Loading summary
A
You're listening to the CyberWire network powered by N2K. AI is making phishing attacks faster, more convincing, and harder for people to spot, and traditional security awareness and phishing training weren't designed for this level of attack. HOX Hunt helps security teams prepare employees for the attacks they face every day with personalized phishing training that adapts to each employee and reduces risky behavior over time for IT and security leaders looking to strengthen their human layer of defense without adding more manual work. Visit hoxhunt.com cyberwire to learn more. That's H O X h u n t.com cyberwire. You're listening to the CyberWire network powered by N2K foreign. AI is transforming every industry, but it's also creating new risks that traditional frameworks can't keep up with. Assessments today are fragmented, overlapping, and often specific to industries, geographies or regulations. That's why Black kite created the BKGA3AI assessment framework to give cybersecurity and risk teams a unified, evolving standard for measuring AI risk across their own organizations and their vendors. AI use it's global, research driven, built to evolve with the threat landscape and free to use because Black Kite is committed to strengthening the entire cybersecurity community. Learn more@blackkite.com.
B
The word is resiliency, Spelled R for robustness, E for elasticity and ziliency because I got tired of finding synonyms for the word resiliency for all the letters that make up the word. The ability to continuously deliver the intended outcome despite adverse cyber events. Example sentence the bottom line is that network defenders can use resiliency tactics associated with with identity, protect, detect, respond and recover to reduce the probability of material impact to our organizations. Origin and context. As a concept, ASAS International coined the phrase cyber resilience as early as 2009, but it was really describing what turned out to be business continuity. In 2010, the US Department of Homeland Security identified resilience in cyberspace as the ability to adapt to changing conditions and prepare for, withstand, and rapidly recover from disruption. The World Economic Forum formalized a cyber resilience definition in 2012 the ability of systems and organizations to withstand cyber events. Since then, other thought leaders have refined it. US President Obama even signed a Presidential Policy directive dictating resilience for the country's critical infrastructure in 2013. In 2017, the International Standards Organization published this the ability of an organization to absorb and adapt in a changing environment to enable it to deliver its objectives and to survive and Prosper. Then in 2019, NIST standardized the definition of cyber resilience as the ability to anticipate, withstand, recover from, and adapt to adverse conditions, stresses, attacks or compromises on systems that use or are enabled by cyber resources. NIST also states that the cyber resilience discussion is predicated on the assumption that adversaries will breach defenses. This statement is often overlooked and not understood. Cyber resilience is not about protecting the system and preventing the adversary from breaching your systems. It means assuming the system is or will be breached and figuring out what you need to do to continue your mission after the fact. So the definition I like Best comes from two Stockholm University researchers in 2015, Jana Sturna and Jelena Zvrakovic. They define it this the ability to continuously deliver the intended outcome despite adverse cyber events. In other words, assume that the bad guys will successfully negotiate the intrusion kill chain, find a weak spot in my zero trust armor, or in general, assume that there will be a massive IT failure at some point in the future. Then devise a strategy to ensure that your organization's essential services will still function. Nerd Reference the difference between merely surviving a catastrophe and demonstrating resilience in the wake of one is can be found in two science fiction classics, Terminator and Terminator 2 Judgment Day in the first movie, Skynet, the artificial intelligence that took over the world, designed the first Terminator robot played by Arnold Schwarzenegger. I'll be back for survivability. Arnold was loaded with various functions to identify, protect, detect and respond to ensure that he would survive and be able to defend himself. However, as he accumulated damage, he began to lose functionality. By the end of the movie, he couldn't perform any of his tasks, but he was surviving. In the second movie, Skynet designed the new and upgraded Terminator 2 robot played by Robert Patrick, to be resilient. He was leaner, smaller and could anticipate, withstand, recover from, and adapt to attacks. His body would absorb the bullet and heal. If he was shot, he could take the damage and continue to perform his higher order functions. That's resilience. Word Notes is written by Tim Nodar, executive produced by Peter Kilpe and edited by John Pettrick and me, Rick Howard. The mix, sound, design and original music have all been crafted by the ridiculously talented Elliot Peltzman. Thanks for listening.
A
Most environments trust far more than they should and attackers know it. Threat Locker solves that by enforcing default deny at the point of execution. With Threat Locker allow listing, you stop unknown executables cold. With ring fencing, you control how trusted applications behave and with ThreatLocker DAC defense against configurations. You get real assurance that your environment is free of misconfigurations and clear visibility into whether you meet compliance standards. ThreatLocker is the simplest way to enforce zero trust principles without the operational pain. It's powerful protection that gives CISOs real visibility, real control, and real peace of mind. ThreatLocker makes zero trust attainable even for small security teams. See why thousands of organizations choose ThreatLocker to minimize alert fatigue, stop ransomware at the source, and regain control over their environments. Schedule your demo@threatlocker.com N2K today. AI is making phishing attacks faster, more convincing, and harder for people to spot. And traditional security awareness and phishing training weren't designed for this level of attack. HOX Hunt helps security teams prepare employees for the attacks they face every day with personalized phishing training that adapts to each employee and reduces risky behavior over time for IT and security leaders looking to strengthen their human layer of defense without adding more manual work. Visit hawkshunt.com cyberwire to learn more. That's H O X H U N T.com cyberwire.
Podcast: Hacking Humans (N2K Networks)
Date: August 4, 2026
Episode Theme:
This episode explores the evolving concept of “resiliency” in cybersecurity—what it means, how it has developed, and why it’s a vital lens for thinking about defense against relentless, often successful, cyber attacks.
The episode’s central purpose is to dissect the meaning of “resiliency” in the context of cyber attacks, tracing its origins, its formal definitions, and its practical implications. The discussion brings clarity to why resilience, rather than mere survivability or prevention, is becoming central in cybersecurity strategies.
“The ability to continuously deliver the intended outcome despite adverse cyber events.”
“Spelled R for robustness, E for elasticity, and ziliency because I got tired of finding synonyms for the word resiliency for all the letters that make up the word.”
"Identified resilience in cyberspace as the ability to adapt to changing conditions and prepare for, withstand, and rapidly recover from disruption."
“The ability to anticipate, withstand, recover from, and adapt to adverse conditions, stresses, attacks or compromises on systems…”
“NIST also states that the cyber resilience discussion is predicated on the assumption that adversaries will breach defenses. This statement is often overlooked and not understood.”
“Cyber resilience is not about protecting the system and preventing the adversary from breaching your systems. It means assuming the system is or will be breached and figuring out what you need to do to continue your mission after the fact.”
“The ability to continuously deliver the intended outcome despite adverse cyber events.”
“The difference between merely surviving a catastrophe and demonstrating resilience in the wake of one is… can be found in two science fiction classics, Terminator and Terminator 2.”
“That's resilience.”
[04:10]
“Cyber resilience is not about protecting the system and preventing the adversary from breaching your systems. It means assuming the system is or will be breached and figuring out what you need to do to continue your mission after the fact.” — Host
[05:40]
“In the second movie...he could take the damage and continue to perform his higher order functions. That’s resilience.” — Host
[05:05]
“Assume that there will be a massive IT failure at some point in the future. Then devise a strategy to ensure that your organization’s essential services will still function.” — Host
This episode is a concise yet powerful guide to understanding resilience in cybersecurity—what it is, why it matters, and how it should change the way organizations think about security planning.