Murat Çelebi, Director of Information Security and Risk at the Central Registry Institution, discussed whether cyber resilience is solely an IT issue or a corporate culture. Çelebi stated:
“Cyber resilience is not just an ‘IT’ issue. It requires a much broader perspective. To ensure resilience, policies and procedures, particularly those established by senior management to guide the organization, and defined roles and responsibilities are all components of cyber resilience. Furthermore, your assets, their criticality, a well-structured risk management system, early detection of risks—especially financial compliance, reputation, and operational risks—are analyzed. Risk analysis, particularly for ‘IT’ risks, within the framework of confidentiality, accessibility, and integrity, is also crucial. While ‘IT’ generally fulfills its assigned responsibilities, the processes following an attack are also very important today, given the inevitability of such attacks. In this context, establishing business continuity processes to address service interruptions caused by attacks or other reasons is of paramount importance.” Identifying your critical business processes, conducting business impact analyses, establishing human, application, and data redundancy, determining the level of loss you can tolerate in each service, and the extent of data recovery you can achieve are all crucial aspects here. In this context, I believe that a well-structured risk management system, starting with top management and continuing with your policies, procedures, duties, roles, and responsibilities, along with the integration of IT, is essential for establishing cyber resilience.
What is Cyber Resilience?
Cyber resilience is an organization’s capacity to be prepared for, prevent, detect, and respond to cyber threats. This concept is the responsibility of the entire organization, not just the IT department. Cyber resilience refers to an organization’s ability to maintain business continuity and be resilient against cyber attacks.
The Role of Senior Management
Senior management plays a critical role in ensuring cyber resilience. Policies and procedures that guide the organization’s direction form the basis of cybersecurity strategies. Senior management should provide leadership in the creation and implementation of cybersecurity policies.
Risk Management and Analysis
A well-structured risk management framework is one of the cornerstones of cyber resilience. Early detection of risks, financial compliance, reputational and operational risk analysis ensure preparedness against cyber threats. In this process, risk analysis should be conducted within the framework of confidentiality, accessibility, and integrity.
Business Continuity Processes
When cyber attacks are inevitable, establishing business continuity processes is of paramount importance. Identifying critical business processes, conducting business impact analyses, and ensuring data redundancy enable preparedness against service disruptions.
IT Contribution
The IT department plays a crucial role in ensuring cyber resilience. However, this process is not solely the responsibility of IT. Collaboration among the entire organization is necessary. While IT provides technological solutions against cyber threats, other departments should support these solutions.
Conclusion
Cyber resilience refers to an organization’s capacity to be prepared for cyber threats, and this process is the responsibility of the entire organization, not just IT. Policies and procedures established under the leadership of top management should be supported by risk management and business continuity processes. While the IT department provides technological solutions, collaboration among the entire organization is essential. In this way, a structure resilient and prepared against cyber threats can be created.
About the Wise
Similar Videos from this Wise
What are the most critical success factors in transitioning to a Zero Trust Architecture?
Murat Çelebi, Director of Information Security and Risk at the Central Registry Institution, spoke about the most critical [&...











