Back to All Resources

3 Ways to Build Cyber-resilience

Illustrated graphic showing connection among various cybersecurity fundamentals that build cyber-resilience

MCIT’s enhanced cyber coverage (see July 2026 Bulletin) is not a defense. Rather, it helps members manage the financial consequences after an attack or data breach. The real defense is an entity building cyber-resilience to protect the organization from risk in an evolving threat landscape.

Members should take steps to reduce the likelihood and impact of a successful attack. This means implementing layered controls, educating employees and having sound policies.

1. Protect

Many security programs and tools are available, which are often required by other coverage providers. Although MCIT does not currently have any technical requirements, it is in the best interest of individual members and the pool as a whole for members to implement these basic security measures.

Endpoint detection and response (ERD) acts like a 24/7 security guard that aims to detect, contain and respond to perceived threats. Protecting machines and servers from suspicious behavior is a basic level of defense.

Multifactor authentication (MFA) requires users to verify their identity using two or more forms of authentication before they gain access to an account or system. This is accomplished by sending a code to a separate device than a computer, such as a mobile phone or security fob. This is critical to combat unauthorized persons accessing data. For MFA to be most effective, employees should be prompted for a code at least once a workday (every eight hours) when logging into systems. Spacing MFA verification over longer periods essentially makes the system as vulnerable as if MFA were not enabled.

Email security to prevent phishing scams, malicious links and spoofed or imposter emails from reaching employees’ inboxes. Programs that filter out known attacks and identify suspicious attempts are critical.

Backup and recovery systems help mitigate the impact and ability for threat actors to hold critical data hostage. If the stolen data can swiftly and easily be recreated or restored, the monetary value of the data to the threat actors is significantly reduced.

Remember, too, that email is for the temporary sending and receiving of messages. Any information contained in those messages that needs to be maintained should be moved to a secure, permanent storage location, such as the local network server. This is especially important for sensitive or protected information that an employee needs to keep.

Email is not a secure storage location. For more details about email and data security, see these resources:

2. Train

Making cybersecurity part of regular employee training is vital. Because email phishing remains one of the most common ways attackers gain access to an organization and its sensitive data, training employees can significantly reduce risk.

Perhaps the single most important security tool is the human firewall, meaning employees actively help protect an organization. These folks are able to recognize and avoid threats and notify or report suspicious activity when they see it.

But employees must be taught and reminded about how to identify threats. No one instinctively knows how to do this. Members need to give their employees the tools and training to be an effective human firewall.

MCIT offers a number of resources to assist members in training their employees. Check them out at MCIT.org/resources (choose the “cybersecurity and data security” Topic filter).

3. Plan

A member’s incident response plan is key to navigating an actual cyberincident effectively. Members should assess their vulnerabilities, develop a response plan, and test and update it regularly.

Developing and regularly testing an incident response plan helps ensure that employees know their roles and to act quickly and correctly if and when an incident occurs.

The main goal is to understand the key aspects and needs of the entity’s business continuity. Making these decisions before an incident is critical. Having established plans before they are needed makes responding to an event much easier.

Members should work within their organizations to determine which departments and systems need to be brought back online first and which departments can be offline the longest. Other decisions, such as how payroll and citizen communications, should be handled during an outage should be factored as well.

Lastly, members need to practice their plans after they have been established. Based on the tests, members should modify the plan as issues are found and operations change. Just as the threat actors and threat landscape evolve, a member’s defenses and responses must as well.

Risk Management Consultant Assists Members

MCIT’s risk management consultant who focuses on data- and cybersecurity can assist members with their questions around these three fundamentals of cyber-resilience, and other concerns. Contact Richard Miehe at 866.547.6516.

Check Out More Cybersecurity Resources

See the Resource Library (select “cybersecurity and data security” Topic filter) for articles and tools to assist in building cyber-resilience, such as:

Topics