Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

ResOps and AI-driven attacks: what resilience teams need to change


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15374
Topic starter  

TL;DR: IDC’s Resilience Operations report says more than 500 North American organisations are moving from recovery metrics toward business outcomes, while nearly 6 in 10 still have not defined their minimum viable business and many remain dependent on manual recovery, according to Commvault. The shift matters because AI is compressing attack and disruption timelines faster than current resilience operating models can keep up.

NHIMG editorial — based on content published by Commvault: ResOps and the discipline that makes readiness provable

By the numbers:

Questions worth separating out

Q: How should organisations define minimum viable business for resilience planning?

A: Start by identifying the smallest set of services, data, processes, and identities required to keep the business operating after disruption.

Q: Why do machine identities make cyber resilience harder?

A: Machine identities make resilience harder because their credentials are embedded in services, scripts, and automations that may fail silently during an incident.

Q: What breaks when recovery remains a manual process?

A: Manual recovery creates delay, inconsistency, and decision bottlenecks when attackers or outages move faster than humans can coordinate.

Practitioner guidance

  • Map recovery order to business-critical identity dependencies Identify which directory services, privileged access channels, service accounts, tokens, and SaaS trust relationships must be restored before each critical business service can operate.
  • Automate identity and workload recovery workflows Build orchestration for account restoration, secret revalidation, privileged access reissuance, and configuration checks so recovery does not depend on manual sequencing.
  • Test resilience with tabletop and cyber-range exercises Run exercises that force business, security, infrastructure, and compliance teams to make recovery trade-offs under pressure.

What's in the full article

Commvault's full post covers the operational detail this article intentionally leaves for the source:

  • IDC’s maturity model and how it stages organisations from reactive recovery to adaptive resilience
  • Examples of the cross-functional operating model behind ResOps, including business, security, infrastructure, and compliance roles
  • The report’s breakdown of tabletop exercises, cyber-range simulations, and validation practices that improve recovery performance
  • How the survey respondents are thinking about future resilience pressure from agentic AI, machine identities, and post-quantum cryptography

👉 Read Commvault’s analysis of IDC’s Resilience Operations report →

ResOps and AI-driven attacks: what resilience teams need to change?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14958
 

Resilience operations is becoming an identity problem as much as an uptime problem. The article is right to move the discussion from recovery time to business continuity, because the systems that decide what comes back first increasingly depend on identity stores, privileged access, and service credentials. If those controls are unstable, the organisation may restore infrastructure but still be unable to operate. For IAM and PAM teams, resilience planning must now include access restoration order and trust revalidation.

A question worth separating out:

Q: Who should own resilience decisions when business, security, and IT priorities differ?

A: Ownership should sit in a shared operating model that aligns business continuity, security containment, infrastructure restoration, and compliance obligations. No single team can optimise resilience alone. The practical answer is joint governance with pre-agreed recovery thresholds, escalation paths, and validation criteria.

👉 Read our full editorial: ResOps is shifting resilience from recovery metrics to business continuity



   
ReplyQuote
Share: