Five things organizations get wrong about cyber resilience

Cybersecurity budgets keep growing. And with that, so do breaches. As we have interviewed a number of service providers in the past several months, here’s five reasons why most organizations are still getting it wrong — whether it comes to tech stack or all-in investments.

1. Confusing more tools with better protection

The instinct when facing a new threat is to buy something. Another platform, another layer, another vendor. The result is a security stack that’s technically comprehensive and operationally unmanageable. According to recent research, nine out of ten IT leaders already acknowledge gaps in their ability to defend against AI-driven threats — not because they lack tools, but because those tools don’t work together. Coverage without coordination isn’t resilience. It’s noise.

2. Assuming offline devices are someone else’s problem

Conventional endpoint security depends on an active operating system and a network connection. The moment a device is powered off, lost, or stolen, it disappears from visibility. In regulated industries — banking, healthcare, government, BPO — that blind spot isn’t an inconvenience. It’s a compliance exposure. Devices that fall outside the reach of traditional management tools can still carry sensitive data, and “we couldn’t see it” is not a defensible answer to the National Privacy Commission.

3. Treating resilience as an IT issue, not a business one

The DICT’s National Cybersecurity Plan 2023–2028 names cyber resilience as a national priority. The NPC requires personal information controllers to maintain incident management policies and file annual security incident reports. At this point, cybersecurity isn’t an IT department conversation — it’s a business continuity, legal, and boardroom conversation. Organizations that still silo it under IT are structurally unprepared for what a serious incident actually costs.

4. Fragmenting accountability across too many vendors

When something goes wrong, who’s responsible? In most organizations, the honest answer is: it depends, and that coordination takes time. Security operations spread across multiple vendors, platforms, and support teams means that incident response becomes a project management problem before it becomes a technical one. Every handoff is time lost — and in a breach, time is the variable that determines how bad it gets.

As an example, this is the gap Lenovo’s expanded Security Services portfolio is directly addressing. Rather than adding another tool to the stack, the approach pulls devices, security technologies, managed services, and ecosystem partners — Absolute, Cisco, Microsoft, SentinelOne, among others — under a single operational model with one accountable relationship. The claimed results are a 50% reduction in system downtime and 40% lower remediation costs, figures that become a lot more meaningful once you’ve lived through an incident where half the morning was spent figuring out which vendor to call first. For Philippine enterprises in banking, healthcare, and BPO — sectors where downtime has direct regulatory consequences — that kind of consolidation is worth a hard look. ThinkShield TraceLock, the newer addition to the portfolio, extends that visibility to offline and disconnected devices using built-in cellular connectivity, closing one of the more persistent blind spots in conventional endpoint management.

5. Underestimating how fast the threat has changed

AI-assisted attacks are not a future problem. They’re the current baseline. Threats are faster, more targeted, and better at exploiting the gaps between security tools than they were even two years ago. Organizations that built their security posture around yesterday’s threat model are already behind. Resilience now means assuming that something will get through — and having the architecture to detect, contain, and recover before the damage compounds.

(Note: This article was written with the help of some AI tools, alongside editorial oversight)