TECH NEWS

What should be done if an AI attack succeeds?

Cyber Resilience in 2026 an ITnation Round table in partnership with HPE and Kyndryl.

June 30, 2026

On 25th June, a group of senior technology and business leaders gathered in Luxembourg to discuss one of the industry’s most pressing topics: cyber resilience.

The timing could hardly have been better. Just days earlier, the US Department of Defense had blocked the use of Anthropic’s latest tools, Mythos and Fable 5, on the basis that they were too effective at identifying flaws in code. In Microsoft alone, more than several hundred weaknesses had reportedly been identified. A phenomenal amount of patching will now be required. On the flip side, do we really want the US government to become involved? What if your entire organisation is using an AI tool based on a model that attracts the unwanted attention or impulsive decision-making of President Trump?

For cybersecurity professionals, the goalposts are moving rapidly. Meanwhile, for many organisations, the uncomfortable reality is that they don’t truly know how resilient they are until something goes wrong.

Melvyn Dias, a senior consultant from HPE commented,

 “A cyber resilient posture requires viewing data protection within a larger framework that spans preventing data loss, detecting and responding to threats, and data recovery. Data protection policies must govern how applications create, store, move, and retain data across hybrid and multi-cloud environments.”

One of the recurring themes during the discussion was that cyber resilience means different things to different people.

For CISOs, who have traditionally been focused on defence, there is now an increasing dialogue with CIOs around the question, “What should be done if an AI attack succeeds?” Infrastructure teams are concerned with backup strategies, immutable storage and disaster recovery. Meanwhile, directors are focused on governance and liability.

“Kyndryl’s perspective is clear” stated, Philippe Bovy, Director & Consult Partner, Kyndryl Luxembourg. “Integrating AI into governance is no longer optional, it is the foundation for securing mission-critical systems in an era where threats evolve at machine speed. Organizations must reframe their strategy—using AI to continuously discover, protect, and respond—while strengthening governance to enable faster, risk-aware decision making”  

 

The introduction of DORA and NIS2 has undoubtedly elevated cyber resilience to the boardroom. Directors now carry greater responsibility for cyber risk than ever before. The challenge, however, is that many board members are not cybersecurity specialists.

Cyber resilience is therefore much broader than cybersecurity alone. It extends beyond software into hardware, infrastructure, data protection and business processes. Organisations still need reliable, immutable backups that cannot be altered or encrypted by attackers. Without them, recovery becomes significantly more difficult.

Within the roundtable, questions included:

  • If your data is replicated across multiple data centres and one suddenly becomes unavailable, which business systems continue to operate? How quickly can they be restored? More importantly, who in the organisation actually knows the answer?
  • Has your organisation already defined which processes are business-critical? If a major incident occurred tomorrow, could your organisation restore them within 24 hours? Many companies confidently assume the answer is yes—until they are forced to test it.

Third-party risk also featured prominently during the discussion, both DORA and NIS2 place on supplier resilience. If a critical supplier suffers a cyberattack, what impact does that have on your organisation? How quickly are they required to notify you? Do your current contracts clearly define responsibilities, recovery expectations and liability?

As cyber threats continue to evolve, contracts, governance and resilience strategies must evolve with them.

The roundtable concluded that cyber resilience is no longer simply a technical challenge. It has become a business issue requiring collaboration between IT, compliance, legal teams and senior management. Technology remains essential, but resilience ultimately depends on preparation, planning and ensuring that the organisation can continue operating when—not if—the unexpected happens.

The discussion highlighted several priorities for organisations over the coming year:

  • Securing and protecting data in an increasingly hostile threat landscape.
  • Developing backup strategies that deliver genuine cyber resilience rather than simply retaining data.
  • Preparing for the emergence of AI-driven attacks and new threat vectors.
  • Aligning infrastructure and operational strategies with the rapidly evolving requirements of DORA, NIS2 and future regulation.
    Watch video

    Share This Story, Choose Your Platform!

    In the same category