* [![perspectives](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/02/prespective-icon.png)](https://www.paloaltonetworks.com/perspectives)
* The First Principle of Resilience: Be Brave Enough to Fail

# The First Principle of Resilience: Be Brave Enough to Fail

![The First Principle of Resilience: Be Brave Enough to Fail](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/07/first-principle-of-resilience-featured.jpg)  
**By [Sam Ainscow](https://www.paloaltonetworks.com/perspectives/author/sam-ainscow/ "Posts by Sam Ainscow")** | **5 min read** |  
![share icon](https://paloaltonetworks.com/content/dam/pan/en_US/cxo-perspectives/images/cxo-share.svg)

* LinkedIn button ![linkedin-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-linkedin.svg)
* Twitter share button ![twitter-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-twitter-x-black.svg)
* \[Email share button ![email-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-email.svg)\](mailto:?subject=The First Principle of Resilience: Be Brave Enough to Fail\&body=Check out this article https%3A%2F%2Fwww.paloaltonetworks.com%2Fperspectives%2Fthe-first-principle-of-resilience-be-brave-enough-to-fail%2F "Share in Email")
* ![copy-icon](https://www.paloaltonetworks.com/perspectives/wp-content/themes/csp2025/dist/images/icons/icon-share.svg)
  [](https://www.paloaltonetworks.com/perspectives/the-first-principle-of-resilience-be-brave-enough-to-fail/?pdf=download&lg=en&_wpnonce=7c4ed01ef4 "Click here to download") MEET THE AUTHOR  
  ![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/07/sam-ainscow-headshot.jpg)  
  A passionate cybersecurity professional with over 25 years of experience who enjoys bridging the gap between senior management and technical teams to deliver the most suitable solution in line with a business' risk appetite. Sam is currently the Group CSO at Hill \& Smith PLC, a member of the CISO Advisory Board at Dune Security, a member of the GIAC Advisory Board and the Chair of the Palo Alto Networks UK Executive Advisory Council....

[Learn more](https://www.paloaltonetworks.com/perspectives/author/sam-ainscow/)

## IN THIS ARTICLE

A few years ago, I had a picture on my LinkedIn profile with a simple mantra: "Be brave enough to suck at something new." It came from a humbling moment. After many years in the industry, I walked into a training course thinking I was a pretty good cyber guy. And when I walked out later that morning, I realized I was less than stellar --- I might go so far as to say "terrible." It was a stark reminder that in cybersecurity, complacency is the most dangerous vulnerability of all.

That experience taught me a foundational lesson: The path to getting better begins with the courage to be bad at something. I believe this principle applies to both individual careers and the essence of organizational cyber resilience. We invest heavily in tools and processes to prevent attacks, but incidents will happen. True resilience, like any honed craft, is built only through practice. No one steps onto a tennis court for the first time and beats a champion.

Resilience requires the same dedication. It requires a commitment to continuously test our defenses, find our weaknesses, and learn from them.

## The Foundation of Resilience: A Clear-Eyed View of Risk

This resilient mindset must be grounded in a practical reality: Risk must drive everything we do in security. Before we can build effective defenses, we must first have a comprehensive, honest understanding of our unique risk profile. This means asking a series of fundamental questions.

First, do you understand your threat landscape? The threats facing a financial services firm are vastly different from those facing a defense contractor or a manufacturing business.

Second, do you understand your people? Are your users highly skilled and potentially capable of finding clever workarounds to security controls, or do you have a culture of [shadow IT](https://www.paloaltonetworks.com/cyberpedia/shadow-it) where unvetted SaaS applications are common?

Third, do you know your assets and data? If you don't have a clear asset inventory, you cannot secure your environment. Where is your most sensitive data, how is it classified, and who has access to it? Are your controls effective? Are they mitigating the specific risks you've identified, and are they doing so with the least possible friction for the business?

## The Hidden Risk: Our Dependence on the Software Supply Chain

Even with a strong handle on internal risk, many organizations are overlooking a massive external threat --- the [software supply chain](https://www.paloaltonetworks.com/perspectives/supply-chain-chaos-in-2025-how-geopolitics-are-rewriting-the-rules/). I think we might all be horrified to see how many critical enterprise products are underpinned by an open-source project maintained by a handful of contributors in their spare time.

This is one of the biggest issues that I believe people aren't talking loudly enough about. We place an enormous amount of faith in our technology providers, but we often lack visibility into their dependencies. As an industry, we need to get more rigorous about vetting the open-source components our developers use and demanding transparency from our vendors. I believe this will continue to be a major source of breaches until we collectively address it.

## Applying the Mindset: A New Model for Security Training

Nowhere is this need for a risk-based mindset more apparent than in employee security training. I see our training programs as no different from the personal protective equipment (PPE) we'd give a worker in a manufacturing plant. Yet, we often approach it with a one-size-fits-all, "sheep dip" approach that is fundamentally broken.

A resilient organization understands that risk is not uniform. The risk profile of a CEO is, of course, different from that of an accounts payable clerk. Our training must reflect this reality. It should be dynamic and personalized, using risk signals from across the business --- an employee's role, their tenure or their IT literacy --- to deliver the right training, to the right person, at the right time.

## The Ultimate Test: Learning from Failure

This philosophy culminates in how we handle an incident. The technical steps of an effective response (identification, containment, eradication, and recovery) are critical. But for me, the single most important phase is what comes after --- the lessons learned.

Every incident, every test, every exercise must be followed by a "lessons learned" session where people can be open, honest, and truthful, without fear of blame. This is a business-wide responsibility. When we run tabletop exercises, we bring everyone into the room who would be involved in a real crisis --- from legal to communications to executive leadership. It is their business and their incident.

This collaborative, blameless process of learning from failure is where true resilience is forged. It's the feedback loop that enables us to find the gaps in our playbook, refine our policies and ensure that next time, we will be stronger, faster, and more effective.

## Resilience Is a Feedback Loop

In our industry, the threats will never stop evolving, which means we can never stop learning. The ability to "suck at something new" is about being open to the feedback that the world is giving you. The lessons-learned process after an incident is the organizational version of that mindset.

Preparedness is everything, but it is not a static state achieved by writing a policy. Instead, it is a dynamic process of training, testing and, most importantly, learning from every failure. This feedback loop forms the core of cyber resilience. It requires courage, humility, and a shared commitment to getting better, together.

Want to hear more on this topic? Listen to the full, unedited conversation with Sam on the [Threat Vector podcast](https://www.paloaltonetworks.ca/resources/podcasts/threat-vector-risk-resilience-and-real-talk-with-sam-ainscow).

* [AI](https://www.paloaltonetworks.com/perspectives/all-articles/?cat=ai)

## Related Content

![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2026/03/Why-Cybersecurity-KPIs-Are-Changing-featured.jpg) BLOG

### AI

**Why Cybersecurity KPIs Are Changing (And What This Means for Security Leaders)**

True cyber resilience is impossible to achieve without strategic and tactic...

[Helmut Reisinger](https://www.paloaltonetworks.com/perspectives/author/helmut-reisinger/ "Posts by Helmut Reisinger")
[](https://www.paloaltonetworks.com/perspectives/why-cybersecurity-kpis-are-changing-and-what-this-means-for-security-leaders/)  
![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2026/03/Weaponized-Intelligence-featured.jpg) BLOG

### AI

**Weaponized Intelligence**

We are building the foundation that makes defense possible....

[Nikesh Arora](https://www.paloaltonetworks.com/perspectives/author/nikesh-arora/ "Posts by Nikesh Arora")
[](https://www.paloaltonetworks.com/perspectives/weaponized-intelligence/)  
![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2026/03/RFP-Bottleneck-featured.jpg) BLOG

### AI

**From Weeks to Minutes: How We Applied an AI-First Transformation to the RFP Bottleneck**

Understanding why manual efforts burn hundreds of hours and are bottlenecki...

[Sandeep Uttamchandani](https://www.paloaltonetworks.com/perspectives/author/sandeep-uttamchandani/ "Posts by Sandeep Uttamchandani")
[](https://www.paloaltonetworks.com/perspectives/from-weeks-to-minutes-how-we-applied-an-ai-first-transformation-to-the-rfp-bottleneck/)  
STAY CONNECTED

## Connect with our team today

Job Level  
Sign me up to receive news, product updates, sales outreach, event information and special offers about Palo Alto Networks and its partners.  
By submitting this form, I understand my personal data will be processed in accordance with Palo Alto Networks [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) and [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown).  
This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.
Reach out  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense?ts=markdown)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses?ts=markdown)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy?ts=markdown)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence?ts=markdown)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond?ts=markdown)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown)

* [Customers](https://www.paloaltonetworks.com/customers?ts=markdown)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown)

* [Communities](https://www.paloaltonetworks.com/communities?ts=markdown)

* [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications?ts=markdown)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown)

* [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown)

* [Documents](https://www.paloaltonetworks.com/legal?ts=markdown)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language
