Cyber resilience means being ready to recover, not expecting a perfect defence.

At Security Edge, Greg Rattray, former Global CISO at JPMorgan Chase, joined Matt Boon, Senior Research Director at ADAPT, to show why mission-focused capability, business alignment, and repeated recovery practice matter as AI accelerates both attacks and defensive change.

 

Key takeaways:

  • AI-enabled vulnerability discovery only creates value when teams can triage findings and remediate the highest-risk attack paths quickly.
  • Security leaders must connect their teams to business priorities and practise disruption scenarios with technology, communications and executive stakeholders.
  • Resilience is measured by an organisation’s ability to recover critical services, not by the assumption that every attack can be prevented.

Security capability must be connected to the mission

Greg says the most effective security teams understand what the business produces, how it makes money and how technology enables it.

His military background shaped a mission-focused approach at JPMorgan Chase, where people, processes and technology were organised around reducing risk against real adversaries and tested through exercises.

For Greg, buying tools is not the same as creating capability.

The measure is whether teams can deliver an effective cyber defence process and whether the technology and business teams can see the value of that output.

AI is turning vulnerability management into vulnerability operations

The speed of AI-enabled attacks means vulnerabilities must be discovered, triaged and remediated in days rather than weeks or months.

Greg identifies triage as the highest-leverage step: organisations need to direct finite remediation capacity towards the vulnerabilities and attack chains that create the greatest risk.

That requires choosing models and harnesses carefully, building the technical capability to use them cost-effectively, and ensuring the technology stack can act on what discovery tools find.

The shift is as much about people and process as it is about code.

Resilience is an enterprise responsibility

Greg’s experience at JPMorgan Chase showed that recovery is not solely a CISO responsibility.

Boards and executives need to understand which digital disruptions would have the greatest operational impact, how quickly critical services can return and whether attackers can reach backup data.

Communication is part of that resilience.

During the JPMorgan breach, internal stakeholders, regulators, customers and the media all needed disciplined, timely information.

Greg’s experience in Ukraine reinforced the same lesson: organisations that understand their technology deeply and can adapt rapidly are better positioned to maintain essential functions under pressure.

Greg’s challenge to security leaders is to get off the mat before the fight begins: identify the most consequential disruption scenarios, practise recovery with technology and business partners, and use what the exercises reveal to build genuine resilience.

Contributors
Greg Rattray Former Global CISO at JP Morgan Chase
Greg Rattray is Partner and Co-Founder of Next Peak LLC, a cybersecurity and risk management firm. He is also currently the Executive... More

Greg Rattray is Partner and Co-Founder of Next Peak LLC, a cybersecurity and risk management firm. He is also currently the Executive Director of the Cyber Defense Assistance Collaborative (CDAC), as well as the Chief Strategy and Risk Officer for Andesite. Dr. Rattray works closely with Andesite’s senior management team and Board to shape corporate objectives, guide product evolution, and drive go-to-market strategy. In addition, he is a senior advisor to the Red Cell Partners Cyber practice, supporting the evaluation of cyber start-ups for potential investments and providing strategic guidance on growth and management initiatives.

Dr. Rattray previously served as the Global Chief Information Security Officer (CISO) at JPMorgan Chase and established their cyber defense strategy and program. As head of Global Cyber Partnerships, he led key industry initiatives including the establishment of the Financial Systemic Analysis and Resiliency Center (FSARC) and the Financial Cybersecurity Profile. Prior to JPMC, Dr. Rattray was founding partner and CEO of Delta Risk LLC, a cybersecurity risk management. He served as the ICANN Chief Internet Security Advisor from 2007-2010. He has also served as Director for Cybersecurity in the White House, commanded the Operations Group of the Air Force Information Warfare Center, pioneered the Department of Defense (DoD) and US national cybe

Less
Matt Boon Senior Research Director at ADAPT
Matt Boon is the Senior Director for Strategic Research at ADAPT, responsible for directing and developing research content and positions. For over... More

Matt Boon is the Senior Director for Strategic Research at ADAPT, responsible for directing and developing research content and positions.

For over 30 years, Matt has worked in research and advisory, including senior leadership roles at Gartner as Principal Analyst, Research Director, and Managing Vice President, where his 18 year history included working with Dell, Microsoft, and many others.

Throughout his career, Matt has been a sought after and highly respected authority on the local and global IT landscape.​ He interacts with executives daily, bringing together groups of C-suite leaders to discuss and prepare for the challenges and opportunities they face.​

At ADAPT, Matt hosts numerous industry-leading business and technology events which Matt chairs, including the yearly Security Edge conference, delivering unique market trends and white-papers, advising executives across the technology provider landscape to make informed IT decisions.​

When he is not working, Matt enjoys walking the many trails of the NSW Southern Highlands, travelling and listening to music. He is also partial to a good steak and nice glass of red wine.

Less
security leadership management