Est.

Reframing Cybersecurity Categories After Major Breach Events

How major 2025 breaches forced the security industry to abandon prevention and embrace resilience.

Staff Writer · · 10 min read
Cover illustration for “Reframing Cybersecurity Categories After Major Breach Events”
Category Displacement · October 4, 2026 · 10 min read · 2,255 words

JLR stopped making cars in the fall of 2025. Attackers got into the company's SAP NetWeaver system, an unpatched piece of enterprise software running the backend, and production halted across plants in the UK, Slovakia, Brazil, and India. Around the same time, another major retailer watched its online orders stall for roughly six weeks after attackers impersonated contractors to trick a helpdesk into handing over Active Directory credentials. Collins Aerospace's vMUSE platform, used to check passengers in at multiple airports, got hit with ransomware and airport staff had to fall back to manual check-in. Three unrelated companies, three very different attacks, one shared outcome: operations stopped.

Each breach forced the word "prevention" to retire from active duty, exposing the pattern underneath those headlines. For decades, prevention organized the entire cybersecurity category. Vendors sold the promise of keeping attackers out, and buyers scored vendors on how well they kept that promise. That word worked as a buying signal because it mapped to something concrete: a wall, a perimeter, a yes-or-no outcome.

Words don't fail quietly in an industry this size; they fail the way a bridge fails: fine for years, then all at once, in public, with everyone watching. Once "prevention" failed at scale and in full view of boards and regulators, it stopped doing its job as a buying signal. Buyers quit organizing decisions around it. Vendors who kept leading with it got tagged with the failure instead of the capability, a forced substitution the breach evidence made.

What "prevention" promised and why 2025 breaches made that promise untenable

Prevention-era language assumed a world with clean edges: attackers outside, assets inside, a vendor standing at the gate. That model made sense when the biggest risk was someone breaking through your own firewall. It stops making sense the moment your biggest risk is a contractor's helpdesk three companies removed from your network.

Look again at the 2025 pattern. None of the three breaches above happened because a company failed to patch its own front door. JLR's exposure ran through an ERP platform. M&S got in through credentials stolen by impersonating a third-party contractor; SIM swapping is a tactic Scattered Spider uses generally, but it hasn't been confirmed as the method in this specific case. Collins Aerospace's damage spread through a passenger processing platform shared across airports, so one weak point took down check-in counters nowhere near each other. Initial access, across all three, ran through shared vendors, cloud integrations, and third-party software, not through a hole in the organization's own wall.

The goals behind these attacks shifted too. Threat groups stopped treating data theft as the main prize and started treating disruption as the prize itself: halted production lines, stalled online orders, grounded check-in desks. That's revenue loss and supply chain stoppage, not just a leaked spreadsheet.

The Bank of England made the shift official when it confirmed the JLR attack had hit UK GDP growth. A cyberattack appearing in a national growth figure shows that "IT safeguard" is no longer a big enough frame to hold the problem. None of this means prevention tools quit working. Patching, firewalls, and endpoint protection still matter day to day. What collapsed is prevention's ability to anchor a vendor's identity, because the most damaging breach patterns now run straight through shared infrastructure that no single vendor, however good its wall, actually controls.

How "resilience" became the category's new organizing noun

Prevention's replacement didn't arrive through a branding workshop. "Resilience" earned its spot because regulators, boards, and frameworks started requiring it. The practical question inside organizations flipped from "how do we keep attackers out" to "how do we keep operating once they're already in." That's the whole shift in one sentence: survive the breach instead of promising there won't be one.

The paperwork caught up fast. NIST's Cybersecurity Framework 2.0 made governance a core function in its own right, putting cyber risk oversight on the desks of executives and boards as well as technical teams. The framework stays voluntary; nobody's required to adopt it by law. But its influence on how companies structure their reporting has been large enough to shift the vocabulary anyway.

Then came the contracts. CMMC's final rule, the Program Rule, published October 2024 and effective that December, tied eligibility for defense contracts directly to a company's demonstrated cybersecurity maturity. The DFARS Procurement Rule followed, published September 2025 and effective November 10, 2025, locking that same requirement into federal procurement. Resilience stopped being an aspiration printed in a mission statement and became a line item a company either qualifies for or doesn't.

CIRCIA's proposed rules add another layer, requiring covered entities to report serious cyber incidents and ransomware payments within tight, tiered deadlines. It's a compliance standard built around continuing to operate. Once a term gets written into a regulatory framework, it turns into a procurement requirement. Buyers need it in board reports. Auditors need to certify against it. If a vendor can't speak it fluently, it gets excluded from deals before the conversation even starts.

The National Cyber Security Centre made the handoff to the public complete. After the carmaker's outage, a national cybersecurity agency advised firms to have a plan for how they'd keep operating without their IT, and that line traveled into the mainstream business press. Resilience language had reached an audience far outside the security function, which is the real test of whether a category term has taken hold.

Why internal vocabulary fails to keep pace with the category shift

Outside the building, the vocabulary has already moved. Inside most security teams, it hasn't. Security reports still run on patch counts, CVSS scores, and firewall block totals, because those are the metrics that made sense when prevention was the organizing idea. Executives, meanwhile, are thinking in revenue continuity, regulatory exposure, and reputational risk, which is resilience language whether anyone upstairs calls it that or not.

A board asks, in plain resilience terms, "are we safer than we were last year?" The answer that comes back, built from vulnerability counts and compliance checkboxes, speaks a different dialect. Even when the technical substance is sound, the initiative stalls at the board level because the question and the answer aren't using the same words to mean the same thing.

Risk registers show the problem in its purest form. If those registers don't adopt language that ties directly to enterprise value, instead of listing abstract threat categories, they stay useful for passing an audit and useless for actually moving a strategic decision forward. A register that reads like a compliance form will get filed like one.

Call this what it is: language debt. Every quarter that the public-facing vocabulary of the category and the internal vocabulary of the organization drift further apart, the gap compounds, and it slows every decision that has to cross from the technical side of the house to the executive side.

Language debt in cybersecurity organizations: what it costs when old terms stay in circulation

Technical debt appears as one dramatic outage, while language debt accumulates as a thousand small frictions that never quite become a headline. It's the daily cost of making decisions with words that no longer describe what's actually happening on the ground. Nobody notices the single instance. Everybody feels the accumulated weight.

Start with how it shapes money. When security teams frame their reports around cost, "we spent X on this tool," instead of risk reduction, business leaders hear an expense line rather than something that protects trust and keeps the business running. That framing decides the next budget cycle before anyone states a number out loud.

Standardized frameworks exist precisely to close this gap. NIST and ISO give technical, legal, compliance, and executive teams a shared set of terms to work from, which cuts the friction of translating between departments. If organizations skip aligning to that shared vocabulary, they absorb the translation cost in every single cross-team conversation, forever, a tax that never gets paid off.

Enforcement actions expose the sharpest edge of language debt. State attorneys general have increasingly gone after deceptive practices and weak disclosures, not just failures in breach response. A company that still calls itself "prevention-first" or markets itself as "breach-proof," while its actual operating posture looks nothing like that promise, carries legal exposure whether or not it ever gets breached. The same logic applies in reverse: a company branding itself resilience-first without the operational substance to back that claim up sits in the same regulatory crosshairs as a company falsely claiming it can prevent every attack. The words a company puts in its own disclosures are now something regulators can hold it to, independent of whatever actually happens on the network.

How AI scales the language problem

If you drop AI into security operations, threat detection, or customer communications, it doesn't clean up a company's vocabulary problem. It photocopies it, at volume, instantly, to every audience the company talks to. An AI model doesn't check whether a term still works in the market. It produces fluent, confident-sounding output based on whatever training data, prompts, and internal documents it was handed, outdated vocabulary included.

An organization still running incident response playbooks, vendor contracts, board reports, and product descriptions on prevention-era language gets AI-generated output that repeats that same misalignment everywhere at once: in the sales deck, in the customer email, in the regulatory filing. One mismatched vocabulary, multiplied across every channel the AI touches.

The 2025 Microsoft Copilot prompt injection incident shows how this plays out operationally. The problem wasn't the AI tool itself; it was that the boundary between trusted input and untrusted input hadn't been clearly governed, a language failure before it's a technical one: what counts as authorized, what counts as a threat, how the system gets instructed to sort anything ambiguous. Get those definitions fuzzy, and the AI will happily act on the fuzziness.

There's a trust cost stacking on top of this too. As AI-generated content becomes the assumed default in security writing, buyers start discounting blog posts and analyst explanations as algorithmic filler, making it harder for a vendor to prove real expertise through the channels it used to own. An organization that hasn't nailed down precise, canonical language for its own category position has no business trusting an AI model to invent or hold that position for it. The ones who try end up producing confusion at scale instead of clarity at scale.

What cybersecurity vendors must do when a category's organizing language changes

Surviving this language shift takes more than swapping "prevention" for "resilience" on the homepage. It means replacing the organizing term everywhere it currently lives: governance documents, product narratives, sales conversations, regulatory filings. The word has to change in the places nobody reads as often as the homepage.

The obvious trap is already visible in the market. Some founders have simply relabeled existing products as "resilience-focused" without touching the underlying architecture or governance behind them. Sophisticated buyers and investors spot that move almost immediately, the way a seasoned poker player spots a bluff from across the table. Real repositioning touches every layer at once: internally, the risk registers, incident response playbooks, board reporting templates, and KPIs all need to speak the new language; externally, the product descriptions, sales decks, and customer communications need to match; and in regulatory filings, public claims need to line up with actual operating posture, because enforcement is now targeting exactly that gap.

NIST CSF 2.0's call for enterprise-wide accountability points at something larger than a wording update. The same vocabulary has to function across technical teams, legal, compliance, communications, and the executive suite simultaneously, making this a governance requirement. Category language, treated this way, works like infrastructure: built once, maintained constantly, load-bearing for every department that depends on it.

Vendors that can show both operational resilience and the vocabulary to make that resilience legible across all those audiences end up in a genuinely durable competitive position. Vendors that bolt on the new word without retiring the old architecture underneath it are building liability, not equity, regardless of how good the new slide deck looks.

John Kindervag, Chief Evangelist at Illumio, has predicted performance contracts and compensation structures that tie executive pay directly to measurable cybersecurity outcomes. If buying shifts toward outcomes like that, vendors whose category language can't translate into something measurable get cut out of enterprise deals before the pitch even starts. If a contract demands proof, fluent language with nothing behind it won't survive it.

Breach narrative as a diligence signal in cybersecurity investment

Investors evaluating a cybersecurity company now read the founding team's breach narrative, how they talk about their own category position and their own history with incidents, as a signal worth weighing alongside the technical due diligence, not a footnote to it. The story a team tells about where it sits in the market, and how honestly it accounts for its own exposure, has become part of what gets priced.

Cybersecurity due diligence no longer just checks financial records line by line. It now covers IP, market fit, and systemic risk from multiple angles at once, and category clarity sits in that mix right next to customer proof and burn discipline. A team that still describes itself in prevention-era language, while every regulatory and market signal has moved to resilience, is handing diligence teams a mismatch they don't have to work hard to find. The breach pattern of 2025 didn't just rewrite how cybersecurity companies talk about themselves. It rewrote what investors are listening for when they decide which of those companies get funded.

Sources

  1. Cybersecurity & Privacy 2026: Enforcement & Regulatory Trends
  2. Top 10 cybersecurity breaches of 2025: Lessons for compliance
  3. The security gaps that caused 2025’s biggest breaches - ManageEngine Blog
  4. Pinsent Masons Update: Cybersecurity in 2026: Key Incident Trends, Enforcement Shifts, and the Global Regulatory Reset
  5. The rise of cybersecurity as a strategic economic priority

More in Category Displacement