Skip to Content



Securing the Digital Horison:
Redefining Cyber Resilience and Impact at 
T.H.I.S. 2026​​

By Obika Gellineau ​


LINKAGE Q2 (2026) - IMPACT
O​rganisations drastically expand their digital footprint as they embrace artificial intelligence, cloud computing and interconnect infrastructure. This expansion simultaneously increases their exposure to cyber risk, thereby making cyber resilience a critical business imperative. Lately, conversations have shifted away from prevention of cyber-attacks to focus on whether an organisation can sustain its business operations during a cyber incident. This transforms cyber resilience into a true competitive advantage

Obika Gellineau (left) featured on the "Cyber Resilience and Risk Transfer" panel at the 8th Annual Tech Hub Islands Summit (T.H.I.S.) 

At the AMCHAM T&T Tech Hub Islands Summit (T.H.I.S.) 2026, I participated in a panel where the dialogue moved from basic cybersecurity awareness to practices that modern enterprises can adopt to build measurable cyber resilience. Achieving a level of readiness for cyber-attacks requires a deep look at emerging risks, securing digital transformation lifecycles, integrating operational technology safely, forming strategic partnerships and rigorous incident response testing.
One of the most critical vulnerabilities highlighted during the discussion was that organisations often underestimate third-party supply chain risk. Most business software relies on open-source libraries, and attackers are increasingly attempting to insert malicious code into these components to create backdoors through trusted software updates. While Boards often focus on direct attacks against the network perimeter, weak vendor oversight can allow attackers to exploit external partners and bypass primary defenses. To mitigate this risk, organisations should align vendor management with guidance such as NIST SP 800-161 and establish a structured programme that categorises vendors by the level of data or network access they require. High-risk vendors should undergo deeper technical evaluations, including reviews of SOC 2 Type II reports, validation against ISO/IEC 27001, breach notification requirements and the organisation’s right to audit security controls. Organisations can transform vendor blind spots into visible and manageable risks through continuous monitoring external vendors.
Subsequently, the panel moved from third-party risk management to organisations undergoing digital transformation. It’s important that organisations remain cyber resilient during this transformative process, but how do you balance innovation with cyber resilience? This is where the concept of Security-by-Design becomes critical for organisations to adopt as part of their digital transformation lifecycle. Security-by-Design is the integration of security processes into the digital transformation cycle at the very beginning of any initiative, rather than waiting till the middle or the end of the project to plan its security. Implementing security from the feasibility stage ensures that digital platforms are constructed with a cyber resilient architecture from day one. Furthermore, it reduces delays in its completion and builds trust with all stakeholders that the digital platform is secure.
On the other hand, not all networks and systems can be modernised through the digital transformation lifecycle. Operational Technology (OT) and Legacy systems still exist within industrial and business environments, respectively. Connecting OT and Legacy systems to modern digital platforms introduces unique risks because these platforms are inherently difficult to protect. These systems were built for isolation rather than connectivity, making them high risk targets for hackers. However, these vulnerabilities should not stall your cyber resilience plans. Implementing strict network segmentation and establishing strong compensation controls reduces the overall cybersecurity risk of OT and Legacy systems. Furthermore, industrial and manufacturing organisations should structure their physical and digital divisions around established frameworks such as ISA/IEC 62443 standard, which provides a structured guideline for securing industrial automation and control systems, and offers a robust defense in these types of hybrid environments.
As the impactful conversation continued, we moved toward the importance of technology partners. We all agreed that technology partners are invaluable assets in an organisation’s journey towards cyber resilience. Their value extends far beyond providing hardware and software solutions where they serve as strategic advisors, operational enablers and trusted partners in resilience planning. The lack of qualified cybersecurity specialists is a common and significant risk in most organisations today. Technology partners are uniquely positioned to bridge this critical talent gap. Organisations can work with these partners to assist them with assessing their cybersecurity maturity against frameworks such as NIST Cybersecurity Framework or ISO/IEC27001, to build their security awareness training programmes and to help them contain and recover from a cyber-attack. Technology partners can strategically, operationally and tactically assist organisations with their cybersecurity programme by providing the necessary expertise and manpower to be cyber resilient.
Ultimately, the cornerstone of true cyber resilience lies in the response and recovery planning, which begins with incident response (IR) and escalates to business continuity (BC) and/or disaster recovery (DR). The IR programme was one of the major talking points of conversation. If a CEO has only one recommendation to prepare for the next major cyber incident, it must be to implement a comprehensive incident response programme, which involves identifying critical response team roles, developing a response plan, development of a crisis communications plan, establishing an escalation process toward BC/DR activation and finally embedding a continuous testing schedule. Every organisation should delegate operational investments to the development and simulated testing of cyber incident response and disaster recovery activities.
At this point the dialogue shifted to the importance of business continuity, which aims to not only reduce operational downtime but also maintain critical business functions after an unexpected disaster. Critical business functions will inevitably fail due to the lack of necessary technology support. Therefore, organisations must assess the risks to their business functions and their business impact to determine their recovery strategies which impact their data backup frequencies and design of DR sites for their mission-critical IT systems. Furthermore, prioritising continuous tabletop simulations and live simulated BC/DR exercises ensures that an organisation is fully prepared to withstand and recover from any digital disruption, while securing their operations and maintaining stakeholder trust.
Cyber resilience must now become a deliberate business priority, not a delayed technical project. The key message from the panellists’ conversation was clear: organisations must prepare before disruption occur by strengthening vendor oversight, embedding security into transformation, protecting OT and legacy systems, engaging trusted partners and testing response plans regularly. Executive leaders should act now by assessing their current resilience posture, closing critical gaps and investing in response and recovery capabilities. The organisations that will thrive in the digital horizon are those that prepare today to withstand tomorrow’s disruption.
ABOUT THE AUTHOR
Obika Gellineau is a Security Consultant at Fujitsu Caribbean (Trinidad) Limited