Beyond Compliance: Resilience Under Pressure

Event: In the Eye of the Storm – CyNam, 2026

Session: Operational Resilience in Practice | Sponsored by Fortem IT & Gigamon


When a cyber crisis hits, organisations don’t just face a technical problem — they face a test of everything: their people, their processes, their technology, and their ability to communicate clearly under pressure.

At CyNam’s 2026 event, In the Eye of the Storm, one session stood out for its practical, experience‑led challenge to how organisations think about resilience.

Sponsored by Fortem IT and Gigamon, the session avoided abstract theory and focused instead on a question that is increasingly urgent for security, risk, and leadership teams across every sector:

Is your organisation genuinely resilient — or simply compliant?


The Problem With Point‑in‑Time Compliance

Regulatory frameworks establish essential baselines for cyber security and operational resilience. However, meeting those requirements at audit time does not automatically translate into readiness when a real incident occurs.

The opening message from Fortem IT and Gigamon addressed this gap directly.

Compliance is largely point‑in‑time — a snapshot of controls assessed against a defined standard. Operational resilience, by contrast, is a continuous state, tested every day by changing threats, evolving infrastructure, and increasing operational complexity.

An organisation may satisfy every control listed in a framework and still have limited visibility into what is actually happening across its environment. This risk is particularly pronounced in hybrid and cloud architectures, where assets are dynamic, distributed, and often partly outside direct organisational control.

Traditional reliance on logs and endpoint telemetry, while still important, is increasingly insufficient on its own. In complex modern environments, those tools can leave blind spots that adversaries are adept at exploiting.


The Case for Deep Network Observability

A core theme of the session was the role of deep network observability as a critical component of operational resilience.

Where endpoint agents and log sources report what individual systems believe is happening, network observability provides independent visibility into traffic flows, behaviours, and patterns across the environment. This additional layer helps organisations understand what is actually occurring across networks, workloads, and services, regardless of platform or location.

This capability is particularly relevant in scenarios where:

  • Encrypted traffic limits the effectiveness of traditional inspection, requiring metadata and behavioural analysis to identify anomalies
  • Third‑party and supply chain integrations introduce dependencies that cannot be monitored solely through internal endpoints
  • Hybrid and cloud services create traffic patterns that are difficult to track with perimeter‑focused tools
  • Regulatory oversight increasingly expects demonstrable, evidence‑led assurance rather than stated intent

From an operational perspective, the benefits are tangible. Organisations with effective network observability are better positioned to detect activity that other controls may miss, shorten mean time to detect and resolve incidents (MTTR), and support continuous reporting aligned with the intent of frameworks such as DORA.


Resilience Is Not Just About Defence

One of the most important reframes offered during the session was the reminder that operational resilience is not defined by whether an organisation is attacked — but by how it responds when disruption occurs.

Strategies built solely around prevention assume that defences will always succeed. In reality, incidents are inevitable. What differentiates resilient organisations is their ability to detect issues quickly, make informed decisions under pressure, and recover in a controlled and confident manner.

True resilience is not something that can be bolted on during an audit cycle. It must be designed into day‑to‑day operations, supported by continuous visibility and evidence of control effectiveness. Leadership teams need accurate, real‑time insight when incidents happen — not just reassurance that requirements were met at the last assessment.


Key Takeaways for Security and Risk Teams

For practitioners and leaders responsible for cyber security, compliance, and organisational risk, the session highlighted several practical lessons:

  • Move beyond point‑in‑time compliance
    Frameworks emphasise sustained capability and evidence over periodic assurance.
  • Avoid reliance on logs and endpoints alone
    In modern hybrid and cloud environments, these controls are necessary but not sufficient. Network‑level visibility helps close critical gaps.
  • Prioritise encrypted traffic and third‑party risk
    These are common areas where malicious activity can go undetected without broader observability.
  • Treat MTTR as a leadership metric
    Faster detection and response reduces operational impact, regulatory exposure, and customer harm.
  • View resilience as an ongoing investment
    The objective is sustained operational confidence — not simply passing the next audit.

About Fortem IT and Gigamon

Fortem IT is a specialist IT and cyber security services provider supporting organisations in the design, delivery, and operation of secure and resilient technology environments.

Gigamon is a global leader in deep observability, delivering network‑level visibility that enables security and operations teams to improve threat detection, performance monitoring, and incident response.

Together, Fortem IT and Gigamon combine managed service experience with advanced network intelligence to support organisations operating in complex regulatory and threat landscapes.


About CyNam

CyNam is the UK’s leading cyber security cluster, based in Cheltenham, connecting individuals, organisations, and innovation across the cyber sector.

CyNam events bring together practitioners, leaders, and technologists to share insight, challenge thinking, and strengthen the resilience of the organisations and industries they support.

In the Eye of the Storm explored how people, processes, technology, and communication come together under pressure — and what effective leadership and preparation look like when disruption occurs.