Tip

Why cyber resilience fails: 5 obstacles holding orgs back

Technical debt, cybersecurity skills shortages and identity risks are among the challenges that can make it difficult for an organization to achieve cyber resilience.

Every organization wants to be cyber resilient, with the ability to withstand attack, maintain operations and reduce risks overall. But desire and reality are two different things. Despite the best intentions of management and IT staff, true cyber resilience is often more of an idealistic goal than an on-the-ground fact.

"Even with leadership support and adequate resources, resilience can break down in the space between strategy and day-to-day operations," said Scott Beale, CEO of ISC2.

The following are five all-too-common obstacles to cyber resilience that experts say plague organizations across industries.

Skills shortages and stretched teams

The most prevalent and obvious obstacle to cyber resilience is that most organizations just don't have enough skilled professionals to succeed.

In the "2025 ISC2 Cybersecurity Workforce Study," 95% of organizations reported missing at least one cybersecurity skill, and 59% described that need as critical or significant. Similarly, the World Economic Forum's "Global Cybersecurity Outlook 2025" survey found that only 14% of organizations are confident they have the people and skills they need.

Budget is likely a contributing factor to why resilience work lags, but Beale said the real issue is time.

"Without time that is deliberately protected, development will almost always be displaced by the next urgent task," he said. "That creates a dangerous gap between having a resilience plan and having people who are prepared to carry it out."

Workforce readiness needs to be a formal part of the resilience strategy from the beginning. "For every investment in technology, organizations should also be asking what skills their people need, who owns the critical decisions and whether teams have practiced working together under pressure," Beale said.

Technical debt and legacy systems

Technical debt is a challenge that is hard to overcome. It accumulates over years through acquisitions, staff turnover and incremental fixes.

"Nobody sat down and designed the environment most organizations have today," said Craig Birch, technologist evangelist and principal security engineer at Cayosoft, an identity software vendor. "You're left with standing privileges, undocumented dependencies and systems people are afraid to touch because no one is quite sure what will break."

Replacing infrastructure like that is disruptive to the very processes it supports, which keeps it near the bottom of the priority list.

"Most organizations are running critical processes on infrastructure that was never designed with today's threat landscape in mind," said Matthieu Chan Tsin, senior vice president and general manager of resiliency services at Cowbell, a cybersecurity advisor and insurer.

Often, a quick fix can solve a problem, but only a full overhaul eliminates debt.

"If something is broken, it's easier to justify the fix and associated spend than doing the same for something that may not break for years but will take years to implement," said Chris Hickman, chief security officer at cybersecurity company Keyfactor.

Unfortunately for resilience goals, each individual purchase looks rational at the time it is made.

"There is a near-term problem, and there is a product that solves that specific problem," said M.K. Palmore, founder and principal advisor at Apogee Global RMS. "The trap is that a portfolio of point-in-time, rational decisions produces an architecture nobody would ever design on purpose."

Palmore said the way to fix technical debt is to avoid answering today's challenge with half-baked solutions that address only the narrow problem they were bought to solve. Instead, Palmore said, "Evaluate every acquisition against where the environment is headed, not just the pain of the moment."

Third-party and supply-chain risk

Modern IT environments rely on third-party services that inevitably introduce supply chain risk factors that complicate cyber-resilience efforts. Often the only insight an organization has into its supply chain risk is an annual suppliers' questionnaire.

"Questionnaires offer zero visibility into real-time risk," said Chris Teekema, head of managed detection and response at BlueVoyant, a managed security provider.

A company's dependency chain extends well past its formal vendor list. This makes the full chain difficult to see.

"Your resilience is ultimately constrained by every critical dependency required to operate the business," said Heath Renfrow, co-founder at Fenix24, a disaster recovery service provider.

When a partner or technology has not been audited, it's extremely difficult to identify an exposure. "An organization can harden what it controls directly but may still inherit exposure through a partner it doesn't control and can't fully audit," said Shane Barney, CISO at Keeper Security, an identity management vendor.

Reducing supply chain risk is an active process that goes beyond annual questionnaires. "Resilience isn't a checkbox you clear once leadership signs off. To be effective, it must be an ongoing set of behaviors," Chan Tsin said.

Identity sprawl and ungoverned access

As the gateway to an organization's information, identity is a lynchpin for cyber resilience.

Organizations have many security and resilience controls to address identity risks, but if one compromised identity enables unauthorized access, controls aren't going to be effective. "A single compromised identity yields the same blast radius that used to require a network-wide ransomware deployment," Teekema said.

The identity problem is becoming increasingly difficult to solve because AI agents and automated workflows are being added quickly, often before anyone has determined who owns them or how to govern their access. "These identities can hold delegated permissions, cross system boundaries and make changes far faster than a person could," Birch said.

The key to overcoming this obstacle is to prevent ungoverned access. "Modern cyber resilience begins with understanding who and what has access to what, and, more importantly, how could malicious activity obtain additional unwarranted privileges," said Morey Haber, chief security advisor at identity security company BeyondTrust.

Unvalidated plans and untested readiness

Organizations often discover they aren't resilient when systems fail and their cyber-resilience plans didn't deliver. Resilience efforts might look good on paper, but they don't always hold up in the real world.

"The biggest problem I see is that organizations still confuse cybersecurity with cyber resilience," Renfrow said. "They spend enormous amounts of money trying to prevent an incident, but comparatively little effort proving they can operate and recover when prevention fails."

Security teams might conduct tabletop exercises, but those don't fully test operational resilience.

"An organization has backups, a recovery plan and a tabletop exercise on the calendar, so everyone feels reasonably prepared," Birch said. "The real test comes when identity is compromised, key systems are unavailable and the attacker may still have a foothold. A plan that has never been tested under those conditions can give people a dangerous amount of confidence."

Real resilience, he said, requires proper testing. "Organizations need to practice recovery under realistic conditions, map the dependencies between systems and give identity recovery the same attention they give data and infrastructure," Birch said. "They also need a clear way to check for attacker persistence before employees and customers begin relying on the environment again."

Being cyber resilient is more than just about having a recovery plan and a strategy that a CISO can present to the board.

"Stop treating resilience as a document," Renfrow advised. "Start treating it as a measurable operational capability."

Sean Michael Kerner is an IT consultant, technology enthusiast and tinkerer. He has pulled Token Ring, configured NetWare and been known to compile his own Linux kernel. He consults with industry and media organizations on technology issues.

 

Dig Deeper on Enterprise Risk Management