🎧 Listen now to The Resilience Room
"Resilience" gets used like a mood board: everyone nods, nobody defines it. Corey Ray and Abe Burnett came on the show to fix that — and their conclusion is uncomfortable. Most security teams aren't failing on sophistication. They're failing on depth.
There's a version of the resilience conversation that never leaves the runway — big words, warm nods, no traction. This episode is the antidote. Corey and Abe work together at Immersive turning what customers actually do inside the platform into strategic analysis leaders can act on, and they arrived allergic to hand-waving. Over an hour they pulled apart what "ready" and "resilient" really mean, built a scorecard you can't easily game, and landed on the one gap that shows up in almost everyone's data. Here's the argument.
1. The difference is time
The two words get swapped around until they mean nothing. Corey's fix is to treat the distinction as temporal. Readiness is everything you do before the shock: the preparation. Resilience is what happens during and after it — your ability to absorb the hit and keep the business running. Crucially, one depends on the other: there's no resilience without readiness underneath it.
Corey, who ran his first bike race last year, reached for cycling to make it concrete. Readiness is the training, the right kit, having ridden the route before. Resilience is the mechanical flat or the spill mid-race — and whether you get back up and finish. You can only find out how resilient you are once your feet are to the fire; readiness is the bet you place before you know.
Abe's addition, straight from a data background: imprecision hurts you. The moment a word goes hand-wavy it stops driving decisions. So the definitions can't be borrowed — they have to be yours. An OT utility and a bank don't get to share a definition of "ready," because the shocks, the regulators, and the stakes are nothing alike.
"Perfect safety means you have a dead business. If you reduce risk to zero, the business is dead." — Abe Burnett
2. Name the enemy
Their sharpest move is to drag resilience out of the abstract. Instead of asking "are we resilient against some undefined black swan?" they ask a question you can actually measure: how ready are we against this threat actor? Scattered Spider. A specific nation-state group. Named adversaries have observable behaviours, so you can measure yourself against those behaviours rather than against a vibe.
That thinking grew out of the team's Threat Intel Digest — an Immersive read on what threat actors are doing, viewed through a global lens, then an industry lens, then down to the individual customer — a version of which now lives inside the platform. And it maps neatly onto how security leaders already think: most CISOs already have the handful of actors that keep them up at night. A readiness score against those specific actors is the thing they're actually asking for.
3. The scorecard, and the gap almost everyone has
The readiness score they described rests on three legs, kept deliberately simple so anyone can read it:
- Coverage — a mile wide. How broadly your capability spans the frameworks and threats that matter to you.
- Proficiency — proven skill. How good you actually are at what you do, demonstrated rather than assumed.
- Depth — a mile deep. How far the bench goes. If one person is out, does the capability survive?
Here's the finding that lands hardest: in the data, most organisations look strong on coverage and proficiency and fall down on depth. They have a concentrated, highly capable few — the starting quarterback is excellent — but the bench behind them is thin. Even organisations in the thousands often lean on a small, proven handful.
"You go to war with the army you have, not the army you want. You don't get to choose the day — and a third of the people you're counting on won't be there."
Why depth erodes: roughly 20% annual turnover at many firms, layered on top of restructurings and role changes, layered on top of plain skill atrophy — skills go stale when they aren't exercised. And the cruel twist Corey names: your most proficient, most motivated people are also your biggest retention risk, because they're the ones who can most easily leave.
Attackers know the calendar. When Sam joked that you'd hack a company in summer when everyone's on holiday, both guests agreed it's no joke — holiday windows and Christmas Day are well-worn attacker behaviour, precisely because that's when the bench is thinnest.
4. Depth is the metric you can't game
That's the quiet strength of anchoring on depth: it has to be earned across the whole organisation. You can dress up a lot of numbers, but you can't fudge whether your capability is real ten people deep. And when Corey looks at the top performers in the data, they share one thing — a security culture that runs top-down, where everyone's marching to the same drum and security is a shared responsibility rather than a mandatory box.
Underneath it all is a design principle the two are unusually strict about: everyone should be able to read it. From the CISO to the janitor, if a person can't repeat back what a score says, it'll get lost the moment it circulates. No black-box, "trust me, bro" methodologies. And every insight has to point at an action — because insight that doesn't inform a decision is just noise drowning out the signal.
5. "We'll risk it" is an accounting decision
Abe reframed the chronic under-investment in cyber as a clash between accounting cost and economic cost. Run the narrow expected-value maths — low odds of a severe hit this year — and skimping looks perfectly rational. (People ride motorcycles, after all.) Widen the lens to the true economic picture and the calculus flips: your performance over time is bigger if you invest more up front.
Which is why framing matters. Treated as the "house of no" — the red-tape team that blocks hundred-million-dollar projects — risk gets starved of budget. Treated as an accelerator that keeps the business moving without disruption, it earns investment. Corey's unlock for getting leaders there is peer benchmarking: anonymised, curated cohorts that show a company its percentile against its industry, geography and segment. Nobody wants to be the laggard — and "we knew we were behind and did nothing" is a brutal line to deliver to a regulator. It also hands an executive a real number to be measured by.
6. AI: the chairs are moving
Abe's metaphor for the AI moment: musical chairs, except the chairs are dodging and weaving away from you — and suddenly there are fewer of them than ever. His working take is that a human still has to own the outcome, because AI can't hold legal responsibility; if a model deletes a drive or misses an attack, a person pays. But he's honest that the reliability gap is closing, which raises an uncomfortable question about what's left for humans — are we becoming "glue people," joining together what the machines produce?
He's also sceptical of the "fully agentic SOC" claims. When customers say they "built their own AI," what they usually mean is a behaviour-and-identity layer bolted onto a foundation model from one of the big providers — not a model of their own. Corey's worry runs the other way: AI turbocharges the vendor-concentration and third-party risk the industry only recently agreed was a problem, and does it while core skills quietly stop being exercised by humans.
A bright spot for defenders. Abe flagged a piece he'd read that morning on a neat inversion: defenders using prompt injection against attackers' own jailbroken models — for example, slipping in a reference a China-based model is trained to shut down on, so the attack stops itself. As attackers evolve, defenders are evolving too.
7. The real threat: apathy, atrophy, and blind spots
Asked for the single biggest issue right now, neither reached for a shiny new attack. Abe named apathy: something like half of organisations still have no mandatory practice, even as attacks grow in velocity and severity. His analogy is a gym you visit once — you don't do a set of curls and stay strong for life, yet plenty of teams treat security training exactly that way.
Corey's answer was blind spots from a non-programmatic approach. Upskilling measured against a framework is good — but if there's no business-continuity exercising, no live ranges, no putting people under fire to see how they actually perform, you're only working one muscle. Which gave the episode its best sign-off: whole-body training, individuals and executives both exercising under live conditions and then together. Sam's name for it stuck.
"Cyber Pilates. Whole body, working together." — Sam Dickison
The takeaway: readiness is a practice, not a checkbox
The thread running through all of it: stop treating resilience as a feeling. Define it in your own terms, measure it against real adversaries, and be honest about where the bench runs thin — because depth is the thing that fails first and the thing you can't fake. The readiness score isn't perfect, and the guests are the first to say so. As Abe put it, borrowing from statistics: all models are wrong, but some are useful. Directional and honest beats precise and hand-wavy every time.
Who's in the room
Corey Ray came up through the risk world — geopolitical risk and global supply chains, then third-party and vendor-concentration risk across cyber, finance and ESG. The subject got personal: a rural Georgia school district where his mother works was hit by ransomware while he was interviewing at Immersive. A cyclist who ran his first race last year — which is where a few of his metaphors come from.
Abe Burnett is a self-described builder who came up through data — economics, maths and computer science, then data analytics in banking and finance, a first data-scientist role building a credit-decisioning system for a small-business lender, and a stint in ed tech — before AI arrived and, in his words, felt like "a dream come true." He hates an inefficiency more than almost anything.