CISOs Are Now Running Business Resilience. Most Companies Haven't Noticed.
Security chiefs are quietly absorbing responsibility for keeping companies alive after a disaster, not just preventing one. Three experienced practitioners explain what that shift actually demands.

Key points
- Chief information security officers (CISOs), the executives responsible for a company's digital safety, are increasingly expected to own business recovery after a cyberattack or outage, not just prevention.
- CrowdStrike created a dedicated chief resilience officer role after its 2024 global outage, but most companies are piling that responsibility onto existing CISOs instead.
- Security consultant Aimee Cardwell says organisations routinely overlook "shadow data", meaning sensitive files that exist in unexpected places like accounting folders, which no standard perimeter defence catches.
- CommVault CSO Bill O'Connell warns that business continuity plans left as unread documents fail in a real crisis; rehearsal is what makes recovery work.
- Cardwell argues companies must set explicit tolerances for data loss, not just recovery speed, because the two goals can pull in opposite directions.
The title on the business card still reads "Chief Information Security Officer." The actual job description is something else entirely.
Over the past several years, the role has stretched well past locking doors and keeping hackers out. CISOs now carry meaningful responsibility for what happens after something goes wrong: how quickly a business gets back on its feet, how much data it loses, and whether it survives at all. Three practitioners who spoke to CSO Online describe a profession quietly absorbing duties that no one formally assigned.
What changed, and why does it matter?
The shift is practical, not ceremonial. John Bruggeman, a consulting CISO who serves organisations ranging from a 75-employee firm to a 40,000-person global company, frames it plainly: security professionals who came up through IT have always thought about uptime. The question was always, "How do I make sure we're not totally down?"
What changed is that boards and chief executives are now asking the same question out loud, often prompted by high-profile outages. After CrowdStrike's faulty software update caused a worldwide technology failure in 2024, the company appointed its first chief resilience officer. That title was a signal to regulators and investors that resilience had moved to the top of the agenda.
Few companies will create that post. For most, the work lands on whoever already owns cybersecurity.
What does "resilience" actually mean in practice?
It is more than restarting servers quickly. Consultant Aimee Cardwell, a CIO and CISO in residence at Transcend, draws a clear line between two separate goals: restoring systems and protecting data. Organisations habitually focus on the first and underweight the second.
The right balance depends on what a company holds. A bank, Cardwell argues, should accept two days of downtime rather than expose customer financial records. A company like Amazon, which converts credit card numbers into harmless codes through a process called tokenisation, before storing them, risks far less from a breach. For Amazon, every minute offline costs millions, so speed back matters most.
Setting those tolerances explicitly is what CISOs now need to drive. Most organisations measure how long recovery takes. Far fewer set a formal limit on how much data loss they are willing to accept.
Cardwell raised a concrete example: a healthcare provider that ran 15 years of patient records through its billing process, attaching names, conditions, and identification numbers to invoices sitting in an unprotected accounting folder. No firewall was watching that folder. The breach came not through the front door but through a filing cabinet no one thought to lock.
"Shadow data", files that exist outside the systems IT officially manages, is where much of today's resilience risk hides. Artificial intelligence tools, because they pull from wherever data lives, are making that problem significantly worse.
Bill O'Connell, CommVault's CSO, offers a practical anchor: define the smallest version of the business that still functions, then build recovery priorities around that core. He calls the discipline "ResOps", a deliberate practice of repeatedly rehearsing recovery the way software teams rehearse deployments.
| Concept | Plain meaning | Who owns it |
|---|---|---|
| Mean time to recovery | How long it takes to restart systems | CIO, increasingly CISO |
| Data loss tolerance | How much information the company will risk losing | CISO (often undefined today) |
| Shadow data | Sensitive files outside officially managed systems | Rarely owned formally |
| Tokenisation | Replacing sensitive numbers with harmless codes | Security or engineering teams |
| ResOps | Repeating recovery drills the way teams rehearse software releases | Proposed for CISOs |
Plans that live in documents fail. O'Connell is blunt: the hardest moments in any incident are always the steps no one practised. Knowing who to call and where to find information under pressure is a muscle. It only develops through repetition.
What should ordinary employees or customers watch for?
If your employer, bank, or healthcare provider suffers an outage or discloses a breach, ask one question before any other: was data taken, or was the system simply unavailable? The answer changes what you need to do. A temporary outage with no data exposure requires nothing from you. A breach involving patient records, financial details, or login credentials means you should change passwords and watch for suspicious contact.
Bruggeman notes that boardroom language matters too. When executives use the word "resilience" rather than "backup", funding follows. That funding eventually determines whether the company protecting your data has practised what happens when things go wrong.



