By Kim Larsen, CISO, Keepit
Among security professionals, there’s a tendency to move on quickly. An incident is investigated, a fix is deployed, and attention shifts to the next headline. But resilience requires more than reacting at speed. It requires stepping back to reflect on what each disruption reveals.
The CrowdStrike outage was one of those moments. The disruption highlighted what many long-timers in security already know: In a landscape of shifting vulnerabilities and attack vectors, escalating threats are the only true constant.
Vulnerabilities cannot be eliminated, nor are they easy to anticipate.
What can be shaped is governance, defined as the discipline that determines how well an organization understands its systems, how decisions are made under pressure, and how quickly recovery takes place.
Governance as the new perimeter
For years, defense strategies were built around attack vectors such as ransomware, phishing, and insider threats. Today, escalating uncertainty is reshaping the landscape. Vendor outages, identity failures, cloud interdependencies, and geopolitically motivated disruptions are proving just as damaging as direct attacks.
In this environment, governance has emerged as the new perimeter. Once seen as a compliance checkbox, it is now the cornerstone of resilience. Without it, organizations risk holding data they cannot classify, dependencies they cannot control, and risks they cannot recover from.
Boards are already being drawn into this shift
Regulations like the NIS2 Directive in Europe require critical entities to prove operational resilience. DORA mandates that financial institutions demonstrate the ability to recover from ICT disruptions with minimal downtime. In the U.S., the SEC’s disclosure rules hold leadership directly accountable for cyber governance and incident response.
A governance strategy that meets this moment delivers three outcomes:
- Visibility: a clear map of what data exists, where it lives, and how it flows.
- Accountability: well-defined roles across security, legal, operations, communications, and product.
- Recoverability: clarity on what must be restored first, how quickly, and by whom.
When governance achieves visibility, accountability, and recoverability, it stops being a compliance exercise and becomes the foundation for sustained resilience.
The 90-day governance plan
A structured 90-day approach turns governance from a compliance exercise into an operational capability the board can measure. With a phased framework, CISOs can establish a practical path to build governance into the core of resilience.
The first 30 days: Establishing the baseline
The first step is clarity. Many organizations still struggle to answer basic questions: What data do we hold? Where does it live? Who owns it? Without a reliable inventory, recovery planning is guesswork.
Classification must come first. Data should be categorized by criticality: What’s essential to resume operations versus what can wait. Assigning ownership ensures that in a crisis, accountability is already established.
At the same time, policies must be set within a recognized framework. Whether aligned to NIST CSF, ISO, or sector-specific standards, the framework matters less than measurability. Governance requires evidence: Who is responsible, how controls are tested, and how results are reported to leadership and regulators.
Finally, governance must extend beyond security teams. The CrowdStrike outage showed that when disruption spreads, communications, operations, and legal leaders become just as essential as IT engineers. Establishing a cross-functional resilience task force ensures that governance is organizational muscle memory, not a technical silo.
Days 31-60: Exposing weak points
With the foundation in place, the next phase is testing. Resilience is proven only when stress is applied.
Recovery strategies should be mapped directly to business functions. Payroll, customer service, regulatory reporting, and operational continuity all carry different tolerances for downtime. Object-based recovery and prioritizing what is most essential first can make the difference between minimal disruption and prolonged outage.
This phase is also about surfacing hidden dependencies. Identity providers, SaaS platforms, and third-party vendors often represent single points of failure. A DNS outage or federation breakdown can cascade through multiple systems at once, disrupting access to critical data.
Preparation must include the unexpected. Governance requires readiness for misconfigurations, accidental data loss, or geopolitical shocks: scenarios that don’t fit neatly into traditional threat models. Tabletop exercises and live simulations expose how governance performs under pressure and where gaps remain.
Days 61-90: Embedding resilience
By the third month, governance must move from a project to a permanent capability.
Continuous monitoring replaces one-time audits. Risk signals must flow through standardized reporting and escalation paths so decision-makers receive clear, timely information.
Staffing also becomes critical. Governance cannot be left as an additional burden on already stretched teams. Dedicated roles, whether through hiring or retraining, must take responsibility for sustaining governance as an ongoing discipline.
The outcome of this phase is integration. Resilience is embedded into the operating fabric of the organization, ensuring governance is not only about compliance but about continuity.
The new mandate
Avoidance is not a resilience strategy.
Responsiveness is.
The real standard is simple: visibility, accountability, and recoverability.
A 90-day governance plan won’t eliminate every risk, but it gives CISOs and boards a clear, structured way to move from firefighting to proactive strength-building. Governance stops being a checkbox and becomes a capability that holds under pressure and sustains trust.
When the next disruption comes, the question won’t be how good your security and leadership teams were at avoiding the problem. It will be how quickly you recovered, how clearly you communicated, and how well you protected people, customers, and reputation.
That is the new perimeter. Governance is the cornerstone of resilience.
##
ABOUT THE AUTHOR
Kim Larsen is Chief Information Security Officer at Keepit and has more than 20 years of leadership experience in IT and cybersecurity from government and the private sector. Areas of expertise include business driven security, aligning corporate, digital and security strategies, risk management and threat mitigation adequate to business needs, developing and implementing security strategies, leading through communication, and coaching. Kim Larsen is an experienced keynote speaker, negotiator, and board advisor on cyber and general security topics, with experience from a wide range of organizations, including NATO, EU, Verizon, Systematic, and a number of industry security boards.





