
11.08.2026
Why companies are not automatically resilient despite high investments in IT security – and how prevention, detection and response combine to form a functioning overall system.
Many companies continuously invest in their IT security: firewalls, endpoint security, SIEM, managed services and numerous other security solutions have long been standard. Nevertheless, when the crunch comes, the reality is often quite different: attacks are detected, but not contained in time. Responsibilities are unclear. Systems provide information that is not brought together. And measures that work on paper fail to mesh in practice.
Right here is being created the resilience gap.
What causes them, how companies should view their security architecture holistically, and why real Cyber Resilience explains that cannot simply be bought off the shelf Sebastian Bittig, Director of Cyber Defence at r-tec, in the accompio expert interview. Bittig has been working with security architectures for around 15 years, combining strategic consulting with operational experience from managed services and Incident Response. r-tec (part of the accompio Group) has specialised in cybersecurity for over 25 years, protecting companies and operators of critical infrastructure in the fields of cloud, OT, IoT and Big Data. As part of the accompio Group, r-tec brings the exact technical depth required to put the topics described in the interview into practice, with its own Cyber Defence Centre, over 100 security experts, a managed SOC and its own CERT.
In the full video interview, Sebastian Bittig explains that the resilience gap arises where individual security measures work, but do not form a functioning overall system. He outlines strategies for sustainably protecting IT infrastructures.
Many companies today invest substantial sums in their IT security. Despite this, a higher level of cyber resilience does not automatically result from this. The reason: a significant gap can arise between investment in individual security measures and their actual effectiveness.
Sebastian Bittig refers to this gap as resilience gap. It arises in particular when companies have established many security measures, but these do not function as a coherent system.
Whether a company is truly resilient often only becomes apparent when a real security incident occurs. That is when it becomes visible whether detection, communication and response are working – or whether there are fractures between the individual security areas.
A typical problem for many companies is a security architecture that has evolved over years. New solutions are added as new requirements arise or new threats emerge. What is frequently missing in this process is an overarching view of the overall system.
„Many years ago, people started with antivirus. Gradually, further solutions were added. In many cases, it was not considered from the outset how the individual systems would work with one another and what information needed to be exchanged between them.“
— Sebastian Bittig, Director of Cyber Defence at r-tec (part of the accompio Group)
This is how they are created Security silosWhile individual solutions work quite reliably from a technical perspective, they do not automatically pass their findings on to the next link in the security chain.
In an emergency, precisely that can become the problem. Information has to be gathered manually, responsibilities are not clear or relevant clues are recognised too late. Above all, that costs one thing: time.
And during an ongoing cyberattack, time is a crucial factor.
Three working individual areas do not yet make a resilient company.
That is the crucial point interplay between prevention, detection and response. All three areas must exchange information, build on one another and work together towards a common goal: preventing a security incident as far as possible, detecting it early, containing it quickly and restoring business operations as rapidly as possible.
That takes more than just individual security tools.
I'm Cyber Resilience Assessment precisely these factors are tested. According to Bittig, a functioning security architecture consists of the interplay of Technology, processes and people. The deployed systems must be able to communicate with each other, data flows must function, and responsibilities must be clearly defined.
Therefore, the resilience gap is not exclusively a technical problem. The organisation of a company also plays a decisive role.
An investment in a security solution must be accompanied by organisational measures. Processes must be defined, responsibilities established and areas of competence regularly reviewed.
It becomes particularly critical when information or contact persons are no longer up to date. Bittig reports on a ransomware incident where an attack was indeed detected by the SIEM deployed, but the response nonetheless stalled.
The reason was not a lack of technical detection. Rather, the customer's primary contact was no longer reachable, the stored contacts were not up to date, and there was no adequate weekend on-call roster.
The example shows: A detected security event is not yet a resolved security incident.
True resilience only emerges when detection is turned into a defined and rapid response.
Resilience is not an abstract goal, but can be assessed using concrete metrics and exercises.
Relevant variables include, for example:
All three metrics provide important indications of how well the response processes are actually working.
In doing so, the focus should not be exclusively on technical metrics. Ultimately, what is crucial is the ResultHow quickly is an attack detected? How quickly can the company respond? And how quickly is normal operations restored?
A particularly vivid example from Bittig's practice is a ransomware incident at a new client.
The company already had a managed SOC service and had good audit reports. Technically, the detection worked too: the deployed SIEM detected the attack and the responsible service provider informed the customer.
Even so, the reaction initially did not get going sufficiently.
The key weakness lay in the organisation: the primary contact person on file was no longer with the company. Furthermore, no one was available at the weekend and the provider’s on-call arrangements were not sufficiently well defined.
So, technically, the attack had been detected. Nevertheless, the entire system was incapable of action.
The difference would have been made by clearly defined processes, up-to-date contact persons and established authorities. Particularly for certain scenarios, it should be regulated in advance which measures a service provider is permitted to initiate independently.
This example illustrates the key message of the interview: Security resilience is not determined solely by whether an attack is detected – but by what happens afterwards.
The pressure to address resilience is now also coming from outside. Regulatory requirements such as NIS-2 and DORA are obliging many companies to deal actively with the issue rather than putting it off until an incident forces them to do so.

accompio supports companies in analysing security structures and testing them with attack simulations.
One of the biggest risks is trying to change too much all at once.
Building a fully functioning security system can take months or even years. Companies should therefore not attempt to rebuild their entire security architecture in a short series of workshops.
Instead, a step-by-step approach is recommended:
In this way, a security model is developed step by step that not only works on paper, but also remains effective in an emergency.
The resilience gap occurs where individual security measures work, but do not form a functioning overall system. True cyber resilience arises from interplay and cannot simply be bought.
Prevention, detection and response must therefore not be viewed in isolation. They must work together, exchange information and be connected through clear processes and responsibilities.
It is not just technologies that play a role here. People, processes and technology must work together.
Therefore, the truly decisive question is no longer which security solution should be purchased next. Much more important is: does the entire system still work when it really matters?
„"How do we ensure that our entire security system works when an emergency arises?"“
For precisely there is where true cyber resilience is decided.

Sebastian is a security expert and advises clients on building resilient IT security structures and security systems.
Cyber resilience describes a company's ability to prevent cyberattacks and security incidents, detect them early, respond effectively, and subsequently restore operational capability quickly. The interplay between prevention, detection and response is crucial here.
In IT, resilience describes the ability of systems and organisations to remain functional even under disruption or attacks, or to recover quickly from them. Cyber resilience is the application of this principle specifically to IT security and cyber attacks.
The resilience gap refers to the distance between existing security investments and a company's actual ability to act effectively in an emergency. It often arises when individual security solutions work, but are not connected into an integrated overall system.
Security tools provide vital functions for prevention, detection or response. However, they do not automatically create a functioning overall system. True cyber resilience is only achieved when technology, processes and people work together and information and responsibilities are clearly defined.
Prevention aims to prevent attacks wherever possible. What cannot be prevented must be detected as quickly as possible through detection. Response then ensures that appropriate measures are initiated, attacks are contained and affected systems are restored. The three areas must be closely integrated in the process.
Resilience can be measured and trained. Key performance indicators such as Mean Time to Detect, Mean Time to Respond and Mean Time to Recover, as well as practical emergency exercises, show how quickly a company detects an attack, responds to it and becomes operational again.
A sensible starting point is an analysis of the existing security maturity level. Attack simulations can help to reveal vulnerabilities in the interaction between prevention, detection and response. Subsequently, companies should integrate existing tools, define responsibilities and gradually improve processes.
No. Cyber resilience is an interplay of technology, processes and people. Unclear responsibilities, outdated contact persons or a lack of standby arrangements can mean that a detected attack still cannot be dealt with quickly.
Response shows whether a company is actually capable of acting in an emergency. An attack can be detected technically – but if nobody can be reached afterwards, responsibilities are unclear or necessary authorities are lacking, a considerable loss of time and potentially greater damage will result anyway.
