Skip to content
Software Supply Chain Security

Cyber Risk Resilience Beyond Compliance (Edna Conway)

governance vs compliance

Cyber threats evolve quickly, and organizations can’t afford to treat security as a one-time project or a simple box-checking exercise. In a podcast featuring cybersecurity and supply chain resilience expert Edna Conway, the central message is clear: improving your cyber risk resilience requires more than compliance efforts. It calls for governance that adapts, planning that accounts for change, and collaboration that extends beyond your walls.

Conway’s experience—spanning legal, engineering, and security—frames a practical perspective for boards, leaders, and technical teams. She connects long-term resilience with how organizations respond to geopolitical shifts, new technologies, and workforce readiness. Below, we translate those themes into actionable takeaways you can apply to your own security program.

Governance isn’t the same as compliance

A common misunderstanding is that compliance automatically equals security. Conway highlights the distinction between governance and compliance in cybersecurity: compliance focuses on meeting specific requirements, while governance is about shaping decisions, priorities, and oversight so risk is actively managed over time.

That difference matters because threats don’t pause while organizations audit. A governance approach helps leaders continually evaluate whether current controls still match the real-world environment—especially as technology and attacker behavior change. Instead of treating policies as static documents, you use governance to drive ongoing risk decisions.

Build resilience for an evolving threat landscape

When defenders rely too heavily on past standards, gaps emerge. Conway’s discussion emphasizes resilience: the ability to anticipate, absorb, recover from, and adapt to cyber incidents. Resilience isn’t a single product; it’s a set of organizational capabilities that mature with experience and feedback.

To move in that direction, consider how your organization answers questions like: What risks are changing fastest? Which dependencies are most likely to fail under stress? How quickly can you detect anomalies, coordinate response, and restore critical operations? These questions help turn abstract security goals into measurable outcomes.

Use supply chain risk thinking to reduce systemic exposure

Cyber risk rarely stays inside one boundary. Conway points to how geopolitical shifts can reshape supply chains and influence risk management strategies. When routes, regulations, or vendor capabilities change, threat exposure can shift as well—sometimes faster than internal teams can update controls.

Cyber risk resilience therefore needs supply chain awareness. That means understanding where critical components come from, which third parties could introduce weaknesses, and what happens if a supplier’s processes or security posture changes. It also involves planning for continuity when external dependencies fail.

AI, blockchain, and quantum computing: plan for disruption

Future digital infrastructure will likely blend multiple technologies, including AI, blockchain, and advances in quantum computing. Conway discusses how organizations should think beyond hype and prepare for technological integration in realistic ways.

For AI, there are both opportunities and challenges. The podcast underlines ethical and regulatory issues tied to AI development and deployment—topics that boards and executives should treat as part of risk management rather than as afterthoughts.

For blockchain and quantum-related progress, the key takeaway is not to chase every trend. Instead, strengthen your cyber risk resilience by mapping where new capabilities might alter your attack surface, operational dependencies, and long-term security assumptions.

Plan budgets for security and innovation together

Resilient security programs require resources, but Conway notes the importance of budget planning and resource allocation for both security and innovation. Organizations often struggle with trade-offs: cutting security investment to fund new initiatives, or delaying modernization due to fear of risk.

A more effective approach is to align funding with risk priorities. If your innovation roadmap creates new pathways for data movement or automation, that should be matched with appropriate security governance. Similarly, if security improvements require process changes—training, testing, response readiness—those costs should be built into planning rather than funded from emergency budgets.

Collaboration is a security capability

Individual organizations can harden their environments, but cyber defense increasingly depends on collective effort. Conway stresses the importance of collaboration and shared knowledge to safeguard digital ecosystems.

In practice, collaboration can take many forms: information sharing with peers, coordinated planning with government partners, and joint research or training efforts with academia. The goal isn’t just to exchange headlines; it’s to learn faster and respond more effectively when new attack patterns appear.

Prepare your workforce with upskilling and role clarity

Technology change creates a workforce challenge. Conway highlights strategies for upskilling teams and preparing the workforce of tomorrow. If your skills don’t evolve, your controls become outdated—even if they were well-designed in the past.

Resilience improves when teams understand not only tools, but also how to apply them in context: threat modeling, secure engineering practices, incident response coordination, and continuous validation of controls. Investing in training, simulation exercises, and role-based learning helps ensure capability meets demand.

Think in long cycles: from “bow and arrow” to space-based data

Conway uses an analogy to show how technology evolves dramatically over time. The shift from early weapons to far more advanced infrastructure mirrors how security strategies must evolve with the environment.

That perspective supports a practical conclusion: security planning should include long-term thinking, not just short-term compliance deliverables. When your organization anticipates the “next stage” of technology and operations, you can redesign controls before risk fully materializes.

Address ethical and regulatory challenges in AI adoption

AI deployment introduces complex questions: data handling, accountability, transparency, and potential misuse. Conway emphasizes the ethical and regulatory challenges surrounding AI development and deployment, reinforcing that these considerations belong inside your risk governance process.

To strengthen cyber risk resilience, document decision-making around AI use cases. Define how models are evaluated, how drift is monitored, and how human oversight works. Also ensure compliance efforts support—rather than replace—governance goals for safe, responsible deployment.

Practical steps to strengthen cyber risk resilience

If you want to translate Conway’s themes into a roadmap, start with a few structured moves that don’t depend on any single technology.

  • Reframe security success: measure resilience outcomes like detection speed, recovery time, and adaptation to new risk signals—not only audit results.
  • Differentiate governance and compliance: use compliance to meet requirements, and governance to set priorities, fund improvements, and continuously reassess risk.
  • Expand third-party visibility: evaluate supply chain dependencies and plan for continuity if external components or processes change.
  • Map emerging technology impacts: assess how AI, blockchain, and quantum-related progress could affect your threat landscape and operational assumptions.
  • Align budgets with risk and innovation: fund security capabilities that enable modernization rather than treating them as competing initiatives.
  • Invest in shared readiness: participate in knowledge exchange efforts and cross-sector collaboration when possible.
  • Upskill for capability, not just tools: train for secure engineering, incident response coordination, and ongoing validation of controls.

These steps support an approach where your defenses improve as conditions change, rather than staying frozen at the time of the last compliance cycle.

Conclusion: resilience is the durable goal

Edna Conway’s conversation makes a strong case that cyber risk resilience is the foundation of long-term cybersecurity. Compliance can be part of the journey, but it cannot carry the entire burden. Governance, supply chain awareness, future-ready planning, workforce development, and collaboration all contribute to how effectively an organization withstands evolving threats.

If you want security that holds up, focus on building capabilities that adapt—so your organization isn’t just “approved,” but genuinely prepared for what comes next.

Source: https://www.securityweek.com/podcast-compliance-wont-save-you-the-future-of-cyber-risk-with-edna-conway/