Skip to content
Breaking:

Cyber Resilience Recognized as Distinct Investment Category Amid Soaring Downtime Costs

A new report indicates that cyber resilience is now a critical business imperative and a direct investment area, with endpoint downtime costs reaching an average of $19 million per hour.

By The Company Wire2 min read
Share
Absolute Security — Cyber Resilience Recognized as Distinct Investment Category Amid Soaring Downtime Costs
Absolute Security — Cyber Resilience Recognized as Distinct Investment Category Amid Soaring Downtime Costs. Christy Wyatt speaking at Black Hat.

Cyber resilience is increasingly viewed not merely as a technical function but as an essential business requirement at the executive level, evolving into a dedicated investment category. Organizations that recognize this shift are better positioned to recover more quickly from disruptions, according to Christy Wyatt, President and Chief Executive Officer at Absolute Security.

During Black Hat 2026, Absolute Security released new research highlighting the substantial financial impact of downtime. The study, which surveyed 1,000 Chief Information Security Officers (CISOs), found that the average cost of one hour of endpoint downtime is $19 million. Despite this significant figure and growing awareness, only 4% of the surveyed professionals felt adequately prepared to recover from a major cyber incident.

Wyatt emphasized the staggering financial implications, stating that the average $19 million per hour cost across the surveyed CISO community underscores the critical need to minimize downtime. This metric provides a quantifiable measure for assessing efforts to enhance cyber resilience.

Speaking with Krista Case on theCUBE, SiliconANGLE Media’s livestreaming studio at Black Hat USA, Wyatt discussed the emergence of cyber resilience as a distinct market category. The conversation also touched upon the expanding role of CISOs, who are now responsible for recovery strategies in addition to preventative measures, and the characteristics that differentiate organizations capable of rapid recovery from those that struggle.

Many organizations conduct tabletop exercises that conclude at the containment stage, focusing on identifying and remediating threats. However, these exercises often neglect to simulate the complete recovery process, such as bringing 5,000 compromised devices back online while maintaining business operations. Consequently, crucial steps like ensuring minimum viable operations, establishing communication protocols, and developing device recovery workflows are often overlooked, leading to failures during actual incidents.

Wyatt posed a critical question for organizations: what would happen if 60% of their endpoint devices were compromised overnight? She stressed the importance of personnel knowing their roles, communication channels, and procedures in such a scenario.

Absolute Security's approach to endpoint security resilience utilizes a firmware-embedded technology called Persistence. This technology is integrated into hardware from 28 PC manufacturers, covering the majority of enterprise laptops deployed over the past two decades. Persistence acts as an anchor, enabling the platform to access a device regardless of its software state. It facilitates forensic data collection, restores network connectivity, and performs remote, bare-metal reinstallation without requiring the device to be physically returned to IT.

The objective of this technology is to reduce recovery times from weeks to mere minutes. Wyatt illustrated the difference: instead of IT instructing a user to ship back a potentially compromised laptop, the system can remotely pull forensics and perform a bare-metal reinstall, allowing the user to be operational again within 25 minutes.

Wyatt noted that boards, having achieved cyber fluency, must now move beyond simply assessing risk posture to understanding the operational implications of a major cyber event. While the CISO increasingly manages both recovery and prevention, the Chief Financial Officer, Chief Information Officer, general counsel, and the board itself all play vital roles. Research indicates that over 72% of CISOs have already broadened their responsibilities to include overseeing cyber resilience. Wyatt advocated for a shift in boardroom discussions from rehearsing for a cyber event to practicing overall resilience, ensuring these plans are documented, practiced, and rehearsed.

Sources

  1. SiliconANGLE report

Company: Absolute Security

Written by

The Company Wire

Newsroom · San Francisco

Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.