Cyber resilience means being ready to recover, not expecting a perfect defence.
At Security Edge, Greg Rattray, former Global CISO at JPMorgan Chase, joined Matt Boon, Senior Research Director at ADAPT, to show why mission-focused capability, business alignment, and repeated recovery practice matter as AI accelerates both attacks and defensive change.
Key takeaways:
- AI-enabled vulnerability discovery only creates value when teams can triage findings and remediate the highest-risk attack paths quickly.
- Security leaders must connect their teams to business priorities and practise disruption scenarios with technology, communications and executive stakeholders.
- Resilience is measured by an organisation’s ability to recover critical services, not by the assumption that every attack can be prevented.
Security capability must be connected to the mission
Greg says the most effective security teams understand what the business produces, how it makes money and how technology enables it.
His military background shaped a mission-focused approach at JPMorgan Chase, where people, processes and technology were organised around reducing risk against real adversaries and tested through exercises.
For Greg, buying tools is not the same as creating capability.
The measure is whether teams can deliver an effective cyber defence process and whether the technology and business teams can see the value of that output.
AI is turning vulnerability management into vulnerability operations
The speed of AI-enabled attacks means vulnerabilities must be discovered, triaged and remediated in days rather than weeks or months.
Greg identifies triage as the highest-leverage step: organisations need to direct finite remediation capacity towards the vulnerabilities and attack chains that create the greatest risk.
That requires choosing models and harnesses carefully, building the technical capability to use them cost-effectively, and ensuring the technology stack can act on what discovery tools find.
The shift is as much about people and process as it is about code.
Resilience is an enterprise responsibility
Greg’s experience at JPMorgan Chase showed that recovery is not solely a CISO responsibility.
Boards and executives need to understand which digital disruptions would have the greatest operational impact, how quickly critical services can return and whether attackers can reach backup data.
Communication is part of that resilience.
During the JPMorgan breach, internal stakeholders, regulators, customers and the media all needed disciplined, timely information.
Greg’s experience in Ukraine reinforced the same lesson: organisations that understand their technology deeply and can adapt rapidly are better positioned to maintain essential functions under pressure.
Greg’s challenge to security leaders is to get off the mat before the fight begins: identify the most consequential disruption scenarios, practise recovery with technology and business partners, and use what the exercises reveal to build genuine resilience.