惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

H
Hackread – Cybersecurity News, Data Breaches, AI and More
U
Unit 42
Vercel News
Vercel News
Martin Fowler
Martin Fowler
云风的 BLOG
云风的 BLOG
爱范儿
爱范儿
MongoDB | Blog
MongoDB | Blog
J
Java Code Geeks
F
Fortinet All Blogs
MyScale Blog
MyScale Blog
C
Check Point Blog
N
Netflix TechBlog - Medium
Microsoft Azure Blog
Microsoft Azure Blog
aimingoo的专栏
aimingoo的专栏
博客园_首页
WordPress大学
WordPress大学
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
IT之家
IT之家
Last Week in AI
Last Week in AI
罗磊的独立博客
大猫的无限游戏
大猫的无限游戏
Jina AI
Jina AI
V
Visual Studio Blog
小众软件
小众软件

Latest from TechRadar

Quordle hints and answers for Monday, April 13 (game #1540) NYT Strands hints and answers for Monday, April 13 (game #771) NYT Connections hints and answers for Monday, April 13 (game #1037) Morbid Metal developer explains why he ditched an origami art direction in favor of gritty sci-fi — 'It worked, but it didn't really feel like me' '71% of US households get routers from ISPs': Why new FCC rules could leave millions stuck with outdated,… 'The CPU is the system’s executive layer': Intel joins SambaNova as both face existential threat from… ‘More bang for your buck’: 7 easy ways to boost your MacBook Neo’s performance for free DJI Romo P vs Roborock Saros 10R — which robot vacuum comes out on top when it comes to dodging obstacles? I put… I spent 6 hours with Genshin Impact on the Galaxy S26 Ultra, and I can't believe how far mobile gaming has come What is the release date for The Testaments episode 4 on Hulu and Disney+? I reviewed the LG G6 for 3 weeks, and it's a fantastic OLED TV that's the new best option for brighter rooms Is your bird feeder camera doing more harm than good? 3 tips for using it safely as RSPB issues urgent disease warning Chelsea vs Man City Live Streams: How to watch Premier League 2025/26 from anywhere in the world, team news How to watch Alcaraz vs Sinner for FREE: TV Channels for Monte-Carlo Masters Final Sunderland vs Tottenham Live Streams: How to watch Premier League 2025/26 from anywhere in the world, team news Are these the best-designed workout headphones ever? I used them for a month to find out How to watch Snooker 900 John Virgo online (it's free) – stream O'Sullivan vs Higgins anywhere I've only just discovered the Walk With Frodo app on Garmin's Connect IQ store — and as as a huge LOTR nerd, it's going to make the next 1,800 miles fly by 'Just not sustainable': Why your monthly £25 broadband internet bill could soon hit £45 How to watch Paris-Roubaix 2026: Free Streams & TV Info as Tadej Pogacar chases third Monument How to watch Euphoria season 3 online – stream Zendaya & Sydney Sweeney drama from anywhere today '$15K bill destroyed a solo developer’s startup': How hackers are using leaked Google API keys to… There's a sneaky way to watch UFC 327 really cheap... NYT Connections hints and answers for Sunday, April 12 (game #1036) NYT Strands hints and answers for Sunday, April 12 (game #770) Quordle hints and answers for Sunday, April 12 (game #1539) Amazon's Ring cameras are the perfect solution to secure your home on a budget — shop today's best deals… I've tested every iPhone since the iPhone 12, and Ceramic Shield 2 is the first iPhone glass I fully trust UFC 327 live stream: how to watch Procházka vs Ulberg, start time, preview, full card We're officially getting the DJI Pocket 4 on April 16, but here's how Insta360 could beat it
The new cyber gap is response latency
Andreas Malik · 2026-05-25 · via Latest from TechRadar

There is a point in many cybersecurity incidents when the technical side is already moving, but the organization around it is still figuring things out.

The alert has fired off, the communication channel has been established, people are joining from security, IT, operations, legal, perhaps communications, and yet the room is not quite ahead of the incident. It is still trying to decide what sort of problem it is looking at.

Which systems must be isolated first, which data matters enough to protect at all costs, which service has to keep breathing even if the rest of the network goes dark for a while, which vendor or dependency, sitting quietly in the background on an ordinary day, is about to become the turning point for the next six hours. In more organizations than many would care to admit, that knowledge is still too scattered, too informal, or too dependent on the right person being around when the crisis hits.

Founder of Risk & Decision and Resilient24.

That is what makes the present moment more serious than another familiar round of “cyber-panic”. The pace has changed, and it is beginning to expose a weakness that many mature security programs have managed to live with for longer than they should have.

Microsoft warned this month that in some Medusa ransomware campaigns, the time from exploitation of vulnerable web-facing assets to exfiltration and deployment can collapse into roughly 24 hours.

The issue is not simply that this is fast, though it certainly is. It is that a day leaves very little room for an organization to discover, in the middle of an incident, what it should already have known before one began.

Build better firefighters

Organizations are obsessed with building better detectors, “finding the fire faster”, but they fail to build better firefighters — the human process of organizing a response once the “fire” is found. The real failure isn't seeing the threat; it's the chaotic, slow, and confusing process of translating that technical signal into a coordinated business action. Most assume that with a clean dashboard, good controls, and respectable governance language, they are prepared, but in reality, they lose the plot at the handoff when the issues are organizational.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

And that's where the cracks are starting to show. What slows response is often not some grand strategic failure, but an accumulation of smaller, older habits: “criticality” defined too broadly to be useful, escalation paths living in spreadsheets, fallback procedures that looked sensible six months ago, annual tabletop exercises treated almost like a ceremonial ritual, completed as a matter of obligation, then forgotten just as quickly. Then a real incident arrives, fast and badly timed, and the whole arrangement reveals itself for what it is: not quite preparation, more a collection of good intentions that have never been taught to move together.

CISA’s own guidance points in a more serious direction than many organizations have yet taken. It tells organizations to identify and prioritize critical systems and data for restoration, maintain communications plans, and exercise incident response and resiliency plans rather than merely keep them on file. NIST’s revised incident response guidance also advises a concrete approach. An organization should not be making its first real decisions about criticality, continuity, and authority while the incident is already unfolding.

A recent example

A recent public example shows just how far this can reverberate. In the US in April, after a cyberattack disrupted critical systems and digital services in Minnesota, Governor Tim Walz authorized Minnesota National Guard support because the incident had significantly impaired the county’s ability to deliver emergency and municipal services. A cyber incident becomes something else the moment ordinary decision paths, communications, and essential operations begin to wobble.

This is where resilience tends to fail now: at the intersection of technical detection and operational execution. Many organizations have spent real money on tools, monitoring, and governance. Far fewer have already defined which information is truly critical, which systems and vendors are upstream dependencies, which fallback procedures must activate first, and which decisions belong to whom once normal conditions begin to slip. The organization might have all the right tools, but it is still oddly unready to handle its own response.

That is also why the answer is not simply “more security.” It is a more disciplined operating model around response. The first step is continuous information control. Before anything goes wrong, an organization needs to know exactly which data, services, dependencies, and communication paths are truly vital. This isn't about what looks good on paper or fits a checklist for rules; but rather real-world operations. They need to clearly identify: what must be preserved, what can be sacrificed, and what absolutely cannot be allowed to drift into uncertainty for even a few hours.

A way of reducing hesitation

The second step is to treat crisis exercise less as a yearly ritual and more as a way of reducing hesitation. Smaller, lighter, repeatable exercises do more for real response than the grand tabletop that happens once a year and disappears into memory the following week. Teams need to rehearse the decisions that become expensive under compression: who isolates what, who declares what, who speaks to staff, customers, or the public, what gets restored first, and what dependencies will quietly halt the work if no one has mapped them in advance.

The third step is to treat continuity communications as part of response design, rather than a courtesy to be addressed after the technical work has started. In many incidents, communication isn't just something you do after the problem starts. It is actually part of the problem itself. If employees don't know where to go, if external partners aren't sure which contact method is safe, or if leaders are trying to use a system that might be broken, everything slows down. These delays pile up quickly, and no report or chart can fix them later.

The next divide in cyber maturity will not be between organizations that detect and those that do not. Detection has improved. The sharper divide, rather, will run between organizations that can act under compression and those that are still trying to decide what matters while the incident is already moving. That is the real gap now. Not a lack of alerts, but a lack of readiness at the moment when alert has to become action. And that is a more unsettling weakness, because it sits much closer to the center of the organization itself.

We've Reviewed, Rated, and Ranked the Best Firewall Software.

This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.

The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit

Founder of Risk & Decision and Resilient24.