The term cyber resilience is currently used frequently. How does cyber resilience differ from traditional IT security?
Nils Hondong: Traditional IT security has largely focused on prevention: stopping threats before they enter the system. Cyber resilience goes much further. It addresses whether an organisation can continue operating safely and effectively even when something does go wrong. Identities play a central role in this context. During an incident, organisations need to know who still has access, which permissions need to be restricted and how legitimate employees can continue working securely. In business-critical environments, this is the real test. It is not only about defending against attacks. It is about maintaining access, containing disruption, recovering quickly and protecting work that must not be interrupted.
Why is it no longer sufficient to focus solely on preventing attacks?
Nils Hondong: Today’s IT environments are simply too complex; prevention alone is no longer enough. Organisations manage legacy systems, cloud services, shared devices, third-party access and increasingly AI-driven services and agents. This creates more attack surfaces, more identities and a greater likelihood that an attack will slip through undetected.
Prevention remains essential. However, organisations also need strong capabilities for detection, containment and recovery, as well as visibility into who or what is accessing critical systems.
Many security strategies now assume that attackers will eventually succeed. How does this assumption change an organisation’s security strategy?
Nils Hondong: The philosophy of IT security is shifting from perimeter defence towards continuous control. The focus is moving to restricting permissions, continuously verifying access, improving visibility and minimising the impact of individual breaches. This is precisely where resilience comes into play. The objective is not only to prevent incidents but also to ensure that a single adverse event does not escalate into an operational crisis.
How important is identity and access management for organisational resilience?
Nils Hondong: Identity and access management plays a central role in organisational resilience. It determines who may access which resources, under what conditions and for how long. In today’s IT environments, this includes employees, contractors, suppliers, service accounts, connected devices and AI agents. Identity governance is also becoming increasingly important because organisations must be able to demonstrate why access was granted, who approved it and whether it was withdrawn at the appropriate time. If identity controls are weak, resilience will be weak as well. If identities are well governed, transparent and adaptable, organisations are far better equipped to protect their operations without slowing down legitimate workflows.
How can organisations identify gaps in their identity security and access management practices?
Nils Hondong: There are usually several clear warning signs. If teams still rely on shared passwords, generic accounts, blanket access rights or manual workarounds, action is needed. The same applies if access reviews are slow, privileged activities are difficult to trace or answering basic audit questions takes too long. A simple test is this: Can the organisation improve security without disrupting critical workflows? If not, there is probably still room for improvement.
What common mistakes do you see organisations making when modernising identity and access security?
Nils Hondong: One of the biggest mistakes is treating modernisation purely as a technology upgrade. In regulated, fast-moving environments, identity management must align with actual workflows, shared endpoints, legacy applications and compliance requirements. If these realities are ignored, controls may look sound on paper but fail in practice.
Another common mistake is focusing exclusively on employees while overlooking external parties and non-human identities. Service accounts, machine identities, APIs, automation tools and AI agents often have extensive access rights but are subject to much weaker governance, creating a significant security gap.
How are multi-factor authentication and passwordless authentication related?
Nils Hondong: The two concepts are closely linked, but they are not the same. Multi-factor authentication requires more than one form of verification. Passwordless authentication removes the password altogether and uses more secure methods such as passkeys, biometrics or device-based credentials. In many cases, passwordless authentication is the better option for strong authentication because it enhances security while reducing friction for users.
What challenges do organisations face when implementing passwordless approaches?
Nils Hondong: The biggest challenge is that going passwordless is not merely a feature. It represents a shift in mindset across the organisation and its workforce. Organisations must address legacy applications, shared devices, recovery processes, user adoption and consistent policy enforcement across different roles and environments. This is particularly important for frontline work, for example at the patient’s bedside in healthcare, on the production line in manufacturing and in many other industries. Many passwordless models were designed for personal devices rather than shared workstations or handheld devices used by multiple people during a shift.
Artificial intelligence is impossible to ignore. What opportunities and risks does AI present for cybersecurity?
Nils Hondong: AI offers genuine opportunities. It can help security teams detect anomalies more quickly, reduce manual effort and analyse large volumes of data more effectively. However, it also introduces new risks. Attackers can use AI to refine phishing attacks, automate reconnaissance and operate at greater speed. At the same time, many organisations are adopting AI internally before establishing effective controls for access, data usage and accountability.
What new requirements do AI applications create for identity and access management?
Nils Hondong: AI introduces a growing number of non-human identities that must be properly managed. These include agents, bots, orchestration services, APIs and automated workflows. Such entities may access sensitive data, trigger actions or interact across systems, meaning they must not be treated as invisible background processes. Organisations therefore need clear identities for them, granular permissions, robust credential management, continuous monitoring and clearly assigned human accountability for what they are allowed to do.
Cyber resilience is not only a technical challenge but also an organisational one. What role do processes, governance and security culture play in building a resilient organisation?
Nils Hondong: When things go wrong, organisations fall back on established behaviours. This is why strong governance, clear processes and a healthy security culture are so important. Technology can enforce controls, but ultimately people still make decisions, handle exceptions, approve access rights and respond under pressure. Resilience depends on whether an organisation can perform these tasks clearly, consistently and rapidly.
Particularly in critical infrastructure sectors such as healthcare, security incidents can have an immediate impact on people. What lessons from these environments are relevant to other industries?
Nils Hondong: The most important lesson is that cybersecurity is fundamentally about ensuring continuity of operations, even in the face of disruption.
In healthcare, for example, the consequences are immediately visible. The same is true in manufacturing and other critical industries. When secure access fails, the impact quickly extends beyond IT into operational processes.
Another key lesson is that security must support speed rather than hinder it. Whether on a factory production line or in an operating theatre, controls are effective only when they are tailored to the way people actually work.
Which measures should organisations prioritise to strengthen cyber resilience sustainably?
Nils Hondong: They should begin by treating identities as core infrastructure. This means modernising authentication, tightening access controls, reducing excessive permissions, improving visibility and governing the full spectrum of identities across the organisation – including AI agents and service accounts.
It is equally important to establish resilience as an operating model. Strong governance, tested response processes and security controls aligned with real-world workflows create long-term resilience. This helps minimise disruption, maintain control and keep critical operations running.
Interview conducted by Nicole Wörner.
Biography – Nils Hondong:
Born in Bocholt in 1979, Nils Hondong completed vocational training as a communications electronics technician specialising in information technology in 2000. He subsequently worked as an administrator in the data centre of an international logistics company before serving as a consultant for Active Directory and Citrix Terminal Services from 2002 to 2007. In 2007, he co-founded OGiTiX Software AG, where he focused on identity and access management, product management and engineering leadership. Following the acquisition by Imprivata, he was responsible for technical development as Director Engineering until 2026. Since 2026, he has served as Director Product Management, with particular expertise in identity and access management and cybersecurity.
