Professional IT services from accompio for companies in Germany.
Blog

The resilience gap: why many security investments fail to work

11.08.2026

Why companies are not automatically resilient despite high investments in IT security – and how prevention, detection and response combine to form a functioning overall system.

Professional man in a suit against a digital background.

Many companies continuously invest in their IT security: firewalls, endpoint security, SIEM, managed services and numerous other security solutions have long been standard. Nevertheless, when the crunch comes, the reality is often quite different: attacks are detected, but not contained in time. Responsibilities are unclear. Systems provide information that is not brought together. And measures that work on paper fail to mesh in practice.

Right here is being created the resilience gap.

What causes them, how companies should view their security architecture holistically, and why real Cyber Resilience explains that cannot simply be bought off the shelf Sebastian Bittig, Director of Cyber Defence at r-tec, in the accompio expert interview. Bittig has been working with security architectures for around 15 years, combining strategic consulting with operational experience from managed services and Incident Response. r-tec (part of the accompio Group) has specialised in cybersecurity for over 25 years, protecting companies and operators of critical infrastructure in the fields of cloud, OT, IoT and Big Data. As part of the accompio Group, r-tec brings the exact technical depth required to put the topics described in the interview into practice, with its own Cyber Defence Centre, over 100 security experts, a managed SOC and its own CERT.

The most important points briefly

  • High security investments do not automatically mean high resilience. What matters is not the number of solutions deployed, but how well they work together.
  • The resilience gap often arises as a result of grown and fragmented security landscapes. Individual systems and teams function on their own, but are not connected to form an overall system.
  • Prevention remains the basis of IT security, but cannot prevent every attack. Whatever is not prevented must be reliably detected and then dealt with quickly.
  • Detection forms the vital link between prevention and response. Insights gained from attacks should also be fed back into prevention.
  • Response is the reality check for a company's cyber resilience. Only when a security incident occurs do you see whether processes, responsibilities, systems and people actually work.
  • Resilience is not just a technical task. Processes, responsibilities, communication and collaboration between teams and service providers are just as crucial.
  • Resilience can be measured and trained. Metrics such as time to respond and mean time to recover, as well as practical emergency drills, demonstrate how quickly a company can respond to an attack and become fully operational again.
  • The path from tool stack to complete system takes time. Organisations should take a phased approach, integrate existing solutions, and clearly define responsibilities and processes.

The resilience gap: expert interview with Sebastian Bittig, Director of Cyber Defense at r-tec (part of the accompio group)

In the full video interview, Sebastian Bittig explains that the resilience gap arises where individual security measures work, but do not form a functioning overall system. He outlines strategies for sustainably protecting IT infrastructures.

Cyber Resilience: Why Security Investments Alone Are Not Enough

Many companies today invest substantial sums in their IT security. Despite this, a higher level of cyber resilience does not automatically result from this. The reason: a significant gap can arise between investment in individual security measures and their actual effectiveness.

Sebastian Bittig refers to this gap as resilience gap. It arises in particular when companies have established many security measures, but these do not function as a coherent system.

Whether a company is truly resilient often only becomes apparent when a real security incident occurs. That is when it becomes visible whether detection, communication and response are working – or whether there are fractures between the individual security areas.

The resilience gap often arises from grown security landscapes

A typical problem for many companies is a security architecture that has evolved over years. New solutions are added as new requirements arise or new threats emerge. What is frequently missing in this process is an overarching view of the overall system.

„Many years ago, people started with antivirus. Gradually, further solutions were added. In many cases, it was not considered from the outset how the individual systems would work with one another and what information needed to be exchanged between them.“

— Sebastian Bittig, Director of Cyber Defence at r-tec (part of the accompio Group)

This is how they are created Security silosWhile individual solutions work quite reliably from a technical perspective, they do not automatically pass their findings on to the next link in the security chain.

In an emergency, precisely that can become the problem. Information has to be gathered manually, responsibilities are not clear or relevant clues are recognised too late. Above all, that costs one thing: time.

And during an ongoing cyberattack, time is a crucial factor.

Prevention, detection and response must function as an integrated system

Three working individual areas do not yet make a resilient company.

That is the crucial point interplay between prevention, detection and response. All three areas must exchange information, build on one another and work together towards a common goal: preventing a security incident as far as possible, detecting it early, containing it quickly and restoring business operations as rapidly as possible.

That takes more than just individual security tools.

I'm Cyber Resilience Assessment precisely these factors are tested. According to Bittig, a functioning security architecture consists of the interplay of Technology, processes and people. The deployed systems must be able to communicate with each other, data flows must function, and responsibilities must be clearly defined.

Cyber resilience is also an organisational topic

Therefore, the resilience gap is not exclusively a technical problem. The organisation of a company also plays a decisive role.

An investment in a security solution must be accompanied by organisational measures. Processes must be defined, responsibilities established and areas of competence regularly reviewed.

It becomes particularly critical when information or contact persons are no longer up to date. Bittig reports on a ransomware incident where an attack was indeed detected by the SIEM deployed, but the response nonetheless stalled.

The reason was not a lack of technical detection. Rather, the customer's primary contact was no longer reachable, the stored contacts were not up to date, and there was no adequate weekend on-call roster.

The example shows: A detected security event is not yet a resolved security incident.

True resilience only emerges when detection is turned into a defined and rapid response.

How can cyber resilience be measured?

Resilience is not an abstract goal, but can be assessed using concrete metrics and exercises.

Relevant variables include, for example:

  • Mean Time to Detect How quickly does a company actually detect a security incident?
  • Mean Time to Respond: How quickly does the company respond to that?
  • Mean Time to Recover: How long does it take for systems and processes to be restored and the ability to act to return?

All three metrics provide important indications of how well the response processes are actually working.

In doing so, the focus should not be exclusively on technical metrics. Ultimately, what is crucial is the ResultHow quickly is an attack detected? How quickly can the company respond? And how quickly is normal operations restored?

Practical example: When a detected attack still becomes a problem

A particularly vivid example from Bittig's practice is a ransomware incident at a new client.

The company already had a managed SOC service and had good audit reports. Technically, the detection worked too: the deployed SIEM detected the attack and the responsible service provider informed the customer.

Even so, the reaction initially did not get going sufficiently.

The key weakness lay in the organisation: the primary contact person on file was no longer with the company. Furthermore, no one was available at the weekend and the provider’s on-call arrangements were not sufficiently well defined.

So, technically, the attack had been detected. Nevertheless, the entire system was incapable of action.

The difference would have been made by clearly defined processes, up-to-date contact persons and established authorities. Particularly for certain scenarios, it should be regulated in advance which measures a service provider is permitted to initiate independently.

This example illustrates the key message of the interview: Security resilience is not determined solely by whether an attack is detected – but by what happens afterwards.

The pressure to address resilience is now also coming from outside. Regulatory requirements such as NIS-2 and DORA are obliging many companies to deal actively with the issue rather than putting it off until an incident forces them to do so.

Transparent castle on a digital server, symbolising IT security solutions.

Resilience for security systems

accompio supports companies in analysing security structures and testing them with attack simulations.

What businesses should avoid when building cyber resilience

One of the biggest risks is trying to change too much all at once.

Building a fully functioning security system can take months or even years. Companies should therefore not attempt to rebuild their entire security architecture in a short series of workshops.

Instead, a step-by-step approach is recommended:

  1. Analyse maturity level and existing architecture
  2. Identify security vulnerabilities and gaps between departments
  3. Combining existing tools in a sensible way
  4. Defining responsibilities and processes
  5. Define response scenarios and authorisations
  6. Test and further develop the overall system regularly

In this way, a security model is developed step by step that not only works on paper, but also remains effective in an emergency.

Conclusion

The resilience gap occurs where individual security measures work, but do not form a functioning overall system. True cyber resilience arises from interplay and cannot simply be bought.

Prevention, detection and response must therefore not be viewed in isolation. They must work together, exchange information and be connected through clear processes and responsibilities.

It is not just technologies that play a role here. People, processes and technology must work together.

Therefore, the truly decisive question is no longer which security solution should be purchased next. Much more important is: does the entire system still work when it really matters?

„"How do we ensure that our entire security system works when an emergency arises?"“

For precisely there is where true cyber resilience is decided.

Sebastian Bittig
Director of Cyber Defence, r-tec

About the expert

Sebastian is a security expert and advises clients on building resilient IT security structures and security systems.

FAQ: Frequently asked questions about cyber resilience

What does ‘cyber resilience’ mean?

Cyber resilience describes a company's ability to prevent cyberattacks and security incidents, detect them early, respond effectively, and subsequently restore operational capability quickly. The interplay between prevention, detection and response is crucial here.

What does resilience mean in IT?


In IT, resilience describes the ability of systems and organisations to remain functional even under disruption or attacks, or to recover quickly from them. Cyber resilience is the application of this principle specifically to IT security and cyber attacks.

What is the resilience gap?

The resilience gap refers to the distance between existing security investments and a company's actual ability to act effectively in an emergency. It often arises when individual security solutions work, but are not connected into an integrated overall system.

Why are security tools alone not enough?

Security tools provide vital functions for prevention, detection or response. However, they do not automatically create a functioning overall system. True cyber resilience is only achieved when technology, processes and people work together and information and responsibilities are clearly defined.

What role do prevention, detection and response play?

Prevention aims to prevent attacks wherever possible. What cannot be prevented must be detected as quickly as possible through detection. Response then ensures that appropriate measures are initiated, attacks are contained and affected systems are restored. The three areas must be closely integrated in the process.

How can cyber resilience be measured?

Resilience can be measured and trained. Key performance indicators such as Mean Time to Detect, Mean Time to Respond and Mean Time to Recover, as well as practical emergency exercises, show how quickly a company detects an attack, responds to it and becomes operational again.

How can companies improve their cyber resilience?

A sensible starting point is an analysis of the existing security maturity level. Attack simulations can help to reveal vulnerabilities in the interaction between prevention, detection and response. Subsequently, companies should integrate existing tools, define responsibilities and gradually improve processes.

Is cyber resilience only a technical issue?

No. Cyber resilience is an interplay of technology, processes and people. Unclear responsibilities, outdated contact persons or a lack of standby arrangements can mean that a detected attack still cannot be dealt with quickly.

Why is response so important for cyber resilience?

Response shows whether a company is actually capable of acting in an emergency. An attack can be detected technically – but if nobody can be reached afterwards, responsibilities are unclear or necessary authorities are lacking, a considerable loss of time and potentially greater damage will result anyway.

Woman with a headset in customer service at Accompio IT Services.

Get in touch with us

We at accompio will be happy to help you.