If you have ever driven across Seattle’s Evergreen Point Floating Bridge, you know the feeling. Seven thousand, seven hundred and ten feet of calm, glassy water beneath you, and the longest, widest floating bridge in the world carrying you across. It is a marvel — and most people don’t realize just how much is happening beneath the surface.
That Bridge Is Sitting on a Lake That Has Soft Mud Underneath
Lake Washington, located between Seattle and its eastern suburbs, posed a significant engineering challenge for decades. The lake is over 200 feet deep in places, with an additional 100 feet of soft clay and mud below. No bedrock is accessible, making traditional bridge foundations unfeasible.
So, what did the engineers do? They did not try to force a foundation where one could not exist. Instead, they built a floating bridge with seventy-seven massive concrete pontoons, each the size of a ship, holding up six lanes of traffic and carrying 70,000 vehicles a day.
Most drivers have no idea the bridge beneath them is constantly rising, falling, and flexing with the water.
And that is the most interesting part and a lesson. The bridge is not stable because it resists movement. It is stable because it was engineered, down to the last detail, to adapt autonomously to changes in the flow and speed of the lake underneath, so traffic above keeps moving no matter what is happening below.
As a golden sunset descended, I sat enjoying the deeply satisfying Southwest Salad and some pan-fried potstickers at an eatery in nearby Kirkland, staring at the bridge and its undulations. I began wondering about the brilliance in the bridge’s design and how it handles the disruptions wind and waves hand it.
And it hit me. There is a lesson for every CISO and board member.
When breaches happen, and they will, our digital resilience must be built to adapt, not just resist. We need systems that flex and recover, not just stand rigid against the storm.
Today’s cyber leaders are in the same spot as those bridge engineers. The digital ground beneath us is soft and shifting. Despite all the money we pour into cybersecurity, attacks keep coming. Now, with AI in the mix, attackers have speed, scale, and complexity on their side, unless we build defenses that can adapt just as quickly.
And here’s the uncomfortable truth: the answer is not the next shiny cybersecurity tool that promises to stop every attack.
Kōun Ryūsui — The Ability to Adapt Effortlessly
Four decisions carried that bridge, and each one has a direct counterpart in how organizations will have to defend themselves over the next few years.
They Considered the Context to Be Prime
Engineers anchored the bridge according to the actual conditions. Fifty-eight anchors, connected by steel cables up to 1,000 feet long, secure the structure. Engineers used different anchor types based on the lakebed: fluke anchors for deep, soft areas; 420-ton gravity anchors for firm, sloped nearshore soils; and drilled shafts where gravity blocks would obstruct boats. Each solution matched the specific conditions at each location.
If we want to be breach ready, our defenses need to fit the way our digital systems actually work — whether that’s in the data center, the cloud, the factory floor, or the hospital. Too many security programs slap the same controls everywhere and call it consistency. That’s not readiness. That’s wishful thinking.
What works in one part of the business can fail spectacularly in another. Each area needs controls tailored to its own risks and realities.
They Assumed Breaches Would Happen. Continuously
Engineers designed the bridge assuming water intrusion was inevitable. Each pontoon is divided into watertight cells to prevent a breach from flooding the entire structure. Float switches, positioned three inches above the floor and connected by over 300 miles of cable, trigger an alarm when water reaches that level. Maintenance crews then isolate the affected cell and remove the water, allowing the bridge to remain operational.
The engineers never asked, “How do we keep all the water out?”
They asked, “How small can we keep the flooded volume, and how fast can we find it?”
That is the cyber resilience mindset.
Stop asking, “How do we stop every attack?”
Instead ask, “If an attack gets through, how do we keep it quarantined?”
The goal is to shrink the blast radius as much as possible — tailored to each system, not just a generic policy.
An intruder in one compartment? That is an incident. An intruder with free rein across the whole structure? That is tomorrow’s headline.
They Divided the Challenge Into Smaller Parts
They separated the road from the water. The deck does not sit on the pontoons. It stands about 20 feet above them on columns, resting on rubber-and-steel bearings that absorb the differential movement, with joints that accommodate up to two feet of lake-level change. The pontoons take the waves, twist and heave. The bearings eat the difference. The road stays flat.
Boards know real resilience isn’t about eliminating every disruption. It’s about adapting and withstanding them. Your systems need to absorb shocks so your most critical business services keep running — even if the infrastructure underneath takes a hit.
That is why every digital enterprise needs to be carved into breach-ready zones, with microsegments connected only through tightly controlled conduits, which can be disconnected to contain breaches.
They Were Prepared Before the Breach
Protocols were established in advance. The bridge is designed for a 100-year storm and sustained winds near 90 mph. Crews continuously monitor wind speed and follow predetermined checklists for warning and closure thresholds, ensuring proactive decisions are made with calm confidence, not in emergency chaos.
We see it all the time — even the biggest organizations freeze up during an incident, debating whether to take systems offline. Pressure mounts, information is incomplete, and decisions get delayed or made inconsistently.
Being prepared for the next cyberattack is the difference between telling your board, “We had to shut down everything to protect the business,” and “Our key services are still running — the impact is contained to a small part of the company.”
Start now. Build breach readiness that lets you anticipate, contain, withstand, and keep evolving, because the next attack is on its way.
Also Read: The CISO’s Guide to Containment in the Age of AI Attacks
This Is the Age of AI-Powered Cyberattacks
In 2026, the world witnessed the first documented large-scale AI-orchestrated cyber-espionage campaign, where a state-linked group targeted roughly 30 organizations, and the AI executed an estimated 80 to 90 percent of the operation on its own. Human operators contributed about twenty minutes of decision-making across phases that the machine ran for hours.
The campaign did not exploit new vulnerabilities. The difference was in speed, complexity, and scale. Tasks that once took skilled teams weeks now take automated agents only hours, making previously impractical attack paths feasible due to minimal labor costs. Also in 2026, every major AI company, viz., Anthropic, OpenAI, and Google, disclosed that AI agents escaped their sandboxes and attacked other companies.
Read More: Enable AI Without Expanding the Blast Radius
Watching the sunset, the waves, and the steady stream of traffic, I realized something.
The traffic on the bridge is increasing each year.
Surrounding businesses and communities are planning to use it more.
The storms themselves have changed.
They are coming faster and less predictably than ever.
And yet the bridge holds.
The more I dug in, the more lessons I found in cybersecurity.
The old 1963 bridge used to close all the time when the weather turned bad. Waves would wash right over the low deck. Today? The bridge almost never closes, even though the storms are fiercer and traffic is increasing.
What changed?
Better architecture, higher deck, stronger anchors, smarter compartments, constant monitoring, and regular inspections.
That is the lesson we need to learn.
We need foundational digital architecture to stop lateral movement that changes seamlessly along with changes in the digital environment, long before we embark on digital and AI innovation, and long before we set up AI governance.
Here is the reality check.
The conditions are not going to get better. Your breach-ready architecture has to keep up, or you will be left behind.
Access The Forrester Wave™: Microsegmentation Solutions, Q3 2026 | ColorTokens Is Named a Leader
Three Questions Worth Asking at Your Next Board Meeting
If an attacker is inside, do we already know, or would we guess the size of the largest compartment they can move within?
Which business services can keep running while we are actively containing an incident, and have we ever proven it outside a tabletop exercise?
What are our pre-agreed thresholds for degrading a service deliberately, who is authorized to call it, and when did we last rehearse that call?
If these questions spark debate instead of clear, confident answers, you’re not ready for the next cyberattack.
My Recommendation to Every Cyber Leader
Don’t try to build a foundation on unstable ground. The perimeter will remain dynamic, threats will continue to evolve, and AI-assisted adversaries will outpace traditional control certification.
Design systems that adapt on their own. Make zero trust your default. Wire your microsegmentation directly into your EDR.
Don’t wait. Start these changes this quarter:
Map your compartments. Know, with certainty, what an intruder could reach from every corner of your organization. If any area is too big, break it down. This is the single most effective move most organizations can make.
Automate your response to attack signals. Set up cheap, early, high-confidence alerts at the boundaries that matter, and connect them to systems empowered to respond at machine speed to contain anything suspicious.
Separate your crown jewels from everything else. Identify the services your business can’t afford to lose, and design them to keep running — even if the underlying systems are compromised, isolated, or rebuilt from scratch.
Build your closure protocol now. Set clear thresholds for AI agent access and monitoring. Decide who has the authority to disconnect them, and rehearse making that call before the crisis — not in the middle of it.
Test your anchors every year. Challenge your assumptions with real adversary simulations, and shore up anything that’s gone soft.
Set up a lofty goal. Build your own roadmap to achieve kōun ryūsui (行雲流水): the ability to adapt smoothly to changing conditions, staying focused and resilient without rigidity or getting lost.
The bridge doesn’t win by fighting the lake. It wins by no longer needing to resist it. Just like the commuters who use the bridge never realize how it weathers the disturbances, let your users, suppliers and leaders never realize how seamlessly you anticipate, withstand and evolve your ability to deal with cyber disturbances.
If you’re thinking about how to build this kind of breach readiness into your environment, contact us to continue the conversation.