Beyond Awareness: Why Cybersecurity Awareness Month Also Means Resilience

Источник: Everpure Blog

Beyond Awareness: Why Cybersecurity Awareness Month Also Means Resilience

Source: Everpure Blog

Beyond Awareness: Why Cybersecurity Awareness Month Also Means Resilience by Everpure Blog A Cybersecurity Awareness Month perspective from Rick Orloff, Chief Information Security Officer at Everpure. The post Beyond Awareness: Why Cybersecurity Awareness Month Also Means Resilience appeared…

•Updated: October 1, 2026

During Cybersecurity Awareness Month, the question is always asked: “Are organizations paying enough attention to the risks in front of them?” For most of the last two decades, that meant phishing, weak passwords, and patch hygiene.

In 2026, that’s still certainly true. However, it’s also no longer sufficient. Awareness now has to include whether you can actually recover, quickly and reliably. No organization can survive extended downtime—weeks or even days of it. Recent estimates put the average cost of downtime at $15,000 per minute. Worse, the damage isn’t just financial: Customers, investors, and employees lose trust fast, and it doesn’t come back easily.

The barriers to attack have been weakened

At Black Hat USA 2026, one reality was impossible to ignore: The barriers to attacking a company have fundamentally changed. I watched exploitation driven entirely by small, cheap, open source models that, until recently, required top-tier commercial systems. What used to be hours of work now takes only minutes.

The numbers back this up: Average breakout time has shrunk to roughly 29 minutes, 65% faster than 2024, as attackers automate reconnaissance and lateral movement at machine speed. 53% of security leaders now name AI-powered attacks their top challenge, and a single team using the Mythos model found 2,000+ zero-days in seven weeks, erasing the lead time defenders count on for patching. Ransomware damage is projected to hit $74 billion in 2026. This is a board-level operations crisis, not an IT problem.

Two AI threats, one target: Your data

We’re facing AI risk from two directions that both converge on your data: malicious AI, human adversaries using AI as an active operator, and rogue AI, systems and agents that act destructively on their own through error or lost guardrails.

This isn’t theoretical: An OpenAI test model escaped its sandbox and pivoted into Hugging Face’s production environment with virtually no human direction, and AI coding agents have wiped out production databases during routine tasks. If the good guys’ AI is breaking guardrails, imagine what ransomware gangs are building toward.

There’s a quieter risk too: Every AI agent and workflow is now a distinct identity with credentials and access. Machine identities already outnumber human ones by roughly 109 to 1, per Palo Alto Networks’ 2026Identity Security Landscape report, and that ratio keeps climbing as agentic AI adoption accelerates. Most identity programs still treat these credentials like leftover service accounts: no clear owner, no expiration, no one watching what they touch, even though nearly half carry sensitive or privileged access.

When one of these is compromised, or an agent simply misfires, you’re not dealing with a phishing-style breach you can contain at the endpoint. You’re dealing with a credential that already has legitimate access to your data, acting at machine speed, with no human in the loop to catch it. That’s exactly the kind of incident resilience has to plan for, not just security.

Why this is a resilience issue, not just a security one

You can’t out-patch a machine that writes a working exploit in minutes. Prevention still matters, but resilience is what happens after AI creates unintended business impact.

Cyber resilience isn’t a SKU you bolt on after the fact; it’s an architectural decision. A backup gives you a recoverable copy of data; cyber recovery answers the harder question of restoring services in order without reigniting the attack.

Every organization needs to map its minimum viable business: what’s required to stay solvent, what comes back first, and how long that takes. Untested, that’s a hypothesis, not a plan.

We’ve seen what good resilience looks like. Earlier this year, a threat actor used stolen credentials to wipe production systems across three data centers at a Fortune 100 company—no malware involved. The storage admin was on PTO, and the password vaults were locked. Because untouched, tamper-resistant snapshots were in place, a non-expert engineer recovered the environment in 20 minutes; core apps and revenue were back within 72 hours. Sites without indelible snapshots took days.

Awareness ≠ resilience, but it’s the starting point

Traditional defenses focus on the network, endpoint, and application layers, but when attackers bypass those perimeters, your data is exposed. Storage has to be the last line of defense, an active defender built on three outcomes:

  • Built-in security: Protection built into how the platform is deployed, minimizing the risk that disruption happens at all
  • Connected detection: Storage that feeds and receives threat context across the security stack
  • Dynamic response and recovery: Automated recovery in minutes, even when every layer above storage fails

All of them are underpinned by data intelligence—knowing what to protect and where to prioritize recovery.

What I’m asking of every security leader this October

Black Hat 2026 made it clear: The economics of cyber offense have changed, and AI has made the attacker’s learning curve easy to climb. That makes resilience more important, not less:

  • Govern every identity, human and machine. This is core to access control, not a hygiene task.
  • Know which data and systems your business cannot operate without—before an attacker forces you to learn it live.
  • Harden the storage layer and connect it directly to SecOps, so recovery moves from days to minutes when prevention fails.
  • Reduce the tools you own but don’t use, and integrate the ones you keep.
  • Put a rigorous recovery test on the calendar, and fix the gaps against your business continuity plan before an adversary does.

Over the coming weeks, we’ll build on this idea with a series of blogs, a tech talk on the business dynamics of cyber resilience, and the announcement of new capabilities built to help you improve security and recover faster. Awareness was the first step. Resilience is what comes next, and the organizations that understand how fast they can recover will be the ones still standing when the next AI-accelerated incident hits.

What this article says

Something is unclear? Ask about the article — I will explain in plain words.

Do not want to dig deeper? We will sort it out for you.