IT Brief India - Technology news for CIOs & IT decision-makers
India
Google Cloud urges resilience as breaches become inevitable

Google Cloud urges resilience as breaches become inevitable

Tue, 28th Jul 2026 (Today)
Mark Tarre
MARK TARRE News Chief

Google Cloud has published a cyber security report on enterprise resilience, drawing on findings from Mandiant and the Google Threat Intelligence Group.

The report argues that many successful intrusions still begin with basic human and organisational weaknesses rather than advanced attack methods. It urges leaders to move away from a model centred mainly on prevention and towards one that assumes breaches will happen, limits damage and improves response.

Mandiant's M-Trends 2026 findings feature prominently. Exploits remained the most common initial infection vector for a sixth consecutive year at 32%, while voice phishing rose to second place at 11%.

In ransomware incidents, prior compromise was the leading confirmed vector. According to the report, that shows attackers are increasingly able to build on earlier access rather than relying only on new entry points.

Containment focus

A central theme is that cyber defence should be designed to contain the effects of an intrusion once attackers get in. Ransomware groups are now targeting recovery systems such as virtualisation hypervisors, backup environments and privileged access management vaults to prevent organisations from restoring operations.

The report recommends stricter separation of credentials and the use of air-gapped, isolated recovery environments so a compromise in a production network cannot also destroy backups. The aim is to reduce what security teams often call the blast radius of an incident.

It also extends that containment argument beyond corporate infrastructure. Attackers are increasingly targeting executives, other high-value personnel, their personal devices, home networks and even family members as potential routes into business systems.

As a result, resilience planning should extend beyond the traditional perimeter. The document calls for digital footprint management to be integrated with executive protection efforts rather than treated as a separate issue.

Human readiness

Alongside technical controls, the report places strong emphasis on staff preparedness during a crisis. It argues that the speed and quality of decision-making under pressure can have a major effect on how quickly an organisation contains an incident and resumes operations.

To improve that response, the document advocates practical training, immersive exercises and mentoring. It also calls for a culture of "safe failure", where teams can learn through realistic practice without fear of blame.

That emphasis reflects a wider industry concern that security outcomes are shaped as much by operational discipline as by the tools a company has bought. The report suggests resilience depends on repeated rehearsal and cross-functional coordination rather than policy documents alone.

AI pressure

The publication also addresses the effect of automation and artificial intelligence on cyber attacks and defence. It cites research from the Google Threat Intelligence Group that identified what it describes as the first known zero-day exploit developed with AI.

That finding has increased pressure on companies to respond with their own automated tools. However, the report warns that AI-assisted vulnerability discovery will not solve security problems on its own if organisations fail to connect those tools to established processes and clear decision-making structures.

Instead, automated discovery should be folded into a mature, structured programme so security teams can prioritise risk, avoid alert fatigue and maintain control during fast-moving incidents. In practice, that means pairing technology with trained staff and repeatable operating procedures.

The report comes as companies face increasing scrutiny over how they prepare for business disruption caused by cyber attacks. For boards and executives, the message is that resilience is not only about blocking attackers, but also about maintaining recovery options and ensuring teams can function when controls fail.

Its underlying assessment is that technical debt and security culture remain central issues. Even as attention grows around machine-speed attacks, persistent weaknesses in architecture, access controls and organisational behaviour still make many breaches possible.

"Technology alone will not define your cyber defense outcomes. True resilience lies in preparing your team, hardening your architectures, and practicing under pressure."