Culture, Behaviour, Technology: The Three Pillars of Cyber Resilience

Organizations have never invested more in cybersecurity technology. Firewalls, endpoint detection, zero trust, cloud security, and AI-powered defenses have become standard investments. Yet cyberattacks continue to grow in both frequency and sophistication.

The reason is simple: attackers are no longer trying to defeat technology alone. They are targeting people and identities because they are often the fastest path into an organization. In today’s threat landscape, cyber resilience depends on three interconnected pillars: culture, behaviour, and technology. Weakness in any one of them creates opportunities for attackers.

Diwakar Dayal
Managing Director & Area Vice President – India & SAARC
SentinelOne

For many years, cybersecurity was viewed primarily as a technology challenge. Today, that mindset is outdated. While organizations continue strengthening their technical defenses, attackers have shifted their focus toward exploiting human behaviour through AI-generated phishing campaigns, deepfake voice and video impersonation, credential theft, and identity-based attacks. The human mind has become the new attack surface.

This shift is evident in conversations with CISOs and CIOs across industries. The consensus is clear: attackers are evolving faster than traditional defense strategies. Rather than spending months attempting to bypass sophisticated security controls, cybercriminals increasingly manipulate trusted employees into making decisions that compromise the organization.

A recent example from the banking and financial services sector illustrates this well. A senior executive approved a financial transaction after receiving what appeared to be a legitimate voice instruction that had been generated using AI. The organization’s security systems functioned as designed, but human trust was exploited instead.

This is why behaviour must become a strategic priority rather than an annual compliance exercise.

Traditional awareness training assumes that knowledge alone changes behaviour. In reality, modern attacks exploit how people respond under pressure, urgency, distraction, and misplaced trust. Organizations need continuous behavioural conditioning through phishing simulations, decision-making exercises, and contextual guidance that reinforces secure decisions during everyday work.

Technology remains essential, but its role is evolving alongside the threat landscape.

The same advances in AI that enable attackers to create highly personalized phishing campaigns and convincing impersonations also provide defenders with new capabilities. AI can identify suspicious behaviour, detect identity-based attacks, and intervene before human error turns into a security incident.

Organizations that have embedded AI-assisted decision support into everyday workflows are already seeing measurable improvements. By providing timely recommendations during high-risk situations, they have reduced human errors and strengthened resistance to phishing attacks. Technology delivers its greatest value when it works alongside people rather than operating independently.

The third pillar, however, is often the most overlooked: culture.

Cyber resilience cannot be owned solely by the security team. Organizations with the strongest security outcomes treat cybersecurity as a business responsibility shared across leadership, employees, and functions. Boards recognize that human readiness deserves the same attention as infrastructure investment. Employees are encouraged to report suspicious activity without fear of blame, security discussions become part of everyday business conversations, and resilience becomes embedded into how the organization operates. This is also reflected in India’s evolving cybersecurity approach.

In 2025, CERT-In conducted more than 120 cybersecurity drills and tabletop exercises involving over 1,500 public and private sector organisations, placing equal emphasis on testing decision-making, incident response and organisational preparedness alongside technology. The message is clear: resilience is strengthened not only by better security tools, but by preparing people and organisations to respond effectively when attacks occur.

This cultural shift also requires organizations to rethink how success is measured. Completion rates for mandatory security training may satisfy compliance requirements, but they reveal little about actual preparedness. More meaningful indicators include how quickly employees recognize phishing attempts, how effectively teams respond during simulations, whether risky behaviours decline over time, and how consistently secure practices are reflected in day-to-day operations.

Technology, behaviour, and culture cannot operate in isolation. Technology provides protection, behaviour determines how people respond under pressure, and culture reinforces secure decisions every day. Focusing on only one of these areas creates gaps that attackers are quick to exploit.

Cyber resilience is no longer defined by who has the most security tools. It is defined by an organization’s ability to bring together technology, people and culture into a single resilience strategy. In an AI-driven threat landscape, the organizations that succeed will be those that strengthen all three pillars together, ensuring that people are equipped, technology is intelligent, and resilience becomes part of everyday business.

Authored by Diwakar Dayal, Managing Director & Area Vice President, Sentinelone India & SAARC

Author