GoFirm
Back to Blog
Case Studies·3 min read

The Board Is Asking the Wrong Question. Here Is the Right One.

By GoFirm

David Ferbrache and James Hanbury published a sharp piece this month on the intersection of risk and resilience. Their core argument: boards are still framing cyber risk primarily as a prevention question - which threats are rising, where the control weaknesses are, how defensive investment is progressing. Those are legitimate concerns. They do not answer the questions that actually drive loss in major incidents: how quickly the event can be contained, how far business value falls during disruption, and whether the organisation can recover at all.¹

Their framework introduces two levers acting on the same loss profile. One reduces the frequency of severe events - prevention and detection. The other reduces the scale of loss once an event occurs - containment, restoration, and degraded operation. The board task is to decide which lever to pull for which scenario, because the answer is not the same for every category of risk.

The most important distinction in the piece is between scenarios where severity is driven by spread and recovery speed, and scenarios where the tail sits in legal exposure, regulatory response, and loss of trust that persists long after operations are restored. For the first category, resilience investment is high leverage. For the second, restoration does little to repair the damage once triggered. The investment case shifts entirely toward prevention.

The authors use DigiNotar as their boundary case. In 2011, the compromise of the Dutch certificate authority led to fraudulent certificate issuance and a complete loss of trust in its services. The organisation subsequently filed for bankruptcy. Systems could theoretically have been restored. The business model could not. That is the category of scenario where the recovery curve is irrelevant because what was lost cannot be recovered through operational restoration.

There is one observation in the piece that deserves more attention than it receives. The authors note that identity now sits so centrally in modern technology estates that compromise can simultaneously disrupt critical access, administration, recovery, and the safe re-establishment of control. That is not a standard operational resilience problem. It is a scenario where the very tools needed for recovery are disabled by the same event that triggered the need for recovery.

This is precisely the scenario where prevention is not just preferable but necessary, because resilience has no purchase once it has occurred. An organisation that cannot safely re-establish administrative control cannot execute its recovery plan. The recovery curve does not return to normal because the mechanism for recovery is itself compromised.

The Ferbrache-Hanbury framework would therefore place identity compromise in the same category as DigiNotar - a scenario where the investment case sits overwhelmingly on the prevention side, specifically on verified human authority confirmation at the point where privilege escalation, identity control changes, and administrative access are requested.

GoFirm operates at exactly that boundary. Before any privilege escalation executes, before an admin account is created or modified, before identity configuration changes, GoFirm routes a confirmation request to the named human authority on their registered personal device through a channel entirely separate from the operational environment. The authority confirms with their biometric. The action proceeds or it does not. An attacker holding compromised credentials, a manipulated AI agent, or a spoofed instruction cannot produce that confirmation.

The authors are right that prevention and resilience cannot be treated as separate board conversations. For most scenarios, both levers matter and the question is calibration. For the scenario where identity compromise disables the recovery mechanism itself, only one lever is available before the event occurs. The board should be asking which controls sit at that boundary, and whether they are actually in place.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in minutes, not months.

References

1. David Ferbrache and James Hanbury, The Evolving Intersection of Risk and Resilience, LinkedIn, June 2026

Share this article