Sicra Header Logo
  • Careers
  • About us
  • People
EnglishNorsk
Talk to us
  1. Knowledge
  2. Insights
  3. Blog
Blog
24.09.2026
min read

Gaute Lien: What makes organizations resilient to cyberattacks?

While dramatic cyberattacks, ransomware attacks, and sensitive data breaches receive significant media attention, Gaute Lien, CEO of Sicra, believes the foundations of resilience deserve more attention. This is the security work that makes organizations resilient in an increasingly complex technology landscape. 
<span id="hs_cos_wrapper_name" class="hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_text" style="" data-hs-cos-general-type="meta_field" data-hs-cos-type="text" >Gaute Lien: What makes organizations resilient to cyberattacks?</span>
Editorial staff
Editorial staffAuthor

– The core of cybersecurity is establishing resilience. Few people notice this work, but it is critical to preventing things from going wrong, says Lien.

As part of Sicra's 10th anniversary, we interviewed our CEO, Gaute Lien, about what it takes to build digital resilience against increasingly complex cyber threats. Lien has worked in cybersecurity for almost three decades and has developed several unique frameworks related to security.

Three areas of focus, and one that is missing

When people talk about cybersecurity, they usually focus on three areas:

  • Major incidents: attack/penetration testing, detection, response, and recovery.
  • Artificial intelligence (AI): Which both enables more advanced attacks and strengthens defenses.
  • Geopolitics and societal security: critical infrastructure, preparedness, compliance with laws and regulations, and collaboration with public authorities.

Lien highlights an underlying area that he believes deserves just as much attention: How to build digital resilience into organizations. Especially when companies launch transformation programs or major IT projects, they often lack sufficiently structured security governance.

Since its founding in 2016, Sicra has delivered tailored technology and cybersecurity services designed to make organizations resilient in an increasingly complex and unpredictable digital world. Sicra's approach to security is rooted in Sicra's security triangle, a model that combines security management, deep technical expertise, and continuous monitoring. This helps secure organizations across their entire technology platform.

After 10 years as a technology and IT security company, Sicra has developed a deep understanding of what actually makes organizations secure. This also includes the costs faced by organizations affected by cybercrime, both financial and intangible, such as reputational damage. Security also has an upside through increased trust in technology and greater user adoption.

Security management: essential for digital resilience

– There is a lot to gain on the technology side, but when things fail, the reason is often a lack of security management or insufficient governance of security activities. That is why we are investing more in our dedicated security management practice, says Lien.

– A lack of security management is also the main reason major transformation programs and IT projects fail or are stopped. I could list 12 to 15 major modernization projects that have been halted or significantly delayed because critical shortcomings were identified in areas such as privacy, GDPR, patient data, or the use of cloud services. The cause is a lack of operating models and governance related to security management, he continues.

The paradox is striking: Security typically accounts for 10–20% of the budget in major projects, yet there are hardly any governance frameworks for this part of the budget. Even Digdir's Project Wizard is unclear and incomplete in parts of this area.

A construction site has better security than the finished building

Lien uses a fitting analogy: A construction site has far stricter safety requirements than the finished building: Restricted areas, access control, protective equipment, and secured elevator shafts. The same principle should apply to IT projects.

– The security foundation has to be built into a project as it progresses. Without experienced security professionals involved throughout the process, you lose critical expertise and overlook digital weaknesses. Basic penetration testing is not enough. Failed projects result in billions in wasted spending and CIOs losing their jobs, says Lien.

The consequences are not only financial. Security shortcomings are often used politically to obstruct transformation projects. And when users lose trust in digital solutions, whether public or commercial, they stop using them. Security therefore directly affects a project's ROI or an organization's top line through user adoption.

New technology requires a new security regime

Lien quotes the French philosopher Paul Virilio, who said: "When you invent the ship, you also invent the shipwreck; when you invent electricity, you invent electrocution. Every technology carries its own negativity, which is invented at the same time as technical progress."

– This does not mean that you should avoid adopting new technology, but that you need to rethink security. If you build a boat but are used to building cars, seat belts and bumper guards will not stop the boat from sinking. A boat needs different security mechanisms. The same applies to new technology, Lien emphasizes.

This applies to IT/OT convergence, where machines and control systems are connected to IT networks. It applies to millions of customer identities, which require a fundamentally different approach from employee identities. And it applies to identities for the rapidly growing number of Agentic AI systems, which Lien believes must be subject to the same security principles as human actors, including background checks, authorization, and behavioral monitoring.

– AI is trained to please you. That does not necessarily make it reliable. AI agents also need a four-eyes principle, he says.

Sicra's strength lies in combining several perspectives at the same time: Technical experts who understand solutions from the inside, together with experience from some of the most demanding security incidents.

The next step: Put security management in place

Sicra has security management as a dedicated area of expertise: Across network security, OT security, application security, and Microsoft solutions. This means integrating security expertise directly into program and project management as well as executive management.

– Conducting one risk assessment and one data protection impact assessment and calling it security governance is not enough. You need both security architecture and ownership of the development or integration of critical security capabilities throughout the entire process, Lien explains.

Strong security management creates predictability in terms of time, cost, and quality, while preventing security-related problems from returning like a boomerang in the final stages of a project. Strong security management is also necessary to build resilience and digital robustness. This helps ensure that the value the project is intended to create is actually realized. In addition, the resulting digital resilience delivers real value to the organization.

Need Assistance?

We are happy to have a non-binding conversation. 
Contact us

Explore more

Ten years. Ten stories from the front lines of cyberwarfare
Blog

Ten years. Ten stories from the front lines of cyberwarfare

Ten stories about how Sicra builds digital resilience against cyberattacks.
The future of cybersecurity: More regulation and three AI risks
Blog

The future of cybersecurity: More regulation and three AI risks

Hedvig Moe on growing regulation and three AI risks shaping cybersecurity.
Cyberattackers use AI, so cyber defense needs AI too
Blog

Cyberattackers use AI, so cyber defense needs AI too

Arctic Wolf on how AI is changing cyberattacks and how organizations can respond.
Digital sovereignty must be measured in recovery time, not by the flag on the vendor’s website
Blog

Digital sovereignty must be measured in recovery time, not by the flag on the vendor’s website

Digital sovereignty is measured by how quickly critical services are restored.

Stay updated
Receive the latest news

Links
SustainabilityFAQPartnersCertifications and awardsCareerPress & brand
Contact
Tel: +47 648 08 488
E-mail: firmapost@sicra.no

Drammensveien 151, 0277 Oslo

Follow us on Instagram

Follow us on LinkedIn
Certifications
iso27001-white
ISO 27001 compliance
miljofyrtarnlogo-hvit-rgb
Eco-Lighthouse
iso9001-white-removebg-preview
ISO 9001 compliance
Sicra Footer Logo
Sicra © 2025
Privacy Policy