<!-- mobian-agent-page publisher="time" canonical="https://time.com/branded-content/commvault/move-fast-and-stay-secure-the-power-of-resilience/" -->

---
description: Breaking news and analysis from time.com. Politics, world news, photos, video, tech reviews, health, science, and entertainment news.
title: Move Fast and Stay Secure: The Power of Resilience
image: https://static.time.com/v3/assets/bltea6093859af6183b/blt35b3d3cee2a346a0/6a4b5228d2f3f959e9974078/toLya4FIqN_2kh3ei.png?branch=production&amp;width=3840&amp;quality=75&amp;auto=webp&amp;crop=16:9
---

# Move Fast and Stay Secure: The Power of Resilience

![](https://static.time.com/v3/assets/bltea6093859af6183b/blt35b3d3cee2a346a0/6a4b5228d2f3f959e9974078/toLya4FIqN_2kh3ei.png?branch=production&width=3840&quality=75&auto=webp&crop=3:2)

Enterprises are moving faster than at any point in modern history. Artificial intelligence is reshaping operations, cloud migration is accelerating, and digital transformation has shifted from a strategic initiative to a baseline expectation. But that speed has a cost. According to Accenture, 77% of organizations lack essential data and AI security practices, and 90% lack the maturity required to defend against AI-enabled threats. The Cloud Security Alliance paints a similarly sobering picture: when organizations are assessed across the full spectrum of resilience capabilities, including governance, incident response, recovery planning, identity management, and third-party risk, just 2% meet the threshold for maturity across all critical areas. Most enterprises have made progress in some of these domains. Very few have connected them into a cohesive whole.

The result is what resilience experts now call the _resilience gap_: the distance between how fast technology evolves and how slowly most organizations can respond when something goes wrong. Business leaders are pushing for innovation. Security leaders are managing an attack surface that expands with every new tool, integration, and cloud environment. Disruption is no longer an edge case. It is the operating environment.

For decades, the cybersecurity playbook was straightforward: build the wall higher, invest in defense, keep the adversary out. That work remains essential. Prevention has not lost its importance; it has gained a partner. A new generation of security leaders recognizes that defense and recovery are not opposing priorities but complementary capabilities, both tied directly to business outcomes. The strongest programs invest in both, understanding that the ability to prevent attacks and the ability to recover from them are two sides of the same operational discipline. That shift is at the heart of the [TIME + Commvault CISO of the Year program](https://www.commvault.com/time-ciso-of-the-year-2026?utm%5Fsource=time&utm%5Fmedium=paid-article&utm%5Fcampaign=ww%5Fbrnd&utm%5Fcontent=text-link "undefined"), which recognizes the leaders who are redefining resilience as a core business capability.

![Close-up of a bald man with blue eyes wearing a light blue collared shirt, smiling slightly.](https://static.time.com/v3/assets/bltea6093859af6183b/blt8fe3891803842751/6a4b5228503bda2c9bcbaf50/52ZUz01cgr_2kh3ei.jpg?branch=production&width=3840&quality=75&auto=webp)

## 

## From Defense to Resilience

Bill O’Connell has spent two decades in security leadership, from healthcare, where patient lives depend on system uptime, to his current role as Chief Security Officer at Commvault. He has watched the CISO role transform from a back-office function to a boardroom priority. Early in his career, he recalls, one company’s security team was housed in a building across a field from headquarters. “Talk about not having a seat at the table,” he says. “Security was kind of an afterthought, and they were physically removed from the day-to-day work.”

That era is over. Today, CISOs increasingly report directly to the CEO. They sit on leadership teams and shape strategic decisions. Customers and regulators alike demand it. But O’Connell believes the most important evolution isn’t organizational. It’s philosophical.

“I like to use the analogy of a boxer. A boxer’s strategy is not to never get punched in the face. That is not a good long-term strategy,” he says. “You really need to make sure that you have good defense, but that you’re also adept and have practiced: how do I get back up?”

The point is not that prevention has failed. It is that prevention alone is not sufficient. The best security leaders today, O’Connell argues, integrate both capabilities: rigorous defense and practiced recovery, working in concert. They are judged not only by the attacks they stop but by how quickly their organizations restore operations and continue serving the customers who depend on them.

## An Operating Model for the Inevitable

This evolution in thinking has a name: ResOps, short for Resilience Operations. Just as DevOps redefined how software is built and delivered, ResOps establishes the discipline required to safeguard, govern, and restore trust in data-driven businesses. 

ResOps is an operating model that connects and optimizes people, processes, and technology across security, IT, and the business to improve readiness and minimize the impact of threats and attacks. It brings together functions that have traditionally operated in silos, including identity containment, regulatory coordination, third-party risk management, data protection and recovery, and crisis communications. The need for this type of model has never been more critical given the frequency of attacks and threats. 

“The best and most modern mindset a CISO can have is assuming that a disruption is inevitable,” he says. “It’s not an if, it’s a when.”

In practice, when the ResOps model is deployed successfully, and an attack takes place, a key outcome is being able to function as what’s often referred to in the industry as a “minimum viable company.” This involves tight coordination and pre-planning between teams during good times so businesses are prepared for the bad times. 

For example, there needs to be agreement in advance on the first five or ten systems that must come back online for the business to function. It means pressure-testing recovery plans through drills and simulations regularly, not once a year as a compliance exercise. And it means breaking down the walls between IT, security, and business operations so that every team, from legal and communications to vendor management and identity governance, is working from the same playbook when a disruption occurs.

O’Connell compares the discipline to physical fitness. “If you want to be fit, you’ve got to go to the gym. You have to work on this on a regular basis,” he says. “If you’re not putting that time and effort in, then when that disruption happens, you’re not going to be able to move fast.”

That preparation is the difference between an organization that goes dark for weeks and one that stands back up before the dust settles. The ResOps model makes this kind of readiness intentional, measurable, and continuous, operating as an ongoing loop: discover and protect critical data, detect anomalies in real time, recover with speed and integrity, then validate and improve. The goal is not to eliminate risk entirely. It is to know, through evidence, that the business can meet its recovery expectations under real stress.

---

> “The best and most modern mindset a CISO can have is assuming that a disruption is inevitable. It’s not an if, it’s a when.”

Bill O’Connell**Chief Security Officer, Commvault**

---

## AI, Speed, and the Case for Confidence

Nowhere is the resilience gap more visible than in the race to adopt artificial intelligence. AI is accelerating innovation and risk simultaneously, creating new categories of threat while offering powerful new tools to defend against them. O’Connell frames the challenge in three parts: securing AI systems themselves, using AI to strengthen security operations, and defending against AI-powered attacks from adversaries engaged in what he calls “an arms race.”

Securing AI goes beyond protecting models from manipulation. As adoption accelerates across the enterprise, organizations must also account for data lineage, ensuring they know where training data originates and how it flows through AI pipelines. They need usage controls that govern which data AI agents can access, and oversight frameworks that maintain accountability as automated decisions scale. Without these layers of governance, AI adoption introduces risk faster than security teams can contain it.

But in O’Connell’s view, the CISO’s most important role in this era is not to slow the organization down. It is to give it the confidence to move forward. “Not the team that says no, but the team that says yes, and here’s how,” he says, “so that they can make use of the most cutting-edge technology for good.” When resilience is embedded in operations rather than bolted on as an afterthought, businesses gain the freedom to innovate boldly, adopt AI at scale, and move to the cloud without hesitation.

## Setting the Standard

The TIME + Commvault CISO of the Year program exists to recognize the leaders who embody this new standard. It seeks CISOs who deliver business outcomes rather than checking technical boxes, who build bridges across teams rather than reinforcing silos, who prove readiness through practice rather than promises, and who lead with confidence rather than fear.

These are the principles at the core of the ResOps manifesto: business outcomes over technical defense, teams over silos, proof over promises, readiness over perfection, confidence over fear. Together, they represent a vision for what cybersecurity leadership looks like when defense and resilience work as one.

As the threat landscape evolves and AI reshapes every industry, the organizations that thrive will not be the ones that built the highest walls. They will be the ones whose security leaders invested equally in prevention and recovery, treating them as inseparable parts of the same mission. The ones who put in the time, built the muscle, and practiced long before they needed to. The ones who understood that in a world where disruption is certain, the only real question is how fast you can get back up.

[Learn more](https://www.commvault.com/time-ciso-of-the-year-2026?utm%5Fsource=time&utm%5Fmedium=paid-article&utm%5Fcampaign=ww%5Fbrnd&utm%5Fcontent=text-link)

Move Fast and Stay Secure: The Power of Resilience

```json
[{"@context":"https://schema.org","@type":"NewsArticle","@id":"https://time.com/branded-content/commvault/move-fast-and-stay-secure-the-power-of-resilience/","mainEntityOfPage":{"@type":"WebPage","@id":"https://time.com/branded-content/commvault/move-fast-and-stay-secure-the-power-of-resilience/"},"headline":"Move Fast and Stay Secure: The Power of Resilience","datePublished":"2026-06-18T14:28:21.257Z","dateModified":"2026-06-02T20:57:47.451Z","description":"","url":"https://time.com/branded-content/commvault/move-fast-and-stay-secure-the-power-of-resilience/","keywords":[],"thumbnailUrl":"","author":[],"articleSection":"","image":[],"publisher":{"@type":"Organization","name":"Time","url":"https://time.com/","logo":{"@type":"ImageObject","url":"https://time.com/images/logo.png","width":528,"height":156},"foundingDate":"March 3, 1923","sameAs":["https://www.facebook.com/time","https://www.instagram.com/time/?hl=en","https://twitter.com/time","https://www.pinterest.com/timemagazine"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"item":{"@id":"https://time.com/branded-content/commvault/move-fast-and-stay-secure-the-power-of-resilience/","name":"Move Fast and Stay Secure: The Power of Resilience"}}]}]
```
