Rather than simply cybersecurity, experts today are talking about cyber-resilience – or how, despite one or more inevitable attacks, affected organisations can continue to operate. (Photo: Shutterstock)

Rather than simply cybersecurity, experts today are talking about cyber-resilience – or how, despite one or more inevitable attacks, affected organisations can continue to operate. (Photo: Shutterstock)

Cyber security hasn’t gone away. But it is no longer enough. Faced with geopolitical tensions, artificial intelligence, new regulations and technological dependence, both businesses and governments are changing their approach. Eight experts, each in their own way, share the same conviction: the challenge is no longer to prevent all attacks, but to keep operating when they do occur.

For years, cybersecurity has been built around an implicit promise: to protect systems in order to prevent attacks. Firewalls, antivirus software, network segmentation and access control were all intended to keep threats at bay. This approach has not disappeared, but it is no longer enough. In a world where cyberattacks are on the rise, where infrastructure is increasingly interconnected, and where artificial intelligence is transforming both usage patterns and threats, the real question is no longer whether an organisation will be attacked, but whether it will be able to continue operating.

This shift is even reflected in the vocabulary used. “I prefer to talk about cyber-resilience rather than cyber-security,” says Muriel MorbéMuriel Morbé, CEO of House of Training. Her choice of words is telling. “A cyber-resilient organisation is not simply one that protects itself. It is an organisation that knows how to keep its operations running and bounce back when an incident occurs.” The executive believes that this development goes far beyond the IT teams. Executives, lawyers, HR managers and risk specialists must now share a common culture of preparedness. European legislation, from the Data Protection Act to NIS 2, is no longer merely a set of regulatory constraints: it is becoming a catalyst for a new form of governance.

At Mixvoip, Patrick BergPatrick Berg, head of cybersecurity, reaches a very similar conclusion when looking at the subject from a much more practical perspective. “Cybersecurity is no longer limited to IT protection: it has become a matter of business continuity,” he explains. His analogy is deliberately simple: a cyberattack is now like a fire. The aim is not just to prevent a fire from starting, but to organise the response when it does occur. “A resilient company is not one that thinks it can avoid all attacks, but one that knows how to react quickly when an incident occurs.” The two approaches complement each other. One emphasises preparing staff, the other the speed of execution. Both reflect the same paradigm shift: performance is no longer measured solely in terms of protection, but by the ability to continue producing, communicating and serving customers despite the crisis.

A strategy for 2030

This shift in doctrine extends far beyond the corporate world. For Ben FetlerBen Fetler, head of cyber at the Defence Directorate, cyberspace has become a battlefield in its own right. “We now talk about hybrid warfare. Before resorting to armed force, enemy forces will carry out operations in cyberspace with a view to destabilising the targeted countries,” he explains. The attacks then target critical infrastructure, supply chains or even public confidence. With this in mind, resilience is no longer merely a management objective but has become a component of national security. Luxembourg is responding to these developments with a cyber defence strategy for 2030, based on skills, operational capabilities, cooperation with the private sector and the anticipation of technological disruptions.

Being able to stand firm also means gaining better control over one’s dependencies. This is the central theme of the discussions on digital sovereignty. For Olivier TrientzOlivier Trientz, Head of Sales for Cybersecurity Services at Proximus NXT, says that companies can no longer ignore issues that, until recently, were the sole responsibility of technical departments: where is the data hosted? Who has access to it? Under which jurisdiction? “Cybersecurity must form the foundation of trust, continuity and performance for businesses,” he summarises. Behind the requirements of NIS2 and DORA, he sees above all an opportunity to regain control over the most sensitive digital assets. In his view, Luxembourg even has “a real opportunity to become a trusted European hub for data and digital services”.

At LuxTrust, this autonomy takes a very practical form. Whilst Proximus NXT encourages businesses to ask themselves the right questions, Pierre GrassetPierre Grasset, Chief Commercial Officer, explains how his company is trying to address this. “For us, sovereignty means independence and control over our various value chains,” he says. This strategy involves the development of proprietary components, European hosting, on-premises deployments where possible and, now, a ‘distributed autonomy’ model enabling customers to continue operating even if LuxTrust’s services are unavailable.

6G will incorporate AI by design

However, simply preparing staff, reducing dependencies or strengthening infrastructure is not enough. This resilience must also be organised in a sustainable manner. This is precisely the rationale behind Post Luxembourg’s reorganisation. “Cybersecurity can no longer be viewed as merely a protective measure. It is becoming a genuine driver of resilience, designed to ensure the continuity of essential services despite an increasingly uncertain environment,” says Mohamed OurdaneMohamed Ourdane, chief security officer.

Meanwhile, Sébastien Girard, head of the cybersecurity business line at Deep, notes that companies are no longer simply looking for technical solutions, but for support covering the entire security lifecycle, from risk assessment through to continuous improvement. Here too, the approach is changing: cybersecurity is becoming as much an organisational issue as a technological one.

Researchers at List are taking this line of thinking further by looking ahead to 6G networks. Their conclusion is clear: it will soon be impossible to add security after the infrastructure has been designed. “Network cybersecurity will no longer rely solely on protective mechanisms added as an afterthought,” explains Sébastien FayeSébastien Faye, head of the Distributed & Intelligent Connectivity group. Future networks will incorporate artificial intelligence right down to their most peripheral components.

For Qiang Tang, head of the Cybersecurity Group at List, this means making “privacy by design” a founding principle. “Privacy by design is therefore not just a compliance principle: it is a driver of cybersecurity.” In the future, trust will no longer rely solely on security software, but on the very architecture of networks.

Finally, according to Franck BedellFranck Bedell, head of information security chez Baloise Assurances Luxembourg, artificial intelligence is driving the industrial-scale growth of fraud at an unprecedented rate. “Fraud is no longer an isolated phenomenon; it is becoming a systemic risk, at the intersection of cyber security and business operations,” he notes. Generated images, synthetic voices, identities reconstructed from stolen data: fraudsters are now less concerned with breaching systems than with manipulating decisions. “We often continue to focus on securing systems, whilst fraudsters are learning above all how to manipulate identities and decisions.” This observation echoes, from a different angle, that of the other speakers: cybersecurity no longer protects just infrastructure; it now protects trust, which is often an organisation’s most valuable asset.

Taken individually, these eight accounts deal with hybrid warfare, digital sovereignty, 6G networks, insurance, regulation and crisis management. Taken together, however, they tell a single story: that of a discipline undergoing a fundamental transformation. Cybersecurity is not disappearing; it is gradually taking a back seat to a broader ambition. Preparing organisations, reducing their dependencies, training their staff, designing trustworthy infrastructure, speeding up incident response and ensuring business continuity. In other words, building resilience that is no longer merely a security advantage, but a genuine driver of competitiveness for the Luxembourg economy.