Tom Exelby spent 15 years in the British Army, including bomb disposal and strategic planning with NATO operations. Now head of cyber security at Red Helix, he argues that military crisis management, risk assessment and communication skills map directly onto how businesses should defend themselves against increasingly sophisticated AI-enabled attacks.
Exelby's core message for business leaders: security is not a brake on innovation. It is the foundation that makes innovation safe. "You cannot grow sustainably on weak foundations, and trying to do so usually costs more time and money later than building it in from the start," he said.
What the military teaches about cyber defence
Exelby points to three military principles that transfer directly to cybersecurity. The first is risk management under uncertainty. Military operators learn to act decisively without complete information - exactly the situation organisations face during an incident.
The second is complex programme management. Military strategic planning coordinates multiple moving parts toward one objective. Cybersecurity in a modern organisation works the same way, spanning people, process, technology and third parties, all changing at once.
The third is interpersonal skill. "The Army puts you in front of a very diverse range of situations, teams and stakeholders, often under pressure," Exelby said. That mirrors cybersecurity, where professionals move between technical teams, boards who need risk explained in business terms, and customers in the middle of a crisis.
AI changes the speed of attack, not the fundamentals
AI is increasing the speed, scale and sophistication of attacks. Exelby's advice is direct: if attackers move at machine speed, defence must too. But the fundamentals of security - identity management, access controls, cloud coverage - have not changed. They just need to be applied faster and more accurately.
"Identity and cloud remain the areas businesses most often neglect, and they're exactly where attackers are finding the easiest way in," he said. Detection and response need consistent coverage there, not just on traditional endpoints.
Exelby warns against chasing the latest tools while basics go uncovered. The businesses best placed to handle AI-enabled threats "aren't the ones with the most tools, they're the ones who've got the basics covered, at machine speed, built for resilience rather than hope."
For professionals looking to build these skills, training in AI for Cybersecurity Analysts covers the intersection of AI and security operations. Management teams can also explore AI for Management to understand governance and risk at the leadership level.
Crisis management: rehearse, clarify command, communicate
Military training treats crisis response as something to drill until it is second nature. Most organisations, Exelby said, have an incident response plan on paper but have never tested it under pressure. "An untested plan tends to fail exactly when it matters most."
Clear command and control is the second pillar. In a crisis, everyone needs to know their role and which decisions they own. Too often in business this is unclear when an incident hits, costing time and giving the adversary the upper hand.
The third is communication. The military trains people to share what is known, what is not known and what is being done, rather than waiting for a full picture. "Organisations that stay silent until everything is confirmed usually lose trust with customers and regulators faster than the incident itself would have cost them," Exelby said.
One change to make this year
Exelby's single recommendation is deliberately short: run an incident response exercise. Not a policy review - an actual exercise, with the right people making real decisions under pressure.
"This could be the difference between a business surviving an attack or failing because of one." The exercise is only half the value. The other half comes after: capture the lessons honestly, make the changes, and use the results to raise awareness across the whole business, not just the security team.
Why this matters for management
For managers, the takeaway is that cyber-resilience is a leadership issue, not a technical one. Boards that understand cybersecurity as an investment - not a cost - are better positioned to adopt AI and other new technology without betting the company on it. The organisations that come through crises well are the ones where people already knew their role and trusted the plan, because they had been through it before, even if only in a drill.
Your membership also unlocks: