After the Attack: Building Cyber Resilience Through Practice 

Expert: Jason Balser

Published: September 22, 2026

I was reading my book on the train. The older gentleman walking by tripped and fell hard onto his right side. Before I could even gasp, a man from three rows away leapt into the aisle to assist him. Luckily, he was OK and probably just quite sore the next day. 

I wondered how (and why) the other man had reacted so quickly. I was closer to the man who’d fallen, but I hadn’t immediately reacted. Was he just a better person than me? Was he more caring? Not necessarily. It turned out he was an experienced EMT. It’s what he was trained to do. It was his default reaction. 

No matter how well-intentioned I might have been in that moment, I would never have been able to react as quickly and decisively as he had. 

We recently posted a blog about how to protect our digital supply chains. We all know that preventing cyber disruptions is the ultimate goal and something we must remain diligent about. 

We also know that not every attack can be prevented and our default behavior in those instances determines how well we can respond and recover. 

What does your organization absolutely have to be able to do? 

Understanding what absolutely has to continue is the starting point for cyber preparedness. When an attack happens, is your organization’s default behavior designed to just restore systems as quickly as possible, or to prioritize the systems and capabilities the mission depends on? 

For a government agency, the answer should probably lean more toward protecting mission outcomes like processing benefits, screening passengers, supporting emergency responses and protecting sensitive information. 

When an incident occurs, the organization needs to instinctively know what matters most and understand what immediate actions need to happen. 

What Is Your Default Response? 

Most organizations have incident response plans and continuity plans. But there is a difference between having a plan and being prepared. 

A plan defines what people are supposed to do. Preparedness means they know what to do when the situation doesn’t unfold exactly according to the plan. They understand what the priority is and can make the right decisions in the moment. When people are under pressure, they tend to fall back on what is familiar. 

The question is whether your organization’s default response is to follow the paper plan or whether the organization has developed a deeper instinct around protecting the mission. 

And that instinct has to exist across the organization. A major cyber disruption may start with the IT team, but its impact races across program operations, leadership, communications and even outside vendors. Each of those groups needs to understand its role in the response and how its actions affect everyone else’s ability to keep the mission moving. 

Know What the Mission Depends On 

If a critical system disappeared unexpectedly, what would stop? 

What data would employees still need access to? Which vendors would matter most? What processes could continue manually? Which functions could wait a day and which ones couldn’t wait an hour? 

Answering those questions helps to uncover dependencies that aren’t always obvious from a checklist or an asset inventory, and you want to know the answers in advance, before the attack occurs. 

The goal is to understand the people, processes, data, technology and outside partners that have to come together to deliver your most important outcomes. 

Practice Until the Response Becomes Familiar 

One of the best ways to expose those dependencies and build preparedness across the organization is to practice. 

There is an established methodology for doing this. FEMA’s Homeland Security Exercise and Evaluation Program, or HSEEP, uses a continuous exercise cycle: design and develop an exercise, conduct it, evaluate what happened and use what you learned to improve. Then you do it again. The purpose is to continually build and improve the capabilities needed to accomplish the mission. 

We already see that approach applied in high-stakes transportation environments. TSA’s Exercise Information System, or EXIS, helps transportation organizations plan, conduct and evaluate security exercises and is aligned with HSEEP. The idea is to create a realistic situation, bring together the people who would have to respond and work through the scenario. 

Done often enough, those exercises build familiarity with how the organization thinks and responds. You plan, practice, find the gaps, improve and practice again. Over time, you start to elevate the organization’s default behavior in a crisis. 

Five-step cyber resilience framework centered on protecting the mission: confirm what matters, map dependencies, practice the response, introduce the unexpected, and evaluate and improve.

Making the Unexpected Part of the Exercise 

AI creates some interesting possibilities here as well. Traditional exercises are often built around predetermined scenarios. AI can help make them more dynamic by introducing new complications based on the decisions participants make. 

In this case, AI’s unpredictability can be an asset. It can introduce plausible but unexpected situations and complications that you might never have thought of. These scenarios don’t focus on mastering one particular scenario. They are designed to help you develop a pattern of reaction and awareness that can be applied when something unexpected occurs. 

Elevating the Default 

The EMT on the train didn’t know someone was going to fall that morning. He certainly hadn’t practiced that exact situation. 

But he had practiced responding to emergencies. He understood what mattered. His training gave him a starting point, and when something unexpected happened, he reacted instinctively. 

Organizations can do the same thing. We can’t anticipate every cyberattack or every disruption to our digital supply chain. We don’t know exactly where the failure will occur, but we can know what we’re trying to protect and understand what the mission depends on. 

The goal is to prepare the entire organization in advance so that when something goes wrong, protecting what matters most doesn’t have to be figured out in the moment. It becomes the organization’s default behavior. 

Learn more about the Expert

Jason Balser - Senior Director of AI & Data Strategy

Jason Balser

Jason Balser is a technology executive and trusted advisor with more than two decades of experience […]

×