Cyber Resilience in an Era of Technological and Geopolitical Uncertainty
New threats do not change the principles of security. They change how those principles are applied.
The fundamental principles of cybersecurity have not changed over the past five years. However, the rapid development of artificial intelligence, growing geopolitical tensions, the digitisation of public and organisational services, and new regulation are fundamentally changing the environment in which organisations manage risk.
These developments have one consequence in common: organisations are trying to address them using approaches designed for a very different environment and set of conditions.
The individual challenges do not operate in isolation. Together, they are changing the nature of threats, shortening the time it takes for those threats to affect organisations, and making an appropriate response increasingly difficult, sometimes perhaps even impossible.
The ways in which Slovak organisations implement security measures vary considerably. This is confirmed statistically, for example, by the annual cybersecurity reports published by the Slovak National Security Authority. Similar patterns are also reflected in annual reports from ENISA and other relevant vendors operating in their respective fields.
Some organisations still rely on formal compliance with regulatory requirements instead of systematically building cyber resilience. Others introduce fundamental changes only after experiencing a security incident.
A practical example: when information security is approached rationally
In this case, regulatory obligations may not be formally covered in their entirety, and the organisation may operate an average rather than state-of-the-art infrastructure. However, that infrastructure is configured appropriately and securely.
If an employee opens a fraudulent invoice, procedural and technical safeguards work together to protect the organisation. Payment to the fraudulent account listed in the phishing invoice is prevented by manually verifying the account number against existing documentation. Access to the malicious website is blocked by the firewall’s security controls.
Both examples are highly relevant today. The question is how well-known, conservative cybersecurity approaches that have proven effective over many years can be applied in an environment that is changing significantly faster than the underlying technology, particularly IT infrastructure.
The availability of artificial intelligence is changing the economics of cyberattacks
The key change in recent years is not artificial intelligence itself, but its widespread availability. This significantly reduces the time and cost required for attackers to prepare and execute cyberattacks.
Artificial intelligence allows attackers to automate the reconnaissance of publicly accessible systems, identify vulnerabilities, and prepare personalised phishing campaigns. Manual target selection is increasingly being replaced by automated tools that continuously identify exposed systems and assess their suitability for compromise.
This trend increases the importance of vulnerability management at the network perimeter. In the future, organisations can be expected to respond to new vulnerabilities in this category automatically and as quickly as possible.
Geopolitical instability is limiting organisations’ ability to modernise infrastructure
Current lessons from security incidents cannot be assessed without considering today’s geopolitical developments.
Disruption to global supply chains, rising semiconductor prices, high demand for computing resources used by AI, and economic uncertainty are extending the planned replacement cycles of computing equipment.
Organisations are increasingly being forced to operate infrastructure for longer than originally intended. The possibility that existing infrastructure may no longer meet new requirements, such as growing data volumes or increasing performance demands, is only one part of the problem.
The second part concerns hardware reliability: its ability to operate without failure and deliver the expected performance.
A third, but not final, part of the problem is the continued use of operating systems, network-device firmware, or application software that is no longer supported by the manufacturer. This significantly complicates vulnerability management and the implementation of new security measures.
A separate category consists of critical government systems built on diverse hardware and application environments that are now obsolete. Where replacement is not possible for any reason, compensating security controls, thorough isolation of the system and its components, and additional layers of protection deployed in front of the legacy environment can help reduce the risk.
Compensating controls are becoming increasingly important
Limited financial resources prevent many organisations from making the necessary investments in cybersecurity. As a result, technological infrastructure is often operated beyond the end of its planned lifecycle, increasing security risk.
When planning security measures, organisations determine the level of financial and time investment they can afford. Where existing infrastructure can be adapted to become more secure, for example by adding new capabilities without replacing it immediately, the decisive factor is often not money but the time required to implement the changes.
The later the measures are introduced, the greater the risk that existing weaknesses will be exploited.
The risks associated with ageing infrastructure can be significantly reduced through:
- network segmentation,
- isolation of critical environments,
- privileged access management,
- effective operational and security monitoring,
- properly designed multi-layered backups.
Measures that reduce the visibility of systems can also be included in this category.
The principle of security by obscurity, meaning security based on concealment or secrecy, is rightly criticised when it is used as the only protection mechanism. However, in an environment of widespread automated scanning of the public internet, it can serve as a supplementary compensating control that reduces the likelihood of systems being compromised by automated attacks.
One example is reducing the exposure of administrative interfaces on internet-facing information systems and websites.
Even the operator of a simple online shop, a sole trader, or a small company can configure certain security measures through standard web-hosting control panels. Simply restricting access to administrative interfaces exposed to the internet can significantly reduce risk.
A basic measure such as protecting an administrative interface with an additional authentication layer, such as Basic Authentication, can make the exploitation of web vulnerabilities considerably more difficult.
The level of protection can be increased further by restricting access according to IP address or geographical location and by deploying a web application firewall with appropriately configured security rules.
Today, these measures can often be implemented as standard without additional costs.
Regulation cannot replace risk management
Formal compliance with regulatory requirements does not, by itself, reduce the risk of a successful attack or improve an organisation’s ability to recover from an attack with the least possible impact.
Where organisations are unable, or unwilling, to translate requirements into real technical and organisational measures, the resulting compliance becomes an example of undue formalism.
From a legal perspective, undue formalism can be understood as rigid adherence to legal provisions and rules. The same principle applies to cybersecurity.
Cybersecurity is not a state achieved by complying with legislation or a directive. It is a process of continuous risk management.
Genuine cyber resilience begins with getting the security fundamentals right
Technology changes, but the fundamental principles of information-system protection remain the same.
Practical experience shows that the security capabilities of existing technologies remain underused in many organisations. Technical infrastructure audits most frequently identify weaknesses in network segmentation and backup design, even though addressing these weaknesses often does not require significant financial investment.
During one technical security assessment, a backup system was found to be directly accessible from the internal employee network. It was not separated from the virtualisation infrastructure and, in the event of a compromise, would have allowed all backups to be deleted.
Its resilience was significantly improved through network segmentation, stricter communication rules, changes to the configuration of the backup storage, and backup encryption.
Absolute security cannot be achieved. However, when protecting backups, maximising the level of protection and maintaining strict and precise controls are essential.
In another case, more than half of the detection mechanisms in a modern security solution were inactive. They could not be used because the organisation lacked network segmentation.
By changing the configuration of the existing infrastructure, the organisation achieved a significant improvement in its level of protection without additional investment.
Practical experience confirms that greater cyber resilience does not depend on purchasing new technologies. In most cases, it is achieved through:
- systematic reassessment of the security architecture,
- correct configuration of existing solutions,
- regular verification of their effectiveness,
- continuous development of users’ skills.
Building cyber resilience today primarily means being able to use existing technologies effectively, continuously verify whether they work as intended, and systematically improve people’s preparedness.
Organisations that can connect technology, processes, and people into a functioning whole will be significantly better prepared to face both current and future threats than organisations that build their security primarily on procuring new technologies or formally meeting requirements.
Hear more from our speakers
Join Qubit Conference® Slovakia 2026 - November 11-12
Related Articles
Where does transparency end and intrusion into privacy begin?
Jan Golais · 13 min read
When a Vulnerability Is Being Actively Exploited: How to Make the Right Decisions in the First 48 Hours
Marek Madžo · 9 min read
NIS2 in Practice: A Manufacturing Industry Perspective
Lucia Žvačeková · 8 min read