Skip to Content

Cyber Resilience - Preparing Businesses for the Storm Before It Hits

22 August 2026 by
Kazi Omer

A Calm Side of Information Security

Cybersecurity has also been a buzzword which makes professionals think of high-end hacking and system hijacking, which isn't their problem, but the world has only shown this side of information security which reflects these thoughts.

In this blog, I'll take you through the calm side of information security. Of course, "calm" would be a very partial word to use for this domain, but to keep things simple, I'll use this word.

The Role of Technology in Business

In today's day and age, companies are built on top of technologies, IT, OT. Everything around us is more or less dependent upon technology.

The classic businesses have leveraged IT to scale or reach the masses.

But what if we remove the IT component from these businesses, even though the main revenue source of the business isn't very IT-oriented?

The business would of course fail or at least won't be able to survive long.

Here's the analogy to understand:

The core business of restaurants is to sell food, but if platforms like Hungerstation, Talabat, or Uber Eats did not exist, the restaurants would not grow as much as they do now.

Similarly, every other business handling tasks/operations at a certain scale is reliant on IT.

Key Questions to Ask

But here are the questions to be asked:

  • What all technologies are being used?

  • What if they fail?

  • How would a specific technology be implemented across a company in an effective and efficient way?

  • How should engineers collaborate to build and manage IT in an enterprise?

What Is Cyber Resilience?

All of these questions are answered or catered to by this side of information security known as "cyber resilience."

To put it simply: it is the ability of a business to react and respond to known and unknown threats, both external and internal, with proactiveness to ensure IT infrastructure and security policies match business objectives and align with compliances.

What Is Proactiveness?

It's a behavior or the practice of looking for potential loopholes, issues, or technological drawbacks and fixing them before the bad guys use them to exploit, and making the organization ready to act if that is exploited.

What Is ITIL?

To ensure the maximal effective usage of technologies in an organization that ensures alignment with business aims, a popular framework like ITIL is used.

ITIL (Information Technology Infrastructure Library) is a framework used by enterprises to include IT in a way that effectively aligns with business objectives and aims.

The framework has several standards and best practices that are used as a reference in order to configure, set up, and work across several IT components.

When a company grows, it might expand its services, and so does the IT.

ITIL supports continuous ITSM (IT Service Management) lifecycle.

To speak without the jargon: ITIL is a framework used to make sure IT is used at its best to fulfill business needs.

Change Management

Change is the only constant.

This is so true in today's day and age; with increasing amounts of complexity in systems, vulnerabilities or spaces for improvement are also growing at a pace.

What Is Change Management?

If everybody in the organization starts making changes individually, there would be chaos, and each department would be in silos.

Effective change management ensures:

  • Changes are documented

  • Changes are assessed against the risks

  • The changes are well tested and managed

Key Terms in Change Management

The complete change management process involves several jargons; a few of them I am including below:

CR (Change Request): it is a document that proposes a specific change in an IT system/component.

It includes what the exact change is, why it's required, and what the risks associated with the change are.

CR also contains how the change has to be carried out and the process to follow if something goes wrong during the change, with the aim to ensure business operations are not negatively impacted by these changes.

These changes are reviewed and approved by a team called the Change Authority Board (CAB) , or Emergency CAB.

It is a team of senior management/stakeholders/decision-makers of the company from different departments: IT, governance, operations, etc.

How Are Changes Managed?

Change management is assessed and performed through platforms that unify each department and structure all the IT activities.

ServiceNow

ServiceNow is a cloud-based platform used enterprise-wide which helps in automating and orchestrating digital workflows.

ServiceNow is used by thousands of leading enterprises; at its core, it is a brilliant data model.

With ServiceNow, enterprises can coordinate and work across departments, keeping every action taken by each department in a digital record with the help of CMDB (Configuration Management Database).

Overall, ServiceNow is used widely across enterprises to measure various risk metrics and ensure compliance across departments in a company.

Conclusion

All these practices and processes prepare for the calm before the storm, and that's the proactive approach.

Read this blog to understand how companies prepare to withstand a storm, i.e., a disaster.

Business continuity plan -strengthening towards resilience
How I build and prepare to aim towards Resilient Business