The Entropy Podcast
Hosted by Francis Gorman, The Entropy Podcast brings together intelligence community veterans, post-quantum cryptography pioneers, CISOs, business leaders, and frontline practitioners for unfiltered conversations on the threats, complexity, and geopolitics shaping our world.
Past guests include former senior CIA officers, leading cryptographers, digital forensics experts, and security and technology leaders from across financial services, critical infrastructure, and government, voices rarely heard together in one place.
Each episode goes beyond headlines to explore how cyber risk, emerging technology, and geopolitical instability are reshaping the way organisations operate, compete, and defend themselves. Expect candid insight on quantum risk, nation-state threats, AI, espionage, financial crime, business resilience, and the human dimensions of leadership.
Designed for CISOs, board members, founders, technologists, policy thinkers, and the professionally curious, Entropy sits at the intersection of business, technology, and cybersecurity a space for genuine conversations with unique minds, the kind that don’t fit neatly into a press release.
The name Entropy reflects the growing complexity and unpredictability of the systems we depend on, and the discipline required to lead through them.
Disclaimer: The views and opinions expressed on The Entropy Podcast are those of the host and guests in their personal capacity and do not represent the views, positions, or policies of their respective employers, affiliated organisations, or any government body. Guest appearances do not constitute endorsement by the host, and the host’s commentary does not constitute endorsement of guests’ views. Content is provided for informational and educational purposes only and does not constitute professional, legal, financial, or security advice.
One of the topics I cover a lot on this show is post quantum readiness, I believe awareness of this emerging technology is key for a safer world into the future. To support this awareness I have built a free resource to help you explore the world of quantum and learn as you go. You can find it here: www.postquantumready.com
Buy Our Swag:
We now have some slick new swag you can purchase through our Esty store.
https://theentropypodcast.etsy.com
Watch and Subscribe
You can also watch full episodes and exclusive content on our YouTube channel:
www.youtube.com/@TheEntropyPodcast
Achievements
The Entropy Podcast delivered strong chart performance throughout 2025, demonstrating consistent international reach and listener engagement.
- Regularly ranked within the Top 20 Technology podcasts in Ireland.
- Achieved a Top 25 placement in the United States Technology charts, holding the position for one week.
- Charted internationally across multiple markets, including Israel, Belgium, and the United Kingdom.
This performance reflects sustained global interest and growing recognition across key podcast markets.
Audio Quality Notice
Some episodes may feature minor variations in audio quality due to remote recording environments and external factors. We continuously strive to deliver the highest possible audio standards and appreciate your understanding.
The Entropy Podcast
Nobody Reads the Plan During the Fire with Patrick Lechner
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
In this episode of The Entropy Podcast, Francis Gorman speaks with Patrick Lechner, co-founder of Resimate.io and an experienced business and cyber resilience leader, about why many organisations mistake documentation for genuine readiness.
Patrick challenges the obsession with business continuity plans, impact assessments and compliance evidence, arguing that resilience should be measured by outcomes: can the organisation continue operating when something critical is lost?
The conversation explores the difference between security and resilience, why businesses should prepare for loss rather than attempt to predict every possible threat, and how leaders can identify their most important dependencies. Patrick also examines the role of AI, the importance of business ownership and why tabletop exercises must become honest operational conversations rather than annual corporate theatre.
This is a practical discussion about building the confidence, capability and human relationships required to respond when the plan no longer matches reality.
Key takeaways
- Resilience is not a collection of documents. Plans and frameworks are useful, but they do not prove that an organisation can sustain operations during a crisis.
- Prepare for loss, not every imaginable threat. Most disruptions can be reduced to losing a site, people, systems, suppliers or data.
- The business owns resilience. Operational leaders should decide what must continue, what level of disruption is tolerable and where investment is justified.
- Cybersecurity and cyber resilience are different. Security attempts to prevent incidents; resilience determines what happens when prevention fails.
- Dependencies must be understood across the organisation. A single failure—such as electricity, identity infrastructure or a major supplier—can create very different consequences across multiple teams.
- AI can amplify weak processes. Automating a poor resilience process may produce more plans and evidence without improving operational capability.
- Tabletop exercises should be frequent and honest. Short, regular discussions are often more valuable than one heavily scripted annual exercise.
- People ultimately carry the response. Trust, authority, shared principles and operational knowledge matter more during a crisis than a spreadsheet stored somewhere on the network.
Soundbytes:
“We were tired of resilience being measured by plans, not outcomes.”
“Plans may be useless, but planning is indispensable.”
“Almost every threat can be reduced to a handful of loss scenarios: losing a site, people, systems, suppliers or data.”
“The board-level question is simple: how confident are we that we can sustain operations if we lose a key dependency?”
“It does not matter why the electricity is gone. If it is gone, the business still has to respond.”
“Investing heavily in prevention does not mean you are resilient.”
“If you have bad processes today, AI is a great tool for accelerating those bad processes.”
“You do not become fit by going to the gym once a year for seven hours. Tabletop exercises work the same way.”
“An exercise should be an honest conversation, not a performance conversation.”
“When something hits, it is the people, the trust and the shared principles that allow the organisation to respond.”
Francis (00:03.34)
Hi everyone, welcome to the Entropy Podcast. I'm your host, Francis Gorman. Before we dive in, if today's conversation challenges you, sparks a new idea, or sharpens how you think about the world, don't keep it to yourself. Subscribe, leave a review, and share this episode with someone who enjoys staying curious. Today I'm joined by Patrick Lechner, the co founder of Resimate.io. Patrick is a business and cyber resilience specialist with more than 10 years of experience in crisis management, security, and resilience strategy. Patrick is a former IT and security director.
and Big Four Cyber Risk and Resilience Strategy Director. He has managed major global events including banking runs, humanitarian crisis, and cyber incidents. Patrick holds a masters in management and information technology from the University of St Andrews. And Patrick, it's lovely to have you here at meet this morning.
Patrick (00:50.027)
Thanks, Francis. looking forward.
Francis (00:53.222)
Patrick, I I I've been looking forward to this conversation because it's it's a team that has kind of, you know, become more visible in in the last while with Dora in Europe and I suppose the the geopolitical landscape, the the whole thematic of resilience and cyber resilience and operational resilience and all the facets of resilience have kind of come to the fore. So can can I ask you, what is what do most organizations misunderstand about resilience?
Patrick (01:22.325)
Hmm. I think when it comes to resilience, the the one thing I feel, having having observed over the last decade or so, is that there's a a misconception that unless you have very sophisticated frameworks in place and and really heavy processes in place, you're not resilient, right? And if you can't show that you have done a very extensive business impact analysis and continuity plans and have hundreds of them, you're not resilient.
I think that's the biggest misconception across any organization. Every organization has resilience. people are resilient. people are able to improvise. They know how their processes work. They know that they need to see how they can sustain operations if something goes wrong. So yeah, I would say the misconception that you only have resilience once you have the right frameworks and processes in place. I think I think that's the one big thing.
Francis (02:18.828)
I was looking at your website before you joined the call and y your strap line just kind of you know, it flows nicely off the tongue for one. So, you know, we built resume because we were tired of resilience being measured by plans, not outcomes. It's a beautiful it's a beautiful sentence. Can you can you talk to me about it?
Patrick (02:32.438)
There you go. Yes, I think it goes exactly what I just said. I think over the past ten years or so we were all obsessed with you know looking at different standards and frameworks and putting the processes in place. And unfortunately somewhere on the way we started optimizing for documents, I feel, rather than actually looking into have we enriched our resilience or not. So what I mean with that is
you mentioned Dora, you mentioned the regulations everywhere. I think they can be incredibly helpful and valuable in giving a common language and and helping set the baseline for an industry. But at the same time, especially with with companies where they have maybe more stretched resource constraints, we often end up then optimizing for the actual document, for the evidence. So
We're not taking regulations or standards or framework and say, okay, what can I take from here and then really help me enrich my my resilience, but more really focus on I need to have this documented, I need to have that documented. so then people are actually spending much more time chasing other people to like, Hey, you gotta fill this spreadsheet in because you know, by the end of the quarter we need we promise to have seventy VAs done and
This BCP, this continuity plan hasn't been reviewed in three years. So we should review that because we promise that you know 80% of our BCPs will be reviewed. So we get into this whole, you know, optimizing for documents and completely lose track of well, how is that actually going to help us if something something hits us? Will we be able to absorb that? Will we be able to sustain our minimal operations and continue? based on my experience, and that spans across different types of crisis situations.
It's not the plan that's going to help you in the end. It is definitely not going to be the the spreadsheet or the the the PA that was done years ago that will help you actually sustain your operations.
Francis (04:38.51)
You know, that that's really interesting because, you know, perfection by PowerPoint and the lovely Excel spreadsheet, you know, every organization has them and you know, when you go, how do you meet your Dora compliance? How do you recover from X, Y, and Z? We pull out what we pull out, we pull out a run book or a lovely slide deck that sells A, B, C and D. But what you're scratching at is that's great, but when crisis actually lands, they're not the things you go to first. Can you can you talk me through
a little bit of what you've observed in the wild. So, you know, y you put all the effort into into the paperwork, etcetera, then something bad happens. Wha how does it play out in reality?
Patrick (05:18.56)
think in reality and that also for me was quite a journey to realise and I think it it changed over the years when you know I started off in in the bigger consulting world where we work with large enterprises building out all these processes and plans but when I then was responsible operationally as well for leading incidents it was clear that it's it's never going according to plan. Yeah and there is huge immense value in planning.
So don't get me wrong, I'm not saying planning is bad. Actually, there's this Eisenhower quote, right? That planning, plans are useless, but planning is indispensable. And I think that's true. So here's the issue: the plans are actually optimizing for, you know, I have this and this requirement, but then in reality, something else hits you, and then you struggle because maybe your crisis management team never really got together. Maybe there's no shared understanding of what actually the principles we're operating by now.
And much more I think the human aspect of the building the right capabilities that whenever something comes, you're able to respond to that. And I think one big shift in my thinking that happened over the years is at the beginning was a lot of things of threat scenarios, all the bad things that can happen to you, and then you have like a dozen risk scenarios and so on. But when it comes to resilience, Francis, I think
If you think about it, it's usually your lost scenarios, right? So resilience capabilities, you need them you want you need to be resilient when something goes wrong and when some you when you lose something. And usually you can bring any type of threat scenario down to kind of like five lost scenarios, something around you lose a site, or you I mean like you you use an office space, like in a pandemic, right? you lose a people, your workforce, you lose systems, you lose maybe a supplier, maybe you lose data.
And then the question is what do we do then? And I think there is the true value in in looking more into kind of like the bigger picture how do we handle loss scenarios rather than very specific run books for this threat scenario and that threat scenario. It's big caveat. if you have a security operation center, if you run you know techno gains in response, it matters a lot when it comes to resilience management. It's much more the bigger picture on how to sustain your business operations in the end.
Francis (07:42.146)
That that's really interesting, Patrick. And there's there's something in there as you're talking. I'm giining dots in the back of my head that kinda goes that the real life test happens with the BAU teams, but the collation of the data and the definition of the plans and run books and all of these other things in the in the planning phase are normally done by projects in most large organizations. So there are contract resources or they're
point in time resources to pull that activity together and then there's a bit of a handover, but a lot of the knowledge actually leaves the organization or moves on to something else within the organization. And then as you say, when the when the moment hits, when that impact comes, the teams that should have the muscle memory actually haven't gone through the planning process to the extent that, you know, they're familiar with it enough. And then that's just saying the humans cracks start coming because, you know, the plans, well, they're not you have to live them. It's like
typing into chat GPT create me an instant response plan and you know then and having to enacted, you you you don't have the muscle memory.
Patrick (08:45.023)
E exactly. And I think this is where we get it wrong as well. I think over the years we have overcomplicated what resilience actually means. And we again it goes back to this. You know, if you optimize for documents, if you optimize for frameworks, you end up there, right? You you get external help in, they they may do an i incredibly good job in defining all your you know, critical business services and functions and processes, document everything down, they may even identify the R tune RPO and you know
all the great stuff that that the standards and regulations require. But then the people that actually would be the ones that have to sustain operations during a hit, they are like, you know, at best they they have been part of a one hour, two hour workshop and that's it. And I think there there's another component around ownership, which a lot of us get wrong in a way that we feel the business has an ownership of completing certain things.
meaning, you know, we need business to complete this VA, we need busin business to complete this and fill in the spreadsheet here. And then we're wondering, you know, why why we have such a bad ownership culture. When in reality the ownership is anywhere with them. It's an ownership of decision. And that means also ownership of prioritization. So I should acknowledge and accept and and actually empower the business as well to understand, hey, you own it no one needs to explain a COO that, you know,
service delivery and continuity of the delivery is important, right? Of course, it's part of their whole accountability set. So handing over that ownership or not, you know, empowering them for having that ownership to also make a decision how much resilience, confidence do we do we need, do we want, what capabilities do we need from a business perspective? So rather than just asking them to fill in spreadsheets and so on, it's really giving them as well the opportunity to say, hey, what do you worry about?
how confident do you feel that if something hits us that you will be able to sustain your operations, right? If this one core system is down. for example, we had this case with a hospital where there's this clinical information or the patient information system and everyone's like, Well, without that system we cannot operate. So then the question is, really? Like really, really? Like, no, it always must run. It's like, well, but what if it doesn't run one day?
Patrick (11:07.339)
Like, yeah, probably we could do this, this, and that. And that was the moment when ownership was clear, right? They own continuity of the process, but then they also own how much they want to do. So it shouldn't be, you know, us resilience professionals telling the business all the stuff they have to do, and especially not filling in spreadsheets, but really giving them a clear picture of these are the things, you know how this is how your business runs, this is how we run, these are the things we need. And
and based on then decide where we wanna invest, where we wanna improve, from a business ownership perspective.
Francis (11:42.304)
If if there's board members listening here today and this is resonating with them in terms of of a resilience question, is there is there key kind of areas or topics or questions they should raise on the agenda to get answered within their organizations?
Patrick (11:58.008)
I think on a from a board perspective, what I would be most interested in is how confident are we that we can sustain our operations if we lose the key dependencies, right? it's not a black or white answer because it has it has a lot of different nuances, but I think the confidence levels across the business, and that may fluctuate and vary as well, is really important. And why do I say confidence level? Because
That is the piece in the end that tells me do I have the capacity, do I have the the competence, do I have the skills, the authority to actually sustain operations? And I will see in some areas it's great and in others not. And then I can go a level deeper. So, like, okay, if we would lose core IT infrastructure, what would that mean in this and this area? If we lose this and that core supplier, what would that mean and how would we actually do that? So I can then drill deeper.
But I think it all starts with understanding who owns actually the continuity responsibility and then enabling those people that they have the right capabilities in place.
Francis (13:06.134)
Great great insights, Patrick. I I always think of a house and its foundations first, you know, and you know, good foundations make sure the house sustains the storm or or whatever bad weather is is is coming. If you're a chief operating officer today and you're looking at your resilience footprint, what are the key pieces you need to get right so that foundation is is solid that you can build on? You're not gonna have a a perfect house on day one, but you know, you can you can
edge forward towards that over a number of years. What are the what are the key steps I need to put in place?
Patrick (13:36.96)
I think there are thinking thinking I think a house is a great analogy. I think there are two modes of operations in resilience and one is basically building capacity and the other one is using that capacity. And it's almost a similar to like a a sports team. you know, you train a lot throughout the year and then a couple of times you're actually gonna gonna need it. And the basis, the foundation of your training of your building the house is really how do we
actually work as an organization, right? So what is our mission and what is our purpose and why do we exist and what do we really care about? That gives you already so much, right? In a hospital, obviously you care about patients being treated well. And in maybe in a more economic economical environment you care more about, you know, adding economical value. So really understanding
What's the purpose of organization and what's the underlying operating model? How do we operate? What is the external dependency, the input we have? how do we organize our self-organization? What are the key services we are delivering to achieve that? And once I understand that picture, then I can really say, Okay, what are the things that we are most worried about? so your foundation is you need to understand how your organization actually works.
Then you can build the first walls in terms of, you know, what are the things we actually worried about from a loss perspective that I mentioned before. And then you start putting putting the roof on and say, like, okay, the kind of capabilities that are going to protect us then from the rain and from the storm. and once I have that picture, I can start putting furniture into the different rooms. And I will need different furniture, right, in the bedroom.
In my operations team, I need a different furniture than I need maybe in my sales team, in the kitchen. And you know, so I think there we need to be clear that there's no one size fits all in fur putting the furniture in into the rooms. But when it comes to the overall house, understanding your business, understanding what you care about, and then what capabilities you need to protect that.
Francis (15:47.628)
I'm gonna follow through with the furniture now and keep that analogy alive for the for the house just because just because we've gone down that rabbit hole. Patrick, so what when I think of furniture, I'm thinking of the the business dependencies. From from from your experience, are there any dependencies that get overlooked until the point where a disruption occurs? Is there is there kind of facets in organizations that, you know, people forget to put the chairs in the room with the desk or or, you know, anything in in that life?
Patrick (16:13.639)
Yeah, here's the thing, no, if you think about it, right, if you ask now this gets interesting, but if you ask the person who is responsible for the kitchen, right, they will not forget that they will need an oven, right? And they will not forget they need a pen. they will not forget that they need a knife. They know that, right? Because they use it all the time. Now if we sit somewhere as res you know, resilience professional and try to type into our favorite LLM, you know, what does a kitchen need?
That can help in terms of you know saying, hey, we worked this out, you know, let's validate, is that what what your kitchen needs? so in terms of dependencies, right? Are these the systems that you're using? Is this the data sets you're using, the suppliers? So that's stuff, that's information, that's already somewhere in in today's organization. And I think with AI, we have really as well an opportunity to accelerate the the a good way of doing resilience. And so
Yeah, I think the stuff that's been overlooked this may be something that's not obvious immediately. So electricity will be needed in entire house. So it does come up and it's a natural single point of failure. It's actually also in any organization usually a single point of failure. but there might be other things running through the house where you say, Okay, we need that in different places, but we even have we haven't really thought about that yet.
Wi-Fi connection, you probably want to have it in the entire house. And so nonetheless, there might be shared components in different rooms that that only once you create the bigger picture and you start connecting the dots, you understand, I actually need
for lack of better better idea now, but you know, I need something to clean every room. but I don't need that operationally immediately. so it only comes up when I connect the dot and say, like, hey, actually this this capability I need everywhere. So your single point of failure is your blast radius analysis, right? These are the things you can only do once you start, as you said, connecting as well the dots.
Francis (18:21.154)
I'm so happy you said electricity there because, you know, my mind was floating around active directory, out of band communications, you know, everything bar the one thing they all require to keep the lights on, which is the the electricity. So like I I think there is, you know, the making the make sure the kitchen guy is in the room and the office guy is in the room, you know, all of those heads do need to come together. I think that plays back to what we said earlier on in the conversation around, you know, the BAU teams maybe been in a two hour workshop.
Patrick (18:26.663)
Okay.
Francis (18:50.88)
And and that is is done. Like it's so important to have all of the different levels of expertise, that multidisciplinary kind of knowledge set within within the organization. 'Cause like obviously electricity is required, but you know, my mind didn't go there because I'm a cyber guy. You know, I was thinking I was thinking technology and, you know, interdependencies of technology sets. You know, electricity. You know, I mean damn.
Patrick (19:16.757)
And that is where I think the loss scenarios become really important, Francis, because it's it's if you try to figure out every, you know, threat scenario, now as well with front D AI, right? Everyone is is scared that the that the world will end. I don't think the the I don't think it's the ending. I think maybe it's the beginning of something new and great. But you don't know right what's going to hit you. and it's probably something different from what you thought it would be. But then
If you lose that component, if you lose your active directory, if you lose your electricity, right, do we know what to do? Right. I I I always like the electricity example because it's so obvious, right? And and then it doesn't matter whether you lose your electricity because of a snowstorm or because there's a general outage, or you know, there was some construction site outside. if your electricity is gone, it's gone, right? And the kitchen people are gonna be freaking out for the fridge.
Right, because you have to continue cooling down your stuff. And the person in in the in the home office is going to freak out for you know not being able to doing doing their their work. And so that means in the same house you have different impacts, but it's the same event, right? It's a loss of this component, and then what does it mean? And anyone who believes that a a business impact assessment with with hundreds of of rows or like
sixty, seventy, eighty, hundred B C Ps with ten, twenty pages is going to save you or or help you even. I sometimes these things, Francis, can become a liability as well. Right. If we if we believe in stuff that was developed once, put aside and then we try to orchestrate all of that. I would much rather believe that the person working in the kitchen actually knows what to do and hopefully have thought about how to cool stuff.
for a short period of time.
Francis (21:15.404)
No, that's that's really insightful, Patrick. And and and even the way you've just went, but it's a single event there is has kinda jumped out on me as well because you know, you you you think of all of the different scenarios, but a lot of those scenarios come back to singular event types. And if you can if you can cater for the event, then the scenario doesn't really matter because you're you're dealing with with that piece. So that again is interesting.
What I always find when I talk to Brazilians people, there is so many subtleties hidden in the conversation that, you know, are obvious but nobody ever says them out loud, which is I really enjoyed it. I also love the way we've kind of gone into a culinary side of it now as well.
Patrick (21:53.207)
Yeah.
Francis (21:56.766)
Patrick, can we can we talk about cyber resilience versus we're a secure organization for a minute, please? Because I I this comes up quite a bit in in in different conversations I have where, you know, people confuse the security of the organization with the resilience of the organization. So let's say, you know, we spent twenty million euro in the last two years on cybersecurity tooling and processes and improvements. but that doesn't necessarily mean you're resilient.
Patrick (22:27.159)
Exactly. and I think the cyber one makes it quite easy actually to to show as well. So now and I I'm sure that the listeners, you know, y wherever in whatever organization you are, there's a whole spectrum of how if we take the front E AI for example, right? That's that's a really great example. What's your strategy for all the developments, all these models that we very
little human inter action and intervention can actually you know connect different vulnerabilities, even low-level ones, and then escalate that at a speed that's very basically impossible for humans to catch. You can take multiple different strategies here, right? And some take that I need to prevent even more, I need to patch even faster, I need, you know, to ingrain certain practices even deeper, access management network.
Segmentation, all of these things, and they're incredibly helpful, also from a resilience perspective, right? So network segmentation, isolation, redundancy, immutability, right? These are all great capabilities that you can put in place beforehand. But believing, right, that that all this stuff will help you, of you know, that that nothing ever will happen, and then you know, you never have to even worry about.
get into a situation where you have to respond. I think that's that's the biggest misconception in in between security and and resilience. And I'm not academic about definitions, right? I think the the business is not academic about this either, right? It's basically, you know, we we for sure want to prevent certain things, we for sure want to do our due care in order to protect our business, our customers and what we care about. But we absolutely need to be realistic that, you know, what are actually our capabilities, that if something goes wrong that we can
absorb a hit and then we can sustain our operations. And from a cyber perspective, I think there's like so many different facets. Again, if you think about traditionally there was always this concept of well, if one data center fails, I'm gonna you know fail over to another one and then the other one is is going to save me. Now with the large scale cyber compromises, we know you know that may actually not be true because you fail over the compromise into the second one and then you like everything is compromised.
Patrick (24:43.637)
So you need to have an ability to restore from a completely maybe brownfield, greenfield, but definitely you know tertiary environment that's clean. So I guess the key points are prevention and doing your due care in order to putting the controls in place and making them also efficient, effective. Absolutely, yes. But if you don't have the capabilities to actually absorb a hit and continue your operations and also
have that conversation with the business that you know IT may not be here all the time. What does that mean to you? Or I can put in all the locks I want in my house. So no, you know, no one is gonna, you know, break into my house and steal something, but the still still something, you know, I can still have a situation like in Berlin we had in January, where you have basically, you know, parts of the city without electricity. the motivation again from a business perspective does matter, is this now a hacker attack? Well was that anything else?
the impact on the business side is is still that I need to sustain my operations. And I think this is where we need to be careful not to overinvest on the prevention side and for completely forget that the costly part is how long does it take to get our stuff together and be able to respond to a situation.
Francis (26:01.56)
thanks for that Patrick again. Great great insights. There there's one piece here, because you're talking about frontier models and I'm looking at AI as a really great value add in certain scenarios, but I also look at it as the potential to undermine the capability of a workforce. And I had Raheem Herjee on a couple of weeks ago and he talked about this idea of synthetic seniority, you know, where
People are coming with these brilliant ideas, but they don't understand the building blocks, they haven't got the knowledge or they haven't failed previously in in the technology and therefore it falls apart. But when I extrapolate that onto the resilience conversation, I'm thinking as we empower people more to utilize artificial intelligence across different processes and to define different outcomes.
If that capability is no longer available, do we need a human resilience lens that comes in under all of this to go, Are our workforce still capable when the machine doesn't do the thinking?
Patrick (27:13.811)
Yeah, but isn't that basically, you know, again, you have a a lost scenario, right? So AI in the end is still a technology. I think there's also a a philosophical component to to AI and what does it mean for the business. But when it comes to you know how much we rely on external systems to do the the thinking for us, sh sure, but but quite frankly
What's the difference with the electricity, right? It's very you know, if if you decide to completely depend on, you know, one source for for, you know, electricity, energy and so on, and and then you know everything runs on that and I have zero processes anymore, which by the way is not reality anyway, but so so I think there from a pure resilience management or strategy perspective, I would not necessarily be too worried about
Where innovation will bring us, right? I would just always try to be very clear and and figure out as well with business what the implications are, what it means, and what the confidence levels are that if that capability is gone, that we can sustain our operations, right? And if we can, then everything is great, right? Why would I not leverage innovation and technology to do it? So I get the point around, you know,
having high reliance on the systems. But honestly, I mean I think we've seen that since over a hundred years that with any innovation we we completely shift the the the reliance. I think the other component around people pretending that they know stuff that actually they don't know or things, you know, don't don't add up, every organization will make their own learnings there, I think. it's new still, it's been around for a couple of years, but I think in terms of you know enterprise adoption of AI,
Everyone is trying and playing around and everyone is making their learnings. From a resilience perspective, what I can see is similar to other areas. I think is if you have bad processes today, right? AI is a great tool to help you accelerate these bad processes. So you get even worse outcomes later. So you mentioned before, right? You can you can throw into your favorite LLM write me a BCP for this and that. Awesome, right? Maybe if you're lucky, you can you can generate a thousand BCPs.
Patrick (29:37.137)
it's not going to help you that much. So I think from a resilience perspective, we also have an opportunity to to leverage the innovation that's there, what it can do, and and take that as an opportunity to maybe revise a couple of processes that we have.
Francis (29:53.538)
Very balanced, Patrick. Very balanced indeed. you didn't you didn't say anything controversial there at all, which is unfortunate for my sound bite, but but brilliant for the conversation. Patrick, I I I want to I wanna switch for a second and talk a little bit about the co founder and setting up a business and and and the reason for this is I talk to a lot of people who have come from consultancy or from a background that's deeply technical and then they've
They've gone into into business, they've they've built a company and an operation and you know, started to make a success of it, etc. That the one thing that that I always look at and I and I find it very admirable is there's a purist view sometimes in consultancy around the lines that must be in place for an of an organization to be secure or be resilient, etc. When you swap into the owner position and the checkbook
Is on your side of the desk around what it costs to do certain things, those decisions become a lot more pointed. Did you experience that the the that piece where you kind of went, This is what perfection looks like, this is reality, we're gonna be somewhere in the middle here to make this this work? As as an operator, switch switching switching from the the consultancy piece into I'm now a business owner.
Patrick (31:07.703)
You mean you mean as an operator, as a provider? Yeah.
Patrick (31:17.313)
Yes.
Francis (31:18.038)
Now the bills stop with with me, and therefore the decisions need to be balanced in the pragmatism of profitability and all of those things.
Patrick (31:20.565)
Yeah, yeah. Yeah, yeah, yeah.
I I love that, Francis. Thank you. I was lucky because I had almost like a transition period out of consulting. I then was leading in a in a in a lean tech company already, security and resilience. So I came, you know, from the big corporate consulting world where, you know, you tell me or I tell you basically what what what you have to do. That's good practice, this is how it's done, and then you have like a long shopping list. to you
I came in with a long shopping list and they're like, sure, go ahead, do it. And like, well, I can't do that on my own. It's like, well then you gotta prioritize. So that was the first big kind of im almost like inspiration to start something like Resume. It's like, my God, right? If you don't have unlimited resources, it's going to be very difficult to prioritize and know, you know, where do I get the biggest biggest bang for the buck? So concretely for us, I think what helps us tremendously.
Is that we have a risk management background, right? We're coming from cybersecurity, we're coming from cyber resilience. So for us, it's always a non-negotiable. So I had experiences, and I give you a very concrete example. I had experiences in the past. You have software as a service providers that may use a multi-tenancy architecture. That means you have in one shared infrastructure, you have different client environments. Now, I saw in companies what it means if that multi-tenancy architecture breaks.
So that means you know one client can, because it's everything living in the same database, one client can access data from the other client. Not great. especially not great explaining your clients why that happened. And even if the impact is not good, or sorry, is not great or not massive, you still don't want to be in such a situation. So for us, it was clear we're gonna put in a single single tenancy architecture, right? Every client is completely isolated on their own. The same now with LLMs, right?
Patrick (33:17.979)
it's very, very easy, for instance, to kind of like go out and build a wrap around Claude or any of these you know, LMs and then say, like, I have this amazing AI tool. It's not super secure, right? And there's a lot of things that can go wrong. So we were like we're making a lot of conscious decisions in our design. And I think we we try to be very balanced between and we almost like, you know, live what we're trying to preach as well, is
The documents are not gonna save you, right? It's the actual capability, having the things in place. And and the the Pareto principle, you know, what are the the 80-20 rules in terms of, you know, if you do these things, isolation, encryption, access management, right? you get pretty far with these concepts. And if then someone comes and says, like, I wanna see your you third party cyber risk management assessment process, yeah, or evaluation criteria.
we will be able to to to handle these conversations if you know what I mean. So your point on prioritizing in a real operational environment, that's the very core of of why we even built resumates.
Francis (34:26.892)
No, that's that's perfect. And and I I I I had to ask 'cause I I I remember this struck me. I was doing the SABSA course a number of years ago. and the instructor at the time said, I'm teaching you guys all this stuff now, but if you come to me as the CEO of this business and tell me I need to do something, you better have a goddamn reason why I have to do it before I put my hand in my pocket and spend the money. And don't point back to my book. You know? And I I just went.
Patrick (34:27.955)
Sure.
Francis (34:56.226)
This is this is a beautiful, you know, scenario where the reality of who owns the purse strings dictates what gets done. And I and I think it's something that we miss sometimes as as technical individuals or in a consultancy lens that someone has to pay for this to be enacted at the end of the day. So you better be sure it's worth the it's worth the money. And, you know, that's why I always find it interesting to ask that question to
business owners who have stepped over the line from one world to another to see what it is. So that's a that's a great insight, Patrick. So thanks very much for for sharing it. Patrick, before we finish up, I want to talk about tabletop exercises for a minute, because I've mixed I've mixed opinions here and I'd like to get your viewpoint. Are they useful or did it just kind of reward people for performing preparedness?
Patrick (35:54.328)
So, because we we we use so many analogies today, one for tabletop, the one I like most is it's very similar. If you wanna be fit and strong and healthy, right, you shouldn't go to the gym once a year for seven hours and hope to be fit for the rest of the year, right? You're gonna be sore for a week. and then that's pretty much it. And I think you should go more frequently, right? You maybe you go every week and maybe you just do like two, three times.
For 30 minutes, it's definitely more valuable. And I think the exact same way about the tabletop exercises. I think if you do it for, you know, optimizing on I need to do one exercise per year, and then it's seven hours, and then you know, it can be valuable, but it can also be like, you know, months and months of preparation. then one great day, everyone high five saying that was a great experience. And then you know, the day after you have like a hundred and forty-nine follow-up action items, and then three weeks later no one really remembers them anyway. So
I think tabletop exercises can be incredibly powerful when they bring people together, when they are fed by a real a real foundation, right? The foundation we we said we're gonna build for the house, understanding how your business works, what are the dependencies, you map the lost scenarios, right? If you take these things that real are, and then you have the right people together and they just start talking together and how things would actually work and run.
Then tabletop exercises, even if it's just 20 minutes, can be super valuable. If it's just a walkthrough, right? How would we do that? Would we be able to do that and have an honest conversation rather than a performance conversation? I think that's an incredibly powerful way to start the whole planning and capability building journey. and then you can increase the sophistication, right? If you feel like, look, we've been talking about this, people know each other, people know the how we would actually respond.
Now let's start testing it, right? And let's start testing it not just in a function, but maybe cross-functions. And I've seen tabletop exercising going through four different days where you have, you know, from the SOC escalation into a production environment, into the executive team having to make a decision on ransomware, all the way to the recovery team actually recovering. You can again, if you try to connect these dots, you immediately see the value if that's not made up but real. So
Patrick (38:18.985)
Rather than once a year for seven hours, let's do smaller exercises more regularly, different kind of scenarios. And if we feel quite confident, we can, you know, start also functional testing, going in there, critical path recovery. I think there's like no shortage of good ideas on what you can do to to test your confidence levels.
Francis (38:41.368)
So my takeaway from that is tabletops without theater have value, but make sure it's in the raw, honest conversation that shows the lineage through the organization. So that's again, a great insight, Patrick. Patrick, before we finish up, is there anything I've left on the table here that you wanna bring to the listeners or have we got through all of the key points?
Patrick (39:05.035)
I think I think it was a great conversation, Francis. if I wrap up on my side, I think, you know, for years we have optimized on documents, building a lot of documents, chasing people to do it. In reality, resilience works in a way that we build capacity and that we use capacity and the ownership is with the business. So we are here to to enable and support them. In the end, the the plans are might be useful for planning, but when something hits, it's really about
the people that have built the trust beforehand, that know the shared principles, they know how, you know, the rhythm works so that you condense the time you're actually able to respond and be able to withstand and absorb any types of hit regardless if it's from D AI or a snowstorm.
Francis (39:54.06)
Patrick, it's been lovely having you on. Thanks for the the the synopsis at the end to bring it all to together. Really insightful conversation. Have a great day.
Patrick (40:02.657)
Thank you, Francis. Have a good one. Bye.
Francis (40:04.45)
Thank you.