< ciso
brief />
Tag Banner

All news with #resilience tag

83 articles

Ransomware Forces Shift Toward Enterprise Resilience

🔒 Ransomware has evolved from simple encryption schemes into multifaceted campaigns that combine data theft, extortion, and operational disruption. Attackers increasingly leverage AI and target third parties, expanding the attack surface and complicating detection. CISOs must now prioritize business continuity, vendor risk, and AI governance alongside traditional security controls to maintain trust and operational resilience.
read more →

MediaConnect Router Adds Configurable Latency Modes

🔧 AWS Elemental MediaConnect Router now lets customers set internal recovery latency per output. Customers can choose between balanced mode (default behavior) and low-latency mode to optimize recovery time for latency-sensitive workflows. The setting is configurable via the MediaConnect API, AWS Management Console, or AWS CLI, and a new CloudWatch metric, RouteFabricRecoveryLatency, exposes recovery latency per route. This feature is available in all regions where MediaConnect Router is deployed.
read more →

Agentic AI Enhances Operational Resilience in Banking

🤖 Deutsche Bank partnered with Google Cloud to build an agentic AI-driven resilience platform that modernizes regulatory tabletop exercises and incident analysis. The platform ingests architecture, logs, data flows, and telemetry to generate context-aware scenarios, audit-ready evidence, and structured session records. Using Gemini Enterprise Agent Platform, LangGraph, and Google ADK, the bank achieves both deterministic, traceable execution and adaptive investigation. This approach supports continuous, regulator-aligned resilience across complex, distributed systems.
read more →

Sharded Hub-and-Spoke to Mitigate Noisy Neighbors

🔎 This article explains how shifting from a monolithic data pipeline to a sharded hub-and-spoke architecture reduces the impact of "noisy neighbor" tenants. The Hub acts as a lightweight router while Spokes provide isolated processing with Pub/Sub buffers between them. The design enables independent scaling, fault isolation, tiered pipelines for priority tenants, and spoke-level best practices such as DLQs, strict connection pooling, and asynchronous I/O.
read more →

AWS Resilience Hub adds recommended resilience tests

🛠️ AWS Resilience Hub now offers recommended resilience tests to help platform engineering and site reliability teams validate service behavior under known failure scenarios. The feature uses AWS Fault Injection Service (FIS) to inject controlled faults, evaluate recovery against defined objectives, and produce pass/fail results with detailed reports. Tests cover Availability Zone and Regional impairments and dependency failures, and are available in multiple global regions.
read more →

NCSC issues guidance for disruptive cyber incidents

🛡️ The UK's National Cyber Security Centre (NCSC) has published What To Do When Cyber-Attacks Disrupt Your Organisation, outlining three chronological stages for response: immediate hours and days, recovery to minimum viable operations, and longer-term restoration to business as usual. The guidance emphasizes preparing in advance, practicing realistic simulations, and engaging NCSC-vetted incident response firms to build resilience against escalating threats such as AI-accelerated attacks.
read more →

CISOs Rising to Lead Business Resilience

🔒 CISOs are increasingly acting as de facto chief resilience officers, expanding from prevention to incident response and recovery. Experts recommend framing resilience in business terms — uptime, data protection, and financial impact — to secure board-level buy-in and funding. Practical steps include defining minimum viable operations, rehearsing recovery through a "ResOps" approach, and partnering with GRC, finance, and operations to share responsibility.
read more →

Jurassic Park and the Myth of Cyber Control

🦖 The article compares Jurassic Park’s failed containment to modern cybersecurity, arguing that visibility is often mistaken for control. It asserts that tooling, dashboards, and backups provide friction but not guaranteed survivability, and that dynamic cloud and AI-driven change invalidate static recovery assumptions. The piece recommends continuous resilience engineering, dependency awareness, and validation to operate through inevitable disruptions rather than assume they can be prevented.
read more →

EKS Auto Mode adds ARC zonal shift support

🛡️ Amazon EKS Auto Mode now integrates with Amazon Application Recovery Controller (ARC) to provide zonal shift and autoshift support for clusters using EKS Auto Mode. This feature automatically protects compute during an ARC-initiated zonal shift by stopping new capacity provisioning and preventing voluntary disruptions in the impaired zone. Enable ARC zonal shift on your cluster to use this capability, which is available in all Regions where EKS Auto Mode is offered.
read more →

Azure’s Unified Approach to Cloud Resiliency

🔧 Azure reframes resiliency beyond simple availability metrics to emphasize sustained operation, recoverability, and trust under real-world constraints. The platform combines zone-first design, data protection, and cyber recovery with observability and automation to help customers meet sovereignty and regulatory needs. New tooling like Azure Infrastructure Resiliency Manager and the Resiliency Agent shift guidance to executable, IaC-driven remediation.
read more →

SaaS single points of failure threaten campuses

📘 Higher education now runs core academic operations on a few massive SaaS platforms, creating systemic single points of failure. When a major LMS was breached during finals week 2026, campuses lost access to rosters, grade books and coursework despite SLAs and certifications. The author argues IT must architect independent, read-only continuity layers synchronized from source systems to maintain operations during vendor outages or attacks.
read more →

Azure Chaos Studio Workspaces public preview

🧪 Azure Chaos Studio Workspaces is now in public preview, offering scenario-focused chaos engineering to validate application resilience. It provides curated outage scenarios (Zone Down, DNS Outage, SQL failover, etc.), a drag-and-drop Scenario Designer, and a managed Workspace that discovers resources and recommends applicable tests. Runs produce structured drill reports and integrations with GitHub Copilot and Model Context Protocol for automated workflows.
read more →

Stonehenge as a Model for Cybersecurity Architecture

🪨 The author uses Stonehenge as a metaphor for designing resilient cybersecurity architectures, arguing organisations must move from fragmented point solutions to a modular, platform-based approach. Palo Alto Networks emphasises a unified cyber data layer, Precision AI integration, and an Autonomous SOC to enable real-time detection and response across IT, OT, cloud, and edge. The piece highlights identity security, AI runtime protection, and supply-chain risks as critical pillars for long-term resilience.
read more →

Cybersecurity’s Shift From Protection to Survival

🔒 The piece argues that cybersecurity must move beyond a prevention-first mindset to a survival-focused discipline. It stresses that while traditional controls (MFA, patching, hardening) remain necessary, organizations need breach readiness: continuity, recoverability, tested incident response, and clear governance. Regulatory and market pressures (EU resilience laws, US disclosure and accountability) plus AI-driven acceleration make resilience an operational imperative.
read more →

AI Forces Security to Shift From Predictability

🛡️ AI is reshaping cybersecurity by breaking the long-held assumption of predictable, deterministic systems. Traditional prevention-focused controls remain important but are insufficient as AI agents, LLMs and automated development accelerate runtime change and attacker capabilities. Organizations must prioritize runtime visibility, use AI to augment defensive operations, rebuild vulnerability management and emphasize resilience and containment to manage evolving AI-driven risks.
read more →

SMB Cyber Readiness: What Strengthens or Breaks It

🔒 The ESET SMB Cyber Readiness Index 2026 finds 45% of small and medium businesses experienced a cyber-incident in the past year, yet confidence in resilience often rises among repeat victims. The report highlights common root causes—phishing, unpatched vulnerabilities, monitoring gaps and weak passwords—and notes a mismatch between headline-driven fears like AI malware and the mundane vectors attackers exploit. Preparation, clear decision authority, and disciplined reduction of attack surface are critical to withstand incidents.
read more →

NCSC: Act Now to Build Cyber Resilience

🔒 Paul Chichester of the NCSC warned at Infosecurity Europe that escalating technological change, geopolitical tensions and evolving threats make predicting cyber risk harder than ever. He highlighted hyper-connectivity, rapid tech transformation and state-backed cyber operations as key challenges, and urged stronger public-private collaboration. Chichester praised the Cyber Security and Resilience Bill and called for practical steps like reducing attack surface, addressing legacy systems, enforcing access controls and running incident exercises.
read more →

AlloyDB Hot Standby: Faster Failovers and Reliability

🚀 AlloyDB for PostgreSQL introduces a Hot Standby HA architecture that keeps the standby node actively replaying WAL records, reducing failover time and preserving cache warmth. This change eliminates standby database startup delays and minimizes post-failover performance degradation, improving RTO and stabilizing application throughput. Hot Standby is rolling out for PostgreSQL 18 and will reach earlier versions in months, with no extra cost and retention of the 99.99% SLA.
read more →

AWS launches next-generation Resilience Hub

🔧 The next generation of AWS Resilience Hub is now generally available, offering platform engineering and SRE teams a centralized console to assess and strengthen workload resilience. It introduces a three-level application model, automated dependency discovery, generative AI-powered failure mode analysis, modular resilience policies, and organization-wide reporting. Integration with AWS Organizations enables central policy definition and posture monitoring across accounts and regions, and existing customers can migrate at their own pace.
read more →

AWS ARC Region Switch: Lambda Event Source Mapping

🚦 Amazon Application Recovery Controller (ARC) Region Switch adds a Lambda event source mapping execution block to automate coordinated failover of event-driven streams across Regions. The block enables or disables Lambda event source mappings for Kinesis, DynamoDB Streams, MSK, and SQS to prevent duplicate processing. Customers can chain a disable block before an enable block, or run plans in ungraceful mode for impaired Regions. Native cross-account support lets a single plan span multiple AWS accounts.
read more →