5 Cybersecurity Tips So You Can Sleep at Night

There’s a joke I like to tell about what keeps C-level executives up at night. The shorthand version is that unlike the rest of the leadership team, the CISO’s bed is made but no one sleeps in it.

It’s been almost two months since I joined Splunk as Chief Information Security Officer and my team has been focusing on Splunk's own foundational security and continuing our ongoing efforts to protect our customers – so security isn’t the thing keeping them up at night. The reality is that it’s not if a breach or exploit will occur, it’s when. So organizations need to be ready to respond and recover when an incident occurs.

Here are five tips on preparing for a cyberattack.

Nail the Basics

The first line of defense is ensuring employees are informed and routinely trained on security policies. Strong passwords updated regularly, phishing prevention training and keeping systems and applications patched and up to date go a long way toward preventing a breach. Keep data encrypted and backed up, and segregate backups so a cyberattack can’t spread. And having a solid asset management strategy enables businesses to identify core critical assets and determine how to secure that data.

Know Who’s Who and Who Can Access What

Operate with a zero trust strategy and authenticate and authorize every user, device and interaction to verify everyone and everything across the business. Implement data governance so people only have access to data and technology relevant to their role. Inventory your data regularly so that you understand where sensitive information resides and who has access to it. Besides keeping passwords updated, implement multi-factor authentication whenever possible to help ensure that legitimate users are accessing systems and data. Practice routine user maintenance to add, update or remove users to help maintain data governance.

Look at Your Data Big Picture

Understanding your data is more than collecting logs and seeing activity. It’s taking in all the different data to understand the big picture and gaining end-to-end visibility across the environment. To be cyber resilient, you need a data-centric security operations portfolio that collects all forms of data, quickly analyzes and responds to risks, has built-in threat intelligence, easily integrates with existing tools sets without creating more data silos and scales with the business.

Have a Plan

As Benjamin Franklin said, “By failing to prepare, you are preparing to fail.” Develop an incident response plan to investigate, contain and remediate a security incident or breach. Having a plan in place helps you make faster, informed decisions to reduce risk exposure. But don’t stop there. Set up an incident recovery plan to outline how to restore your business. And if an attack occurs, gather your teams to figure out how risk was missed to put future protections in place. Save time and cost of recovery by having plans in place.

Communicate

Know who you’re going to call and how you’re going to tell customers. Ensure that everyone knows what to do and can carry out the plan if a cyberattack occurs. Identify who gets called, develop technical responses for customers and know who the decision makers are in your organization. The smoother you handle incidents internally and externally, the better for your customers and your bottom line.

When it comes to security, it pays to look ahead and be prepared. Before joining Splunk, I was a Splunk customer. If you want to find out how using Splunk helped me sleep at night, get in touch.

Related Articles

Security Predictions 2026: What Agentic AI Means for the People Running the SOC
Leadership
10 Minute Read

Security Predictions 2026: What Agentic AI Means for the People Running the SOC

Splunk's Hao Yang shares our security predictions for 2026 and how agentic AI is reshaping how we see the SOC.
The Performance Playbook: Why Business Context Is the Key to Customer-Centric Visibility
Leadership
4 Minute Read

The Performance Playbook: Why Business Context Is the Key to Customer-Centric Visibility

Systems show symptoms. Business context shows impact. Discover why the future of observability is understanding what matters most to your customers.
MachineGPT, Agentic AI, and the New Foundation for Digital Resilience
Leadership
4 Minute Read

MachineGPT, Agentic AI, and the New Foundation for Digital Resilience

MachineGPT is foundational to the rise of Agentic AI in the enterprise, which is poised to fundamentally reshape digital operations – and it's advancing faster than we expected.
MachineGPT: Speaking the Language of Machines to Shape the Future of AI
Leadership
4 Minute Read

MachineGPT: Speaking the Language of Machines to Shape the Future of AI

MachineGPT brings the power of generative AI to one of the most overlooked resources: machine data. Splunk SVP & GM Kamal Hathi explains why mastering data as the heartbeat of the digital world is a game changer.
Powering and Protecting the AI Revolution: A New Era for Splunk and Cisco at .conf25
Leadership
3 Minute Read

Powering and Protecting the AI Revolution: A New Era for Splunk and Cisco at .conf25

Splunk's Kamal Hathi recaps our innovation highlights from .conf25, marking a pivotal moment for Splunk and Cisco as we deliver significant new value to our customers that make the use of AI a practical reality in their organizations.
Machine Data: Fighting Fire With Fire for Digital Resilience
Leadership
2 Minute Read

Machine Data: Fighting Fire With Fire for Digital Resilience

Kamal Hathi shares how Cisco and Splunk are helping organizations manage the explosion of machine data and AI-driven complexity, delivering real-time digital resilience to counter threats at machine speed and scale.
.conf25: Reinventing Digital Resilience for the Agentic Era
Leadership
3 Minute Read

.conf25: Reinventing Digital Resilience for the Agentic Era

Kamal Hathi shares how Cisco and Splunk deliver the data foundation, agentic intelligence, and cross-domain insights needed to build a more secure, resilient, and always-on digital enterprise.
UK Needn’t Fear The Data Deluge
Leadership
4 Minute Read

UK Needn’t Fear The Data Deluge

UK businesses face a data explosion—fueling growth but also raising risks in security, compliance, and operations. With smart data management strategies, organisations can regain control, boost resilience, and turn data into a true competitive edge.
Digital Resilience By Design: Seamless Troubleshooting Across Splunk & Cisco
Leadership
7 Minute Read

Digital Resilience By Design: Seamless Troubleshooting Across Splunk & Cisco

Cisco and Splunk deliver Digital Resilience by Design with seamless troubleshooting across security, observability, and networking domains, powered by AI innovations to manage complexity and stay ahead of risk.