Resilience is one mission, not two scorecards

Attackers do not respect org charts, and neither do outages. Yet many enterprises still keep IT operations and security in separate tools, data, and narratives, leaving early warning signs unconnected until damage is done. In this conversation with CIO&Leader, Subhalakshmi Ganapathy, Chief IT Security Evangelist at ManageEngine, Zoho Corp., argues that convergence begins with shared incidents, not restructured teams. She explains why a common data foundation matters, where automation must hand over to human judgment, and why mindset, not tooling, is the hardest barrier. Her larger point: resilience must become a shared metric, built on trust in teams, data, and AI.

Subhalakshmi Ganapathy, Chief IT Security Evangelist at ManageEngine, Zoho Corp.

CIO&Leader: When IT operations and security teams have worked in silos, what gaps or blind spots does that create for enterprise resilience?

Subhalakshmi Ganapathy: Adversaries don’t respect silos, and neither do incidents. Attackers often target operations to disrupt systems, and early indicators of a breach may appear as operational symptoms such as unexplained latency, system downtime, failed jobs, or performance degradation. When IT and security work separately, IT may see a performance problem and try to restart or scale a system. In contrast, security sees a faint anomaly without the operational context to prioritize it. Neither team has the complete picture, and the underlying cause can go undiagnosed until the impact becomes significant. The blind spots extend beyond incident response. Duplicate tools can tell different stories, post-mortems can have conflicting timelines, and unclear ownership can create gaps between teams. This fragmentation slows detection, weakens response, and can ultimately affect business trust. Enterprise resilience requires a shared view of what is happening across the environment, rather than separate operational and security narratives.

CIO&Leader: What does “unified operational visibility” concretely look like in practice, and how does it build trust in shared data? Is it a shared dashboard, a shared team structure, or something deeper?

Subhalakshmi Ganapathy: It’s deeper than a shared dashboard, although that may be the most visible layer. True unified visibility means IT and security teams work from the same telemetry, including logs, network flows, endpoint signals, and application performance data, normalized into a common data fabric. Both teams see the same event with the same context, whether it initially appears as a performance issue or a security anomaly.

Trust in that data comes from three things: a single source of truth (no duplicate tools telling different stories), agreed standards for data ownership and quality, and joint review processes where both teams validate what they are seeing.

Structurally, this can take the form of a fusion center or a unified SecOps/ITOps function. But the deeper shift is cultural, where operational and security signals are treated as two lenses on the same reality rather than as competing narratives.

CIO&Leader: For an enterprise still running IT and security as separate functions, where would you advise them to start the convergence journey, and how should they build trust along the way?

Subhalakshmi Ganapathy: Start with a shared incident, not a shared org chart. Pick a high-impact scenario such as ransomware or a major outage and run a joint tabletop exercise where both teams work from the same data, timeline, and playbook. This quickly surfaces the real points of friction, including visibility gaps, conflicting priorities, and unclear hand-offs.

Compliance can also provide a practical starting point. A shared audit-logging initiative or a unified breach notification playbook aligned with DPDP, GDPR, or CERT-In requirements gives both teams a concrete reason to work together, often with executive sponsorship already in place.

From there, integrate the tools teams already use so they can access the same underlying context. For example, integrating a SIEM with an ITOps observability platform can ensure that a security alert carries relevant performance context. This does not necessarily require a single platform; well-integrated systems can work equally effectively. The next step is to establish a shared incident-command model with clear roles.

Trust is built through small, visible wins like a jointly resolved incident, a shared post-mortem, or a KPI that both teams own. Structure should follow shared work, not the other way around.

CIO&Leader: How is AI changing the speed and shape of incident response when IT and security teams operate on the same data and tooling, and how does it affect trust in the response?

Subhalakshmi Ganapathy: AI becomes more effective when it can learn from richer and more connected data. When IT and security operate on the same telemetry, operational and security signals can be analyzed together rather than as separate events. An anomalous login, a latency spike, and an unusual data transfer, for example, can move from being three separate alerts in different queues to becoming one coherent narrative that AI can reason about. This can significantly compress incident response times by reducing the cross-team coordination that would previously have been required. Trust in AI-driven response, however, depends on explainability. IT and security teams need to understand why something was flagged, what data informed the recommendation, and how confident the system is in its recommendation. The risk is over-reliance. AI should accelerate human judgment, not replace it, especially for actions affecting production systems or customer trust.

CIO&Leader: What role does automation play in reducing mean time to detect and mean time to respond once teams are unified, and where should automation stop and human judgment take over to preserve trust?

Subhalakshmi Ganapathy: Automation is particularly valuable in detection and the initial stages of response. It can handle enrichment and correlation, isolate an endpoint, revoke a session, or open a ticket with the relevant context. These capabilities can help bring MTTD and MTTR down from hours to minutes. When teams are unified, automation can extend across the incident lifecycle because handoff friction is reduced. However, automation should stop where consequences become irreversible or require significant business context, for example, taking down production systems, communicating with regulators or customers, attributing intent, or determining acceptable business risk. Those need human judgment, ideally from IT and security together. The principle should be simple: automate the known, escalate the novel. Trust in automation is built through transparent playbooks, clear rollback paths, and regular reviews of the system’s autonomous actions. Hence, humans stay accountable even when they are not in every loop.

CIO&Leader: Culturally, what’s the hardest part of breaking down the IT-security silo: is it tooling, reporting lines, incentives, trust, or something else?

Subhalakshmi Ganapathy: It is more about mindset and identity than tooling or reporting lines. IT teams typically see themselves as builders and enablers, measured on delivery and uptime, while security teams see themselves as guardians, measured on risk reduction and control. Those perspectives can come into conflict, particularly when a security action could affect a business-critical system. Until leadership creates a shared definition of what “good” looks like for both functions, teams can default to their own priorities. Trust is the second major hurdle. Security has historically been viewed as the “no” function, while IT has sometimes found ways to work around it. Rebuilding that trust takes time, joint wins, and leadership that visibly supports collaboration. Tooling is the easiest part; it can be procured. Reporting lines are a lever, but they are not a solution on their own; even organizations with unified CIO-CISO structures can operate in silos. The real work is redefining a shared purpose, i.e., resilience.

CIO&Leader: How should CIOs and CISOs redesign accountability and KPIs so resilience becomes a shared metric, reinforcing trust rather than creating two separate scorecards?

Subhalakshmi Ganapathy: Resilience is not a security-only concern; it belongs equally to ITOps. A Full Stack Observability (FSO) view makes this obvious. The same telemetry that shows a service is degraded can help determine whether the cause is a configuration drift, a capacity issue, or a security compromise. KPIs should therefore reflect shared ownership. This could include time to restore critical services (regardless of cause), the percentage of incidents resolved without customer impact, mean time to detect and recover across both cyber and operational events, and a composite resilience score covering redundancy, recovery, and response maturity. Compliance metrics can also be included in this shared scorecard, such as audit readiness, control effectiveness, and breach notification timelines under DPDP, GDPR, or sector-specific mandates. These are inherently cross-functional and give both leaders a board-level reason to co-own the outcome. Individual KPIs like patch compliance and uptime will continue to matter, but they should ultimately contribute to shared outcomes. Two scorecards can reinforce two separate priorities; a shared scorecard helps establish one resilience mission.

CIO&Leader: As enterprise environments grow more distributed, multi-cloud, hybrid work, and IoT/OT convergence, how do unified IT-security operations need to evolve to keep pace?

Subhalakshmi Ganapathy: The traditional perimeter is disappearing, and so is the notion that any single team can own a technology domain end-to-end. With workloads distributed across multi-cloud, hybrid, and IoT/OT environments, the volume and variety of telemetry data have increased significantly. The only way to keep pace is to consolidate that telemetry into a common data lake that both observability and security teams can draw from. When performance metrics, logs, traces, network flows, identity events, and threat signals all land in the same repository, IT and security spend less time debating whose data is correct and more time responding to what data shows.

This shared foundation is what makes distributed unified operations viable at scale. Instead of stitching together fragmented views from each cloud, region, or edge location, teams get a single correlated picture regardless of where the workload runs. For example, a latency issue in a regional cloud environment and a suspicious login from an OT device on a factory floor are investigated together when the relevant data is connected. Observability platforms provide the operational view and security platforms provide the threat view, but both can work from the same underlying facts. It also addresses the cost and complexity of duplicating telemetry across separate technology stacks. When combined with cloud-native tooling, identity as a control plane, and OT-aware sensors, a shared data foundation can become the backbone of unified operations across a highly distributed enterprise.

CIO&Leader: What’s a real-world example (anonymize if needed) where unified IT-security operations meaningfully changed the outcome of an incident and strengthened trust, versus how a siloed response might have played out?

Subhalakshmi Ganapathy: Consider a generalized scenario involving a mid-sized financial services organization. Its monitoring team detects intermittent latency in a customer-facing application, while the security team, working from the same platform, simultaneously identifies unusual outbound connections from the same server cluster. Because both signals are visible with shared context, the teams can connect them within minutes and identify that the latency is linked to a compromised process attempting to exfiltrate data. The affected systems can then be isolated, the exfiltration blocked, and forensic investigation initiated immediately. In a siloed model, the IT team might initially treat the latency as a performance issue and restart services or scale capacity, potentially giving the attacker more time and affecting the availability of evidence. Security, meanwhile, may lack the operational context needed to link the anomaly to the application issue. The key point is that unified visibility does more than shorten response times. It can change how an incident is understood and enable IT and security teams to respond to the underlying issue rather than treating its symptoms separately.

CIO&Leader: Looking ahead, what will “resilient enterprise operations” look like in 3-5 years, and what should organizations be building toward today to strengthen trust and resilience?

Subhalakshmi Ganapathy: In the next three to five years, resilience will be defined not only by prevention but by adaptive recovery, meaning the ability to absorb disruption, whether caused by an attack, an outage, or a supplier failure, while continuing to serve customers. We can expect AI-driven autonomous operations to handle more routine detection, response, and remediation; digital twins of critical business services to help organizations simulate and rehearse disruptions; and identity-centric, zero-trust architectures to become increasingly standard. Regulatory expectations around AI governance, critical infrastructure, and sector-specific requirements are also likely to make unified operations important for compliance. IT and security may not become a single function in every organization, but the direction is toward a single resilience discipline with specialized expertise. Organizations can start building toward this today by investing in a unified data platform, establishing shared incidents, resilience, and compliance KPIs, upskilling teams in AI and cloud-native operations, and conducting joint resilience exercises across cyber, operational, and business continuity scenarios. Above all, organizations need to build trust in their teams, their data, and their automation. That is the foundation on which resilient operations will be built.

Share on