Building Cyber Resilience for the AI Era — CyBrilliance - September 3, 2026

Q&A with CyBrilliance CEO Gordon Cowan 

Artificial intelligence is changing the enterprise risk equation by increasing the speed, scale and complexity of how data, identities, applications and business decisions are connected. For CIOs and CISOs, that increases the importance of understanding where information originates, how it moves through the enterprise and whether its integrity can be demonstrated when decisions are made.

The implications extend across cybersecurity, business continuity, governance and financial risk. While existing security controls remain important, organizations also need greater visibility into the dependencies surrounding those controls and a reliable evidentiary record of what occurred before, during and after an incident.

BizTechReports spoke with Gordon Cowan, founder and CEO of CyBrilliance, about how enterprise leaders should reassess cyber resilience as AI adoption accelerates. Drawing on his cybersecurity work and 45 years in the insurance industry, Cowan discussed the strategic, operational, financial and technological implications of preparing enterprises for a threat environment increasingly shaped by automation, compromised identities and rapidly evolving attack methods.

Here is what he had to say:

Q: How does the growing use of AI change the way executive leadership should think about cyber resilience?

A: AI increases the complexity because we now have to understand how decisions are being made and the trusted sources of information on which those decisions and their underlying assumptions are based. If an organization is using AI to support an executive decision, where did that information come from? Was it validated? Was it verified? Was it tested?

You have to break the environment down into its components because everything is becoming increasingly integrated. A vulnerability or deficiency at one point in that continuum can affect something much further downstream, including a business decision.

AI is also accelerating vulnerabilities, gaps and deficiencies that already exist in protocols and security solutions. That means resilience has to encompass preparedness, readiness, visibility, response, recovery, governance and survivability. Leadership needs confidence in the entire process rather than assuming that deploying AI on top of the existing environment leaves the underlying risk profile unchanged.

Q: What should organizations establish before expanding AI into consequential business processes?

A: Start by determining exactly what AI is being used for and what the ultimate objective is. Once you understand that, you can determine what information is required, where that information will come from and whether those sources can be trusted.

That sounds like a lot of detail, but it needs to be scoped at that level. When a plan is presented to the board, executives should be able to say that the information supporting it has been verified and validated within a defined scope, and that there is evidence behind what they are asking leadership to use to make a business decision.

There is more work in preparation than people sometimes recognize. Preparedness establishes the conditions before disruption. Readiness is the demonstrated ability to activate those conditions when normal assumptions fail. Skipping a step can introduce a vulnerability that becomes consequential later.

Q: What does operational readiness require in an environment where organizations must assume that some attacks will get through?

A: Visibility is fundamental. There are still significant visibility gaps even with the security tools organizations have today. Data visibility does not simply mean knowing where your databases are. You need visibility into unstructured data, information residing on endpoints and data while it is moving. You need evidence showing where that data was, who handled it and when.

That evidence becomes valuable before, during and after an incident. Beforehand, it can identify where problems are developing. Following a breach, it helps establish what happened and provides the evidence needed to recover to what I describe as a trusted operational state.

Preparedness therefore means having the tools and visibility required to understand the environment before something happens rather than attempting to reconstruct everything after an attack. Readiness is the demonstrated ability to activate those conditions when normal assumptions fail. Together, they support survivability: the ability to preserve critical operations, trustworthy data, decision authority and a viable recovery path under degraded conditions.

Q: How do compromised credentials and changing attack methods affect traditional security assumptions?

A: I am not advocating that organizations remove or replace their existing security technologies. Detection and defense, backups, identity and access management and privileged access management all remain important. CyBrilliance complements existing environments, teams, providers, controls and technologies by examining the dependencies and assumptions around them.

The problem is that many of those capabilities were developed around earlier threat tactics. Attackers are finding vulnerabilities and deficiencies around those controls.

Credential theft is a good example. If somebody enters your environment with legitimate credentials, the system may recognize that person as authorized. At that point, you need to think about what happens after the individual gets through the door. What can they see? What can they access? What can they do?

Organizations therefore have to manage access beyond the initial credential check and limit what a compromised identity can expose. The same principle applies elsewhere. Resilience requires understanding where the gaps around established controls exist and finding ways to mitigate them.

Q: How should executives connect cyber resilience investments with financial risk?

A: Executives should begin with the business objective, not the technology. Identify the critical decisions, information, systems and operating conditions required to achieve that objective. This provides a clearer basis for understanding what is at risk and where resilience investment will deliver the greatest business value.

In today’s operating environment, healthcare and most other organizations depend on continuous operational availability. Disruption can therefore create financial exposure within minutes or hours. Banking and critical infrastructure are particularly vulnerable because even brief interruptions can affect essential services, safety, liquidity, public confidence and downstream dependencies.

Recovery time is consequently a financial variable. If an organization’s required operating window is measured in minutes or hours but restoration takes days or weeks, the gap represents material business and financial exposure. A service-level agreement is not proof of recovery capability unless that capability has been demonstrated under relevant disruption conditions.

Executives must also consider data certainty. If the organization cannot establish what information was affected, whether sensitive data was exfiltrated, which systems remain reliable or which recovery sources can be trusted, the investigation may become prolonged and expensive. The consequences can include regulatory notification, legal exposure, contractual obligations, reputational damage and continued operational uncertainty.

Resilience investments should therefore be prioritized against measurable financial and operational exposure. Leaders should define the required operating window, establish decision authority and escalation thresholds, identify the evidence needed to support action, and validate whether critical systems and data can remain operationally available through disruption or be restored from an evidenced trusted operational state.

Finance should be able to assess whether an investment reduces downtime, protects revenue, limits capital at stake, reduces investigation and compliance costs or preserves critical operations. That assessment should be based on demonstrated capability and evidence, not policy, confidence or an untested recovery assumption.

The objective is not to claim that risk has been eliminated. It is to establish preparedness before disruption, readiness to activate when normal assumptions fail and survivability through the preservation of critical operations, trustworthy data, accountable decisions and a viable recovery path.

Q: What does your insurance background tell you about the relationship between cybersecurity controls and cyber insurance?

A: Organizations should not think of cyber insurance as something they simply purchase and then forget about. An insurance policy establishes responsibilities for both parties. It defines the controls an organization is expected to have and, importantly, the evidence required to demonstrate that those controls were being maintained.

That becomes important after an incident. An organization may have purchased substantial cyber-insurance coverage and assume that the financial protection will be available following a breach. However, the policy contains conditions and responsibilities that must be met and evidenced.

That is why evidence matters. Cybersecurity, compliance and insurance become connected. Organizations need an ongoing record demonstrating that required controls were implemented and operating rather than trying to establish compliance retrospectively after an incident.

Q: Why are traditional backup and recovery strategies becoming a particular area of concern?

A: Backups are only valuable if they can be accessed and trusted when they are needed. Attackers understand that, which is why backups themselves can become targets for wiping, encryption or corruption. Many chief information security officers will point to immutable or offline copies as the answer. These are important safeguards, but immutability does not automatically make a backup trusted. It does not prove that the copy is complete, current, free from compromise, accessible during an attack or capable of restoring a functioning operating environment.

An immutable copy is like a fire plan: useful, but not proof that the exits, route and people will function when the building is under stress.

The more important question is whether the organization can identify the last known-good state, access it when identity, network, cloud or administrative systems are impaired, and restore the operating systems, applications and data required to continue operating.

There is also a significant operational dependency. Much backup infrastructure relies on cloud, network, identity and management services. During an incident, response teams may isolate those systems, potentially isolating the resources required for recovery.

Organizations need to examine those dependencies rather than assuming that having backups has solved the recovery problem. Restoration must be tested under the conditions that matter, including compromised credentials, unavailable network services, corrupted backups and uncertain data integrity.

This reflects a broader distinction between resilience and survivability. Resilience is what an organization has designed to withstand disruption. Survivability is the demonstrated ability to preserve critical operations, trustworthy data, decision authority and a viable recovery path when normal systems, controls or recovery sources are impaired or un-trusted.

Time is equally critical. An enterprise may be able to rebuild systems, but if rebuilding takes weeks or months, that may be unacceptable for a bank, healthcare organization, critical infrastructure operator or any organization dependent on continuous operational availability. The objective should be to restore operating systems, applications and data quickly enough to meet the operational requirements of the business and to establish, with evidence, that the recovered environment can be trusted.

That evidence should connect the recovery source to the last known-good state and account for relevant data activity, encryption, exfiltration indicators, governance records and material events before, during and after the incident. Recovery is not complete simply because systems are running again. The organization must be able to determine what has been restored, what may remain affected and whether it can authorize a return to operations.

The issue is therefore not whether an organization has immutable or offline backups. The issue is whether it has demonstrated the ability to access a trusted recovery source and restore critical operations within the required operating window when normal assumptions fail.

Q: What capabilities should CIOs and CISOs prioritize to close the resilience gaps you are describing?

A: I look at three connected capability areas that need to work together. One is governance. Organizations need a way to understand their requirements, controls and responsibilities.

The second is continuous data visibility. Assessments performed periodically provide a snapshot, but organizations increasingly need continuous monitoring, so they know what happened to their data, whether information was exfiltrated, whether an insider was involved or whether activity occurred through shadow IT.

The third area is recovery and restoration. Organizations need capabilities that can help them return systems, configurations, applications and data from an evidenced trusted source to a known-good condition within the timeframes the business requires.

The important element connecting these areas is evidence. Logs are useful for incident response, but they are also important for business decisions, regulatory requirements and insurance. AI makes this even more significant because organizations increasingly need to capture how decisions were made and what information supported them.

Governance therefore has to wrap around the entire continuum. Organizations need visibility before an incident, evidence of what happened during it and the ability to establish that the environment they recover afterward can once again be trusted. That validation must be evidence-based and scope-limited: it should show what was examined, under what conditions, what was observed and what remains unproven. It is not a certification, warranty, legal opinion, regulatory determination or guarantee of future performance.

###

​EDITOR’S NOTE: Click Here To Learn More About CyBrilliance


Next
Next

Nearly Nine in Ten CEOs See Some Cost or Revenue Benefits from AI in Targeted Areas, But Most Are Struggling to Scale It – BCG – September 1, 2026.