CISOs Emerge as Key Players in Business Resilience Strategy

David Brooks
7 Min Read

The finance guy in me sees the world in balance sheets and risk-adjusted returns. You protect assets, you mitigate liabilities. For most of my career, the Chief Information Security Officer, the CISO, was viewed through that lens: a cost center, a necessary defensive line item protecting the digital assets. Their success was measured in negatives—the breaches that didn’t happen, the threats that were stopped at the perimeter. But a quiet, profound shift is underway on the front lines of corporate security. The CISO’s mandate is expanding from pure asset protection to ensuring the entire enterprise can withstand and recover from a hit. They are becoming, in effect, their organization’s chief resilience officers.

This isn’t just a semantic change. It’s a fundamental reorientation of priorities driven by a simple, brutal economic calculus. “The central question for most organizations is: If you’re down, how much money are you going to lose? What’s the impact to your revenue?” explains John Bruggeman, a consulting CISO with decades of experience across firms from 40,000 employees to just 75. As Bruggeman notes in a recent CSO interview, CISOs have always possessed an operational mindset focused on uptime. Now, that instinct is being formalized and elevated. It underpins all business operations, and the stakes couldn’t be higher.

We saw this writ large after CrowdStrike’s global outage, an event that sent shockwaves through the tech and finance sectors. The company’s response was telling: they appointed their first-ever chief resilience officer. That wasn’t just an internal reorganization; it was a direct signal to customers, regulators, and investors—a public commitment to strengthening operational durability. But for most companies, creating a new C-suite role isn’t on the table. Instead, that expansive responsibility is increasingly landing on the CISO’s desk.

So, what does it mean to execute this resilience mindset? First, it requires moving beyond a narrow definition of resilience as mere technical uptime. Aimee Cardwell, a consultant and CISO in residence, argues for a more nuanced view. For a bank or a hospital, resilience might mean prioritizing data protection over speed. The regulatory and brand damage from a data leak could far outweigh the cost of being offline for a day. For an e-commerce giant like Amazon where every minute of downtime represents millions in lost sales, the equation flips. Speed is paramount.

Cardwell pushes for a critical, often-avoided conversation: setting explicit tolerances for data loss. What kind of data, and how much of it, is the business prepared to risk? This question is becoming exponentially harder to answer with the rapid adoption of AI which amplifies the problem of “shadow data”—information living in unexpected, unprotected places. Cardwell recounts a healthcare breach where 15 years of patient data was exposed not through a clinical system but via an insecure accounting folder filled with old invoices. “AI is magnifying that ten times,” she warns. “It’s almost impossible in a large enterprise to have an understanding of where all that data is.” This is where resilience collides with operational reality. You can’t recover what you can’t see.

Execution, then, is about rehearsal and prioritization. Bill O’Connell, CSO at CommVault, frames it with stark clarity: “Define the smallest version of the business that still works, then build your recovery priorities and drills around that.” He advocates for what he terms a “ResOps” approach—treating resilience with the same rigorous, iterative testing as software development (DevOps) or security operations (SecOps). The most painful part of any incident, O’Connell notes from experience, is always the step you never practiced.

This shift presents a delicate challenge for CISOs themselves. Their professional identity has been built on defense. O’Connell is careful: “When you talk to CISOs, you have to be mindful, because if you say, ‘Worry less about defense,’ they get scared because that’s their job.” The point is not to do less on defense but to ensure recovery and availability receive balanced investment and focus. For the board, O’Connell reframes the conversation in the language of business risk: potential impact, financial exposure, and mitigation strategies.

For CISOs looking to strengthen this mandate, collaboration is the new currency of influence. Bruggeman suggests a powerful partnership model. The CISO articulates the cyber and operational risks; the Governance, Risk, and Compliance (GRC) team codifies and quantifies them; and the CFO or COO turns that analysis into funding and organizational mandate. “It’s a shared responsibility,” Bruggeman emphasizes. He sees this as an opportunity for CISOs to elevate their stature, filling a void where a single “chief resilience officer” rarely exists. Responsibility is distributed, creating a natural space for leadership.

From my perch in the Financial District, this evolution makes profound business sense. In an era of constant digital shocks—from ransomware to cloud outages to AI-driven threats—resilience is a competitive advantage. It’s the difference between a company that stumbles and gets back up and one that falls hard. The modern CISO is no longer just the guardian of the gates. They are becoming the architect of the foundation, ensuring that when the ground shakes, the whole structure doesn’t come down. That’s not just a new job description; it’s a critical new pillar of corporate strategy.

  • Shift in CISO role: From cost center to resilience leader
  • Operational mindset: Focus on uptime and recovery
  • Data protection priority: Varies by industry
  • Setting tolerances for data loss: Essential for risk management
  • ResOps approach: Treat resilience like software development
  • Collaboration as currency: Essential for CISO influence
Aspect Traditional Focus New Focus
CISO Role Cost Center Chief Resilience Officer
Success Metrics Breaches Not Happening Operational Durability
Priorities Asset Protection Enterprise Recovery
Data Management Technical Uptime Data Protection vs Speed
Collaboration N/A Shared Responsibility
Risk Management Defense Recovery and Availability

Share This Article
David is a business journalist based in New York City. A graduate of the Wharton School, David worked in corporate finance before transitioning to journalism. He specializes in analyzing market trends, reporting on Wall Street, and uncovering stories about startups disrupting traditional industries.
Leave a Comment