Resilient Organisations Practise Until Response Becomes Routine, Says Horizon3.ai

Image credit: Dan Bird / Horizon3.ai

Editorial Brief
At a glance: AI-assisted overview, optimised for journalists, search & news aggregators
Press Release

London – 4 March, 2026

Snehal Antani, co-founder and CEO of security firm Horizon3.ai: “Cybersecurity teams should build ‘muscle memory’ so they’re prepared when it really matters. The principle of constant practice, well known from disaster recovery, applies equally to cyber resilience.”

“Cyber resilience often gets treated as a new challenge driven by modern threats. It isn’t. We solved a version of this problem decades ago in disaster recovery. The lessons still apply,“ said Snehal Antani, co-founder and CEO of cybersecurity company Horizon3.ai.

Horizon3.ai is regarded as one of the leading providers of offensive security. This approach involves organisations continuously testing their own IT environments through continuous penetration tests to uncover potential weaknesses that cybercriminals could exploit.

Continuous pentesting represents a shift from the traditional—and still common—model of passive defence, where organisations surround their systems with as many protective layers as possible and hope they will withstand an attack, without putting that assumption to the test. Today, there are technologies available that allow organizations to safely hack themselves, fix their issues, validate their fixes, and repeat this process as often as they like.

Parallels between cyber resilience and high availability systems

Snehal Antani draws comparisons with the high availability of IT systems—often referred to as business continuity: “Downtime is not acceptable. Failures are inevitable, so you practice for them. Systems are intentionally failed over from one data centre to another every month or every quarter—not because something is broken, but to gain proof that recovery works. Repetition builds confidence. In a crisis, you don’t debate—you act. You train the way you need to operate when it really matters. That discipline creates a kind of muscle memory. Resilience isn’t a policy document sitting in a folder; it’s an operational habit built through repetition and accountability.”

This resilience model—making continuous rehearsal for the real event a guiding principle—aligns with the concept of offensive security and is, Antani says, the best modern response to the growing threat of cybercrime.

Snehal Antani explained: “Today, cyber resilience often gets framed as a tooling, compliance or reporting problem. New frameworks emerge, dashboards improve, metrics multiply. But none of that guarantees performance when systems fail under pressure. In reality, cyber resilience represents the same operational challenge disaster recovery faced years ago: systems fail, attackers exploit weaknesses, and the business still needs to recover. Customers expect availability, and regulators demand accountability.”

Resilient organisations practise until action becomes routine

The security expert contrasted active and passive approaches to security: “Resilient organisations accept reality. They assume something will go wrong. They look for weak points before attackers do. They rehearse response and recovery until execution becomes routine. Other organisations rely more on assumptions—a highly fragile approach. Defence and recovery plans often look solid on paper but frequently fail in practice. Backups exist and processes are documented, but regular testing to prove it works in a real incident is missing. Cyber incidents expose that weakness—often with more serious consequences.”

The co-founder and CEO of Horizon3.ai gave a concrete example: “When a server crashes, the cause isn’t immediately clear. It could be an operational issue, or malicious activity. Until the team knows for sure, they have to treat it as both. Service restoration can’t wait for perfect attribution. In those moments, disaster recovery and cybersecurity converge. Restore operations first. Investigate second. That requires teams that have rehearsed together, not siloed plans that have never been exercised under pressure. It’s rarely a tooling problem. Rather, it’s a process problem — and a leadership problem.”

One penetration test a year is far too little

Antani pointed to a basic rule of disaster recovery: a backup is only a backup once it has been successfully restored. In cybersecurity, he said, the equivalent principle is often ignored. An annual penetration test—where an organisation attacks its own IT systems to identify weaknesses—offers limited assurance in an environment that is constantly changing. “Risks change faster than annual cycles can capture,” he said. Patches arrive weekly, configurations shift, new services are introduced, and cloud and identity architectures continue to evolve. “Without regular security validation, leaders make decisions based on incomplete information. They believe risk gets managed, while in reality those risks have already shifted,” Antani warned.

He recommends running regular pentests closely tied to change. Patch cycles should be followed by validation, with results reviewed on an ongoing basis. The goal, he said, should be continuous improvement: “This cadence matters, because attackers don’t operate on annual schedules. They adapt continuously. Defenders need feedback loops that move at a comparable pace. Incidents will happen. What sets resilient organisations apart is how well they prepare for the real event. That preparation isn’t built during a crisis—it’s established beforehand, through repetition and leadership commitment.”

A new phase of cybersecurity driven by artificial intelligence

He continued: “Resilience reflects what organizations choose to rehearse and measure. What matters are regular drills, clear ownership, and a bias toward validation over assumption. It’s not easy—especially in large, complex environments—but complexity doesn’t remove the obligation to test. From my time in the military as a civilian CTO, one lesson carries over directly: Under pressure, teams don’t rise to expectations. They fall back on training. Preparation determines performance.”

In the view of Horizon3.ai’s co-founder and CEO, cybersecurity has entered a phase where speed matters even more. He explained: “AI-driven attacks compress timelines. Humans will increasingly manage by exception. Organisations without trained muscle memory will have very little margin for error.”

Notes to editors

About Horizon3.ai. Horizon3.ai’s NodeZero® platform is trusted by 40% of the Fortune 10 companies, the world’s largest banks, top global pharmaceutical and semiconductor manufacturers, critical infrastructure operators around the globe, and the US Defense Industrial Base to proactively find, fix, and verify exploitable vulnerabilities to continuously fortify cyber defenses and improve cyber resilience. The fastest-growing cybersecurity company in America (Inc. 5000, Deloitte Fast 500), Horizon3.ai was founded by a mix of US Special Operations veterans and industry experts and is headquartered in San Francisco.

Get more news like this

Get more news like this on Google. Set News By Wire as a ‘Preferred News Source’ to get quicker access to news that’s important.

All done!
Thank you for subscribing.

Email Subscription