The theme of this year’s Cybersecurity Awareness Month, making cyber criminals’ lives more difficult, reflects one of the most effective ways to improve cyber resilience. No organisation can prevent every attack, and as AI enables attackers to scale and refine their tactics, the threat is unlikely to disappear.
Cyber criminals often target high-value sectors such as manufacturing and financial services, where downtime can quickly lead to operational disruption and significant financial losses. Organisations that make it harder to cause disruption become less attractive targets, strengthening the resilience of their industries as a whole. This starts with security fundamentals, including endpoint protection, cloud security controls, employee awareness training, email security and firewalls, all of which increase the effort required to compromise a network.
However, attackers also rely on disruption and the pressure created by prolonged outages. In many cases, the operational and financial impact of downtime is what drives organisations to consider paying a ransom. Maintaining secure, isolated or air-gapped copies of critical data can significantly reduce that leverage by providing a trusted recovery path, even if production systems and connected backups have been compromised.
A well-tested incident response plan is equally important. Organisations should know who is responsible for decisions, how incidents will be contained and communicated, and how critical services will be restored. Regular exercises help identify gaps before an attack occurs and ensure that teams can respond quickly under pressure.
The goal should be to make attacks less disruptive and less profitable. By combining comprehensive security controls with air-gapped recovery solutions and validated backups, along with regularly tested incident response plans and proven recovery processes, organisations can reduce opportunities for attackers and contribute to a stronger collective defence.






