ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Why cyber resilience starts with designing for isolation

When more than 100 hospitals recently switched to pen and paper following a cyber-attack, it looked like a step backwards. But disconnecting systems from the internet was one of the smartest moves they could have made. It stopped attackers in their tracks and bought hospital staff valuable time to work out what had been compromised before things got worse.

 

Most organisations don’t think like that in the moment because isolating systems can feel like admitting defeat. The pressure to protect revenue, productivity and customer service often means that businesses put off the difficult decisions until everything fails at once and the business is forced into total shutdown.

 

By that point, the attacker is usually already deep inside the network and recovery gets a lot harder. But the organisations that bounce back the fastest are usually the ones that are prepared to take controlled action early on by containing the incident before a single breach turns into a catastrophic multi-million-pound loss.

 

Detection is just the beginning

The cyber-security industry has historically poured a lot of money into software-based defences like detection and monitoring tools. While that investment matters, spotting an attacker is only the first step. The more important question is how quickly and effectively you can stop damage from spreading when they inevitably breach your network.

 

Cyber-resilience shouldn’t be measured by how quickly an organisation can detect a threat. It needs to focus on how effectively it can contain an attacker and protect the systems that matter most while you recover from the attack.

 

And that’s where software-defined controls fall short because relying on software to fix software weaknesses creates a fragile dependency that can’t guarantee safety when systems are compromised.

 

Buying time when it really matters

This challenge is getting a lot harder with critical assets spread out across cloud environments, operational technology, business networks and third-party connections, and with AI helping attackers find weaknesses and move through environments much faster. 

 

Previously, segmentation has largely been a software-based security control that is only as reliable as the environment in which it operates. But organisations need additional layers of resilience that keep working even when parts of their digital infrastructure are compromised.

 

That means enforcing security boundaries at the infrastructure level, so compromised systems can instantly be isolated on demand without disrupting the wider business.

 

Done properly, this means the business can keep running while the threats are contained. So, instead of one compromise cascading through the whole organisation, deep segmentation selectively protects against maximum loss and gives security teams valuable time to recover from an attack.

 

This is a mindset shift away from relying solely on software-based defences towards designing an independent, physical layer of infrastructure control that remains absolutely enforceable even if software systems are compromised.

 

Designing for isolation – delivering resilience

The goal here isn’t to disconnect everything during an attack. It’s to either isolate the affected systems or separate critical assets when at risk.  The rest of the business can keep operating without the risk of contagion. This is not about turning off a business; it’s all about allowing critical systems to run autonomously for as long as needed before re-integrating with other systems when safe.

 

For most businesses, keeping sensitive systems permanently connected delivers little strategic value while significantly increasing the potential impact of a breach because always-on connectivity expands the attack surface and gives attackers more opportunities to move between systems once they break in.

 

The highest resilience comes from treating connectivity to high-value assets as conditional, giving people and systems access only when it is needed and isolating critical systems whenever a threat of an attack exceeds a defined threshold. 

 

When the ability to connect and reconnect sits outside the view of attackers, they can’t see or tamper with those controls. This allows critical systems and essential recovery backups to remain isolated and only brought online through tightly controlled, auditable time windows. 

 

So, by reducing unnecessary exposure and limiting pathways for lateral movement, organisations can buy themselves valuable time to respond, contain threats before they spread, reduce the blast radius of an attack and minimise the operational and financial impact of a breach.

 

Building resilience into the network – the Breach Assumed model

As AI accelerates both the speed and sophistication of cyber-attacks, the ability to instantly contain threats even when defences are breached will become increasingly critical. The design philosophy arising from this is increasingly known as “breach assumed”, which shifts focus from assuming defences will work 100% forever, and turns it towards “designed for resilience”.

 

The ability to dynamically enforce security boundaries at the infrastructure layer the moment it’s needed will become a core requirement of cyber-resilience, giving organisations time to investigate, time to recover and, most importantly, time to stop losses from spiralling.

 


 

Michael Vallas is Global Technical Principal at Goldilock Secure

 

Main image courtesy of iStockPhoto.com and narvo vexar


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543