In the wake of large-scale cloud outages and cyber breaches that bring business to a grinding halt, corporate boards and the C-suite have been continuously pushing for greater business and cyber resilience.
One ongoing resiliency challenge has been keeping up with adversaries who move at machine speed and play by no rules. The best way to address the gap is anti-fragility, according to cybersecurity experts speaking at RSAC 2026 in San Francisco this week.
“We want systems that are self-healing, systems that are evolving themselves.”Anthony Rodriguez, AVP of application security engineering and threat management at CVS Health
A session on the first day of the annual industry event contrasted resilience, the ability to withstand stress, with anti-fragility, in which a system uses stress to improve—thus becoming more resilient. John Kindervag, chief evangelist at Illumio — and a former Forrester analyst who created the zero trust model — and Anthony Rodriguez, AVP of application security engineering and threat management at CVS Health, urged cybersecurity teams to move away from resilience and toward the more adaptive and proactive anti-fragility.
Why resiliency is no longer enough
Once you acknowledge that attackers will eventually find your weaknesses, you need to build a practice of intentionally stressing your systems before attackers do it for you.
Kindervag drew an analogy to weightlifting. The human body is an anti-fragile system, and when you lift weights, your body gets stronger during recovery. The stress of the workout leads to positive gains and greater adaptability if stress and recovery are in balance.
In cyber systems, the stressor is an attack or incident, and the adaptation engine is zero trust. Kindervag and Rodriguez said that cybersecurity and engineering have been moving toward a state of greater dynamic readiness. You can see that across the industry as static, reactive systems move toward proactive and real-time.
AI is both exacerbating cybersecurity risks and helping engineers mitigate those risks. “We want systems that are self-healing, systems that are evolving themselves,” said Rodriguez. “Organizations can take those same signals and evolve faster. The key is if you're going to pick up on the signals and use them.”
Kindervag noted that nobody wants to spend money or do anything until something bad happens, citing an executive who recently told him that a $150 million fine is just a rounding error. “We’ve got to get leadership to start caring about cybersecurity and quit waiting for the bad things to happen,” Kindervag said.
The pair covered the role of AI in enhancing system adaptability and the importance of reducing manual processes to better respond to unknown threats, and folding in chaos engineering principles, which involve deliberately introducing stressors to systems to identify weaknesses and improve overall robustness.
Engineering for Real World Chaos
Source: “Beyond Resilience: Building Anti-Fragile Cyber Systems,” RSAC 2026
They argued that anti-fragility should be a continuous process, with organizations learning from each incident to prevent future occurrences. That means going beyond disaster recovery and business continuity thinking. To evolve your systems to successfully operate under continuous stress, trade standard, linear DR/BC strategies for injecting chaos to actively try to take out your production environment.
“It’s better that you just plan for the fact that you will have a failure ... not whatever particular failure that you're hoping for—and you continuously try to break it... taking systems down, putting real traffic against it, going through different scenarios, just continuously add stress to the environment and the teams that support that environment,” Rodriguez said.
“We’ve got to get leadership to start caring about cybersecurity and quit waiting for the bad things to happen.”John Kindervag, chief evangelist at Illumio
“It’s better that you just plan for the fact that you will have a failure," Rodriguez said. What failure will hit your infrastructure is not predictable, he added, so "you continuously try to break it ... taking systems down, putting real traffic against it, going through different scenarios, just continuously add stress to the environment and the teams that support that environment."
Practical steps to start the anti-fragile journey
The speakers recommended starting small, focusing on specific areas for improvement, and continuously iterating to build a more resilient and adaptive cybersecurity posture.
Below is a version of their steps with additionally sourced detail:
Next week
Pick a target or workflow like a high-value service or a frequent incident source and define three to five stressors such as dependency outage, region failover, credential misuse scenario, anomalous east–west traffic, or a “bad deploy.” Then identify signals that would tell you the system is drifting into danger.
And review the last incident and extract one systemic fix you can ship now.
Next 90 days
Practice failover by moving real traffic through your backup paths regularly, so they don’t stagnate. Automate the recurring fixes such as log rotation, guardrails, configuration drift detection, and dependency checks. Next, apply segmentation and least-privilege boundaries to reduce the blast radius. Broaden the fix by searching for similar failures once you discover the first and search for the same condition across the environment and remediate.
Next six months
Incorporate behavior, device, network, and workload signals for better decision-making, and don't just assume “authenticated = trusted." Institutionalize controlled stress by scheduling chaos drills and red-team exercises with clear learning objectives. Track meaningful metrics such as recurrence reduction and systemic risk reduction, time-to-recover, and blast radius containment. Finally, reward the quiet, often thankless work of prevention and creating durable fixes while discouraging hero culture and blame.
Measuring Anti-Fragility
Source: “Beyond Resilience: Building Anti-Fragile Cyber Systems,” RSAC 2026
Cultivating an anti-fragility culture
Kindervag and Rodriguez closed by reinforcing a central distinction: Resilience keeps you alive; anti‑fragility changes your trajectory.
When organizations treat stress as a signal, practice failure deliberately, apply learning across teams, and align culture around improvement, security programs don’t merely endure stress, they get better under pressure.
“Security shouldn't just help you withstand the attacks,” Kindervag said. “It should help you get stronger and stronger over time.”
