News

Building security awareness increases risk resilience

Steve Durbin
Published 10 - September - 2026
Read the full article on Digital Insurance
riskdigital insurance

Leadership changes happen everywhere. Scenarios can differ, but it might result in a strategic pause. Stakeholders wait to see what happens next. But risk management can’t afford such a pause. Distraction creates the conditions attackers look for.

During any transition, the safe move is to protect what is working, rather than rushing to change it. This is a typical new leadership problem, where, in an effort to show quick progress, security processes are altered at a time when no one is fully in control. But uncertainty, regardless of cause, surfaces gaps in the risk posture that need to be addressed.

1. The awareness gap: Employees remain one of the most frequently exploited parts of an organization’s security environment, with the human element involved in many of the breaches. The question that should be asked here isn’t whether all employees have access to the technology they need, whether a device, an app, or an account. This gap is simple enough to fulfill. What is difficult to bridge is security awareness. For instance, an employee that uses AI without a clear understanding of what not to share is wading into shark waters.

2. The skills gap: Risk managers and security professionals are in short supply, with organizations admitting their resilience goals are negatively impacted because of this skills gap. The problem is also one of perspective. Organizations are looking at cyber roles purely from a technical lens. Good professionals are those who also notice patterns others may miss and think out of the box about how a system can be protected. They can also assume the attacker’s position to imagine how a system might be compromised.

3. The trust gap: Building cyber-risk resilience is not an individual affair. It often involves trusting people and organizations out of your control. The foundation behind active intelligence-sharing alliance network depends on every partner investing effort. When that doesn’t happen, trust issues surface. The same gap shows up during acquisitions. Buyers often accept a target company’s assurances about its data and cyber posture at face value, without independently checking whether those claims hold up.

4. The implementation gap: Systems that comprise ambitious technology projects must talk to one another and share data. But often they don’t. Stakeholders don’t have clear visibility of what data exists, where it lives, or who can access it. This makes data protection all the more challenging.

Building security awareness increases risk resilience
Read the full article on Digital Insurance