if ( !emtpy($headline_subheadline ) ) : ?>
New tools are exciting, but strengthening baseline capabilities provides a better bang for your security budget. Here are five tips for security leaders looking to make a measurable impact.
endif; ?>
Risk management has always been a difficult job, but the current threat landscape has taken the challenge to a new level. I’ve spent years leading cybersecurity efforts at large enterprises, including Hyatt and United Airlines, and in that time I’ve seen cybercriminals grow increasingly creative, leveraging innovative tactics and technology to further their efforts. I’ve also seen security professionals make the mistake of assuming that responding to those new and emerging tactics requires shiny new tech tools. In reality, mastering foundational controls is what moves the needle.
New tools are exciting and innovative, so it’s easy to understand the draw. But they’re often less impactful than simply focusing on strong fundamentals. Embracing AI, for example, can provide real value for organizations, but it is only effective when built upon a rock-solid foundation of security basics. Don’t spend your budget cycling through expensive new security tools each quarter. Get real bang for your buck by strengthening the baseline security capabilities that have a real, measurable impact on attacker success.
Here are five areas that fit the bill.
1. Gain visibility with better asset discovery and management
One of the most troubling issues plaguing modern businesses is a lack of visibility. If you don’t know where an asset is located within your digital environment, you won’t be able to protect it. If you don’t know an asset exists in the first place, it’s an even bigger problem.
Today’s businesses need to secure on-premises servers, cloud (and multicloud) environments, individual devices and endpoints, third-party applications, and countless other potential targets. If you don’t have an up-to-date, actively maintained inventory of every asset present within those systems, you’re putting your business at unnecessary risk.
That means engaging in a comprehensive discovery process that encompasses all your digital environments is a critical first step toward greater security. Working within larger enterprises gave me a greater appreciation for the importance of asset management. Inventory of physical and digital assets often are scattered across the organization. One of my biggest wins is bringing that all together by (1) identifying what platform should be the single source of truth and (2) integrating these data points, ensuring the data is accurate, and updating accordingly.
2. Manage your identities more effectively
Security leaders have been saying “identity is the new perimeter” for almost a decade, but identity management is still overlooked or taken for granted. That’s a real problem, because the average organization now manages tens (if not hundreds) of thousands of human identities, machine identities, applications, AI agents, and countless other identity types.
When I worked for Hyatt, I saw firsthand how challenging it could be to manage the endless cycle of visitor identities alongside full-time staff, part-time workers, contractors, and others. Manual management is impossible at this scale, which means an effective identity platform is essential.
I have my teams start by ensuring the most basic security measures are in place. For example, we’ve known for decades that multifactor authentication (MFA) significantly decreases the likelihood that an identity will be compromised. MFA isn’t a magic bullet that will solve every problem, but research shows that accounts with MFA are 99% less likely to be hacked. Personally, I would go one step further by implementing passkeys, which have proven even more effective and alleviate friction on remembering and entering passwords. It’s a win-win situation, as some security enhancements can create unwanted friction. This is the opposite of that.
3. Right-size your approach to security
Too many organizations get caught up in chasing the “latest and greatest” security technology, but it’s important to consider what your business actually needs. That starts with determining your risk appetite.
What products or services represent the “crown jewels” of your organization? What data can you not afford to lose access to? Preventing disruption to those areas should be your top priority, and where most of your attention should be focused. From there, you can move down the ladder, assigning priority tiers to specific risks and determining which are acceptable and which are not.
It doesn’t matter how big or small your organization is. It is imperative to create a common security framework that can be understood and digested at all levels in the organization. This will provide your organization a clear picture of how well your security program is doing. Start small and leverage widely used frameworks like CIS CSC to initiate the conversation. From there, strengthen your foundation by identifying what is working and what is not.
Every organization takes risks based on the business appetite. We just need to have the data to make informed decisions about what to prioritize.
4. Prioritize resilience and recovery
Security and risk management used to focus heavily on prevention, but that’s no longer enough in today’s threat environment. The complex, sprawling nature of the modern digital landscape means that, with enough time and resources, a determined attacker will find a vulnerability to exploit. That doesn’t mean security teams should abandon prevention — it’s always a good idea to make the attacker’s life as hard as possible — but it does mean resilience and recovery must be prioritized, too.
That starts with having the right systems and processes in place to react to a breach. The quicker you can identify a breach in progress, the quicker you can shut it down. But if the worst does come to pass and your organization suffers a serious breach, it also means having a recovery plan. Secure backups for both systems and data are a must, but technology alone isn’t enough. You need to have the right processes in place, and you need to practice putting them into action. Too many organizations overlook this critical step, leaving employees wondering what to do in a crisis.
5. Create a common security language
This may sound a bit abstract, but it’s arguably the most important step. Too often, the biggest obstacle preventing organizations from managing risk more effectively is poor communication between those on the security side and those on the business side. Business leaders often lack the technical expertise to understand the details of specific security risks, while risk management professionals aren’t always well versed in the language of business. Bridging that communications gap is critical.
For security and risk management teams, it’s important to be able to quantify risks in a meaningful way, assigning a dollar value whenever possible. While it’s admittedly difficult to estimate the cost of a breach or security incident that didn’t happen, there are defensible metrics to assign value to risks based on projected lost business, regulatory penalties, reputational damage, and other factors.
Building a strong foundation of security fundamentals
The rapid adoption of AI is unlocking unprecedented potential across every industry, but even the most cutting-edge technology can’t solve every problem on its own. If you really want to reduce your cyber risk in a meaningful way, you need to build a strong foundation of security fundamentals. That means doing the “un-sexy” work in the security trenches, like identifying visibility gaps, prioritizing resilience, and improving interdepartmental communication.
Take it from a longtime CISO: Security isn’t always exciting. In fact, it shouldn’t be. The most effective action you can take to reduce your exposure and keep your digital environments secure is to focus your efforts on the everyday vulnerabilities commonly exploited by real-world attackers.










