Security Is Shifting From Prevention to Resilience
好的,我现在需要帮用户总结一篇文章的内容,控制在100字以内。首先,我得仔细阅读文章,抓住主要内容和关键点。 文章主要讲的是Sophos的高级副总裁Dan Cole讨论网络安全策略的转变。他提到从以预防为主的思路转向注重弹性和响应。这可能是因为网络威胁变得更加复杂,比如国家行为者和AI辅助攻击的出现。 Cole还回顾了他职业生涯中的变化,从早期的大规模恶意软件到现在的混合工作环境。他指出,尽管工具和威胁者在变化,但核心挑战依然存在:攻击者行动迅速,防御者总是被动反应,完美预防不现实。 因此,组织开始重新评估安全成功的衡量标准,不再只关注是否能完全阻止入侵,而是关注检测、遏制和恢复的速度。这推动了MDR(托管检测和响应)的发展,尤其是在缺乏全天候内部专家的组织中。 此外,文章还提到了AI在攻防中的作用。攻击者利用自动化进行侦察和利用,而防御者则用AI来处理警报、更快识别威胁并缩短响应时间。但Cole强调AI不是万能的,人类专业知识仍然重要。 混合工作也是一个关键主题。用户在办公室、家里和其他地点之间移动,一致的安全策略跟随用户而非网络变得至关重要。碎片化的控制和不一致的执行会留下盲点被攻击者利用。 最后,现代网络安全是技术、人员和流程的平衡。预防仍然重要,但弹性现在是有效安全计划的关键指标。 总结时需要涵盖这些要点:策略转变、预防与弹性的平衡、AI的作用、混合工作的影响以及整体平衡的观点。控制在100字以内可能需要简化一些细节。 最终总结可能如下:Sophos高管Dan Cole探讨网络安全策略从预防转向弹性和响应的趋势。随着威胁复杂化和混合工作的普及,组织更注重快速检测、遏制和恢复能力,并借助AI提升效率。现代安全需技术、人员与流程的平衡。 </think> Sophos高管Dan Cole探讨网络安全策略从预防转向弹性和响应的趋势。随着威胁复杂化和混合工作的普及,组织更注重快速检测、遏制和恢复能力,并借助AI提升效率。现代安全需技术、人员与流程的平衡。 2026-2-3 17:1:35 Author: securityboulevard.com(查看原文) 阅读量:1 收藏

Avatar photo

Dan Cole, senior vice president of product management at Sophos, unpacks how cybersecurity strategy is shifting from a prevention-first mindset toward resilience and response.

Cole traces his career from the early days of mass malware outbreaks like Melissa and ILOVEYOU through today’s environment of nation-state actors, AI-assisted attacks, and sprawling hybrid workforces. While the tools and threat actors have evolved, he argues the core challenge has remained the same: attackers move fast, defenders are always reacting, and perfect prevention has never been realistic.

That reality is driving organizations to rethink how they measure security success. Rather than asking whether breaches can be stopped entirely, Cole explains that CISOs and boards are now asking how quickly incidents can be detected, contained, and recovered from. This shift is helping elevate managed detection and response (MDR) as a practical layer of operational resilience, especially for organizations without round-the-clock in-house expertise.

He also explores how artificial intelligence is changing both sides of the equation. Attackers are using automation to scale reconnaissance and exploitation, while defenders are increasingly relying on AI to triage alerts, surface real threats faster, and reduce response time. Cole emphasizes that AI alone is not the answer—human expertise still matters—but AI can dramatically improve signal-to-noise ratios when paired with experienced analysts.

Hybrid work emerges as another recurring theme. With users moving between office, home, and remote locations, Cole highlights the importance of consistent security policies that follow the user rather than the network. He discusses why fragmented controls and inconsistent enforcement create blind spots that attackers can exploit.

Ultimately, modern cybersecurity is a balance between technology, people, and process. Prevention still matters, but resilience is now the defining measure of an effective security program.

Avatar photo

Alan Shimel

Throughout his career spanning over 25 years in the IT industry, Alan Shimel has been at the forefront of leading technology change. From hosting and infrastructure, to security and now DevOps, Shimel is an industry leader whose opinions and views are widely sought after.

Alan’s entrepreneurial ventures have seen him found or co-found several technology related companies including TriStar Web, StillSecure, The CISO Group, MediaOps, Inc., DevOps.com and the DevOps Institute. He has also helped several companies grow from startup to public entities and beyond. He has held a variety of executive roles around Business and Corporate Development, Sales, Marketing, Product and Strategy.

Alan is also the founder of the Security Bloggers Network, the Security Bloggers Meetups and awards which run at various Security conferences and Security Boulevard.

Most recently Shimel saw the impact that DevOps and related technologies were going to have on the Software Development Lifecycle and the entire IT stack. He founded DevOps.com and then the DevOps Institute. DevOps.com is the leading destination for all things DevOps, as well as the producers of multiple DevOps events called DevOps Connect. DevOps Connect produces DevSecOps and Rugged DevOps tracks and events at leading security conferences such as RSA Conference, InfoSec Europe and InfoSec World. The DevOps Institute is the leading provider of DevOps education, training and certification.

Alan has a BA in Government and Politics from St Johns University, a JD from New York Law School and a lifetime of business experience. His legal education, long experience in the field, and New York street smarts combine to form a unique personality that is always in demand to appear at conferences and events.

alan has 143 posts and counting.See all posts by alan


文章来源: https://securityboulevard.com/2026/02/security-is-shifting-from-prevention-to-resilience/
如有侵权请联系:admin#unsafe.sh