have made all the difference. Especially for certain scenarios, it should be established in advance which measures a service provider is authorized to initiate independently.
This example illustrates the central message of the interview: Security resilience is not determined solely by whether an attack is detected—but by what happens afterward.
What Companies Should Avoid When Building Cyber Resilience
One of the greatest dangers is trying to change too much at once.
Building a functioning comprehensive security system can take months or even years. Companies should therefore not attempt to rebuild their entire security architecture in a short series of workshops.
Instead, a step-by-step approach is recommended:
1. Analyze the maturity level and existing architecture
2. Identify security gaps and inconsistencies between departments
3. Integrate existing tools effectively
4. Define responsibilities and processes
5. Define response scenarios and authorizations
6. Regularly test and further develop the overall system
Step by step, this creates a security model that not only works on paper but also remains effective in an emergency.
Conclusion
The resilience gap arises where individual security measures work but do not form a functioning overall system. True cyber resilience arises from their interaction and cannot simply be bought.
Prevention, detection, and response must therefore not be viewed in isolation. They must interlock, exchange information, and be linked through clear processes and responsibilities.
Technology is not the only factor at play here. People, processes, and technology must work together.
The most important shift in perspective is therefore this: The focus should not be on the question “What security solution do we still need?”, but rather:
“How do we ensure that our entire security system works in an emergency?”
Because that is precisely where true cyber resilience is determined.
FAQ: Frequently Asked Questions About Cyber Resilience
What Does Cyber Resilience Mean?
Cyber resilience describes a company’s ability to prevent cyberattacks and security incidents, detect them early, respond effectively, and then quickly restore operational capability. The key lies in the interplay of prevention, detection, and response.
What does resilience mean in IT?
In IT, resilience describes the ability of systems and organizations to remain functional even in the face of disruptions or attacks, or to recover quickly from them. Cyber resilience is the application of this principle specifically to IT security and cyberattacks.
What is the resilience gap?
The resilience gap refers to the discrepancy between existing security investments and a company’s actual ability to respond effectively in an emergency. It often arises when individual security solutions function properly but are not integrated into a cohesive, holistic system.
Why aren’t security tools alone enough?
Security tools provide important functions for prevention, detection, and response. However, they do not automatically create a functioning overall system. True cyber resilience is achieved only when technology, processes, and people work together, and information and responsibilities are clearly defined.
What roles do prevention, detection, and response play?
Prevention aims to prevent attacks as much as possible. Attacks that cannot be prevented must be detected as quickly as possible. Response then ensures that appropriate measures are taken, attacks are contained, and affected systems are restored. These three areas must be closely integrated.
How can cyber resilience be measured?
Cyber resilience can be assessed using metrics such as time to respond and mean time to recover, among others. In addition, practical emergency and attack simulations are important because they show whether technical measures, processes, and responsibilities actually work in a real-world scenario.
How can companies improve their cyber resilience?
A good place to start is an analysis of the existing security maturity level. Attack simulations can help identify weaknesses in the interplay between prevention, detection, and response. Companies should then integrate existing tools, define responsibilities, and gradually improve processes.
Is cyber resilience just a technical issue?
No. Cyber resilience is a combination of technology, processes, and people. Unclear responsibilities, outdated points of contact, or a lack of on-call procedures can result in a detected attack still not being addressed quickly.
Why is response so important for cyber resilience?
Response demonstrates whether a company is actually capable of taking action in an emergency. An attack can be detected technically—but if no one is available afterward, responsibilities are unclear, or necessary authorizations are lacking, this still results in a significant loss of time and potentially greater damage.
Further Links
👉 www.accompio.com
Photo: unsplash