Article

The Great Shift: From Prevention to Cyber Resilience

By August 26, 2026August 27th, 2026No Comments
By Keith McCloskey,
Vice President, National Security

For a long time, prevention was the gold standard in cybersecurity. But as the threat landscape accelerates due to AI and other technologies, federal leaders face a new reality: it’s not a matter of if, but when an organization faces a breach. The goal now is to ensure your most critical functions continue to operate and persist when facing the inevitable.

Today, cyber resilience, or the ability to quickly absorb, adapt, and recover from an attack, is the guiding North Star, and driving resilience across your organization means making smart, risk-based and proactive decisions across four key areas:

  1. Identifying critical functions – How do you prioritize your resources and systems?
  2. Proactive threat mitigation and secure design — How do you design and protect your systems?
  3. Operational resilience — How do you keep operations running when things go wrong?
  4. Governance — How do you properly manage cyber risk?

1. Identifying Critical Functions

Organizational resilience starts with understanding which operations and systems are truly critical and making resource decisions based on live, exploitable risk rather than static inventories. That means staying sharp across the following areas:

Dynamical High Value Assets (HVA)

Identifying an HVA (under OMB M-19-03) is not a one-time compliance exercise. Under the new CISA frameworks, asset criticality is highly dynamic. If a critical database is suddenly exposed to the internet, its risk profile and remediation timeline accelerate instantly.

Why It Matters

  • Forces continuous monitoring of critical infrastructure posture, rather than relying on annual audits
  • Prepares for future mandates: Aligns with the 2026 Executive Order on Post-Quantum Cryptography (PQC), mandating HVAs and high-impact systems transition to quantum-resistant encryption by 2030
  • Prioritized resource allocation: Ensures security budgets and zero trust deployments target the systems that would cause mission failure if breached

Risk-Based Vulnerability Management

Attackers use AI to weaponize vulnerabilities in hours, meaning static Common Vulnerability Scoring Systems (CVSS) scores and rigid 14-day patching windows can’t keep up. Released June 10, 2026, BOD 26-04 requires agencies to prioritize remediation based on four real-world factors: public exposure, known exploitation, exploit automation, and technical impact.

Why It Matters

  • Shrinks the window: Mandates a 3-day remediation window for critical, internet-facing vulnerabilities
  • Actionable mitigation: Recognizes that taking a system offline or applying a compensating control counts as a valid immediate response to stop the 3-day clock while a formal patch is tested
  • Forces rapid intelligence: Agencies must operate on an “assume compromise” basis for internet-facing edge devices

Complete Network Visibility (OT and IoT)

You cannot prioritize what you cannot see. Issued May 22, 2026, OMB M-26-14 requires agencies to bring Operational Technology (OT) and Internet of Things (IoT) devices fully into their cybersecurity and logging programs.

Why It Matters

  • Expands the definition of critical infrastructure beyond data centers to include physical controllers, building systems, and edge devices
  • Agencies have until July 2027 to meet the new Logging Reference Architecture (LRA) maturity levels, demanding 100% visibility of the attack surface
  • Failing to log OT/IoT assets makes compliance with BOD 26-04’s triage requirements impossible

2. Proactive Threat Mitigation and Secure Design

The old “detect and respond” playbook has expired, and the agencies currently pulling ahead on cyber risk resilience are building security into their systems and supply chains from the start by:

  • Implementing Content Disarm and Reconstruction (CDR) technology
  • Sourcing with Software Bills of Materials (SBOMs)
  • Future-proofing their encryption through Post-Quantum Cryptography (PQC)

Content Disarm and Reconstruction (CDR)

Traditional antivirus works by checking files against known threats. The problem? Sophisticated attackers won’t allow themselves to be listed in the first place.

CDR flips the script by assuming every file could be malicious, stripping it to safe components, and rebuilding a clean version in milliseconds.

Why It Matters

  • Bypasses zero day exploits and advanced persistent threats (APTs) that evade detection-based tools
  • A zero trust must-have for agencies handling cross-domain transfers or high volumes of external documents
  • CDR doesn’t need to know what the threat is — it removes the risk entirely

Software Bills of Materials (SBOMs)

Are you aware of all the software used by your agency (and your vendors)? SBOMs answer this question and advance cyber risk management by providing a comprehensive inventory of all your software dependencies.

Why It Matters

  • CISA’s updated 2025 SBOM guidance adds component hashes, license data, and generation context to the original 2021 framework
  • Agencies not building SBOM practices now will be playing catch-up when contract requirements arrive

Post-Quantum Cryptography (PQC)

The quantum threat is no longer a future hypothetical, with “Harvest now, decrypt later” attacks (where adversaries collect encrypted data today to decrypt once quantum computers mature) an active cyber risk management concern.

Why It Matters

  • NIST finalized its first three quantum-resistant standards in 2024
  • Federal deadlines are set: vulnerable algorithms deprecated by 2031, fully disallowed by 2035
  • Migrations of this scale take years, so start building your cryptographic inventory now

3. Resilient Operations and Recovery

The real test of operational and cybersecurity resilience is how fast you spot an incident, contain it, and keep mission-critical operations running. Strengthening cyber incident response will require cyber teams to rethink authorization, reporting, and readiness moving forward:

Authorizations: Moving to Continuous ATO (cATO)

A traditional ATO cycle that takes 6 to 18 months and repeats every three years leaves agencies perpetually behind the threat curve. cATO shifts to an ongoing, real-time view of your security posture.

Why It Matters

  • Over 50 DoW software factories are already delivering code under DevSecOps practices that make cATO viable
  • Authorization becomes a living practice rather than a document that ages on a shelf
  • Federal civilian agencies are catching up — cATO is no longer just a DoW conversation

Incident Response Reporting

The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) rule is still being finalized, but the core obligations are already law, meaning the window to prepare your cyber incident response plan is now.

Why It Matters

  • Covered entities must report significant cyber incidents within 72 hours and ransomware payments within 24 hours
  • Use the pre-enforcement period to clarify ownership, map your escalation chain, and stress-test your legal review process

Tabletop Exercises: Ensuring Readiness

Exercises covering ransomware, phishing, insider threats, and other scenarios can greatly improve cyber resilience and sharpen real-world cyber incident response.

Why It Matters

  • Adversaries are using AI to move faster and probe defenses at a larger scale than before — your scenarios need to reflect that
  • Tabletop exercises provide auditable evidence of rehearsed response increasingly required by regulators and cyber insurers

4. Governance

Good security doesn’t run itself.

Deploying the right tools and processes only matters if there’s clear accountability behind them. Governance is what connects individual security investments into a coherent, organization-wide strategy, and that means elevating cyber risk management to a leadership conversation across two fronts: unified risk operations and data governance.

Unified Risk Operations

Most agencies manage cyber risk in fragments, with teams handling compliance, threat monitoring, and incident response in silos. Unified Risk Operations brings those functions together into a single operational view, providing leaders with the full picture when making vital decisions.

Why It Matters

  • NIST CSF 2.0’s “Govern” function formally establishes cybersecurity risk management as an enterprise-level leadership responsibility
  • Siloed risk functions create blind spots while unified operations ensure that a threat detected in one part of the agency doesn’t fall through the cracks
  • Cross-agency risk harmonization is increasingly expected under the National Cybersecurity Strategy’s push to reduce duplicative and conflicting federal requirements

Data Governance

Agencies without clear policies around what data they hold, where it lives, and who can access it are flying blind when assessing the real impact of an incident.

Why It Matters

  • AI adoption is expanding agency data footprints faster than governance policies can keep up
  • Clear data classification directly accelerates incident response — you can’t scope a breach you can’t map
  • Data governance isn’t just a security issue, but a mission continuity issue, especially for agencies handling sensitive or national security data

Building cyber resilience isn’t about checking boxes. It’s about building organizations that are genuinely hard to disrupt and recover quickly when the inevitable disruption comes.

Need further assistance on building your organization’s cybersecurity resilience strategy?

Contact Our Experts

Enjoy Everforth ECS Articles Like This One?
Don’t Miss Any.

Share
WE'RE HIRING