{"id":3947,"date":"2026-08-03T04:09:51","date_gmt":"2026-08-03T04:09:51","guid":{"rendered":"https:\/\/futureknowledge.in\/?p=3947"},"modified":"2026-08-03T04:09:51","modified_gmt":"2026-08-03T04:09:51","slug":"making-sense-of-cybersecurity-part-2-delivering-a-cost-effective-response","status":"publish","type":"post","link":"https:\/\/futureknowledge.in\/?p=3947","title":{"rendered":"Making Sense of Cybersecurity \u2013 Part 2: Delivering a Cost-effective Response"},"content":{"rendered":"<p><span style=\"font-weight: 400\">At <a href=\"https:\/\/www.blackhat.com\/eu-24\/\">Black Hat Europe<\/a> last year, I sat down with one of our senior security analysts, <a href=\"https:\/\/gigaom.com\/analyst\/stringfellow-paul\/\">Paul Stringfellow<\/a>. In this section of our conversation (you can find the first part <a href=\"https:\/\/gigaom.com\/2025\/01\/09\/making-sense-of-cybersecurity-part-1-seeing-through-complexity\/\">here<\/a>), we discuss balancing cost and efficiency, and aligning security culture across the organization.<\/span><\/p>\n<p><span style=\"font-weight: 400\"><strong>Jon:<\/strong> So, Paul, in an environment with problems everywhere, and you\u2019ve got to fix everything, we need to move beyond that. In the new architectures we now have, we need to be thinking smarter about our overall risk. This ties into cost management and service management\u2014being able to grade our architecture in terms of actual risk and exposure from a business perspective.<\/span><\/p>\n<p><span style=\"font-weight: 400\">So, I\u2019m kind of talking myself into needing to buy a tool for this because I think that in order to cut through the 50 tools, I first need a clear view of our security posture. Then, we can decide which of the tools we have actually respond to that posture because we\u2019ll have a clearer picture of how exposed we are.<\/span><\/p>\n<p><b>Paul:<\/b><span style=\"font-weight: 400\"> Buying a tool goes back to vendors\u2019 hopes and dreams\u2014that one tool will fix everything. But I think the reality is that it\u2019s a mix of understanding what metrics are important. Understanding the information we\u2019ve gathered, what\u2019s important, and balancing that with the technology risk and the business impact. You made a great point before: if something\u2019s at risk but the impact is minimal, we have limited budgets to work with. So where do we spend? You want the most \u201cbang for your buck.\u201d<\/span><\/p>\n<p><span style=\"font-weight: 400\">So, it\u2019s understanding the risk to the business. We\u2019ve identified the risk from a technology point of view, but how significant is it to the business? And is it a priority? Once we\u2019ve prioritized the risks, we can figure out how to address them. There\u2019s a lot to unpack in what you\u2019re asking. For me, it\u2019s about doing that initial work to understand where our security controls are and where our risks lie. What really matters to us as an organization? Go back to the important metrics\u2014eliminating the noise and identifying metrics that help us make decisions. Then, look at whether we\u2019re measuring those metrics. From there, we assess the risks and put the right controls in place to mitigate them. We do that posture management work. Are the tools we have in place responding to that posture? This is just the internal side of things, but there\u2019s also external risk, which is a whole other conversation, but it\u2019s the same process.<\/span><\/p>\n<p><span style=\"font-weight: 400\">So, looking at the tools we have, how effective are they in mitigating the risks we\u2019ve identified? There are lots of risk management frameworks, so you can probably find a good fit, like NIST or something else. Find a framework that works for you, and use that to evaluate how your tools are managing risk. If there\u2019s a gap, look for a tool that fills that gap.<\/span><\/p>\n<p><b>Jon: <\/b><span style=\"font-weight: 400\">And I was thinking about the framework because it essentially says there are six areas to address, and maybe a seventh could be important to your organization. But at least having the six areas as a checkbox: Am I dealing with risk response? Am I addressing the right things? It gives you that, not Pareto view, but it\u2019s about diminishing returns\u2014cover the easiest stuff first. Don\u2019t try to fix everything until you\u2019ve fixed the most common issues. That\u2019s what people are trying to do right now.<\/span><\/p>\n<p><b>Paul:<\/b><span style=\"font-weight: 400\">\u00a0Yeah, I think\u2014let me quote another podcast I do, where we do &#8220;tech takeaways.&#8221; Yeah, who knew? I thought I\u2019d plug it. But if you think about the takeaways from this conversation, I think, you know, going back to your question\u2014what should I be considering as an organization? I think the starting point is probably to take a step back. As a business, as an IT leader inside that business, am I taking a step back to really understand what risk looks like? What does risk look like to the business, and what needs to be prioritized? Then, we need to assess whether we\u2019re capable of measuring our efficacy against that risk. We\u2019re getting lots of metrics and lots of tools. Are those tools effective in helping us avoid the risks we deem important for the business? Once we\u2019ve answered those two questions, we can then look at our posture. Are the tools in place giving us the kind of controls we need to deal with the threats we face? Context is huge.<\/span><\/p>\n<p><b>Jon:<\/b><span style=\"font-weight: 400\">\u00a0On that note, I\u2019m reminded of how organizations like Facebook, for example, had a pretty high tolerance for business risk, especially around customer data. Growth was everything\u2014just growth at all costs. So, they were prepared to manage the risks to achieve that. It ultimately boils down to assessing and taking those risks. At that point, it&#8217;s no longer a technical conversation.<\/span><\/p>\n<p><b>Paul:<\/b><span style=\"font-weight: 400\">\u00a0Exactly. It probably never is just a technical conversation. To deliver projects that address risk and security, it should never be purely technical-led. It impacts how the company operates and the daily workflow. If everyone doesn\u2019t buy into why you\u2019re doing it, no security project is going to succeed. You\u2019ll get too much pushback from senior people saying, \u201cYou\u2019re just getting in the way. Stop it.\u201d You can\u2019t be the department that just gets in the way. But you do need that culture across the company that security is important. If we don\u2019t prioritize security, all the hard work everyone\u2019s doing could be undone because we haven\u2019t done the basics to ensure there aren\u2019t vulnerabilities waiting to be exploited.<\/span><\/p>\n<p><b>Jon:<\/b><span style=\"font-weight: 400\">\u00a0I\u2019m just thinking about the number of conversations I\u2019ve had with vendors on how to sell security products. You\u2019ve sold it, but then nothing gets deployed because everyone else tries to block it\u2014they didn\u2019t like it. The reality is that the company needs to work towards something and make sure everything aligns to deliver it.<\/span><\/p>\n<p><b>Paul:<\/b><span style=\"font-weight: 400\"> One thing I\u2019ve noticed over my 30-plus years in this job is how vendors often struggle to explain why they might be valuable to a business. Our COO, Howard Holton, is a big advocate of this argument\u2014that vendors are terrible at telling people what they actually do and where the benefit lies for a business. But one thing he said to me yesterday was about their approach. One representative I know works for a vendor offering an orchestration and automation tool, but when he starts a meeting, the first thing he does is ask why automation hasn\u2019t worked for the customer. Before he pitches his solution, he takes the time to understand where their automation problems are. If more of us did that\u2014vendors and others alike\u2014if we first asked, &#8220;What\u2019s not working for you?&#8221; maybe we\u2019d get better at finding the things that will work.<\/span><\/p>\n<p><b>Jon:<\/b><span style=\"font-weight: 400\"> So we have two takeaways for end users &#8211; to focus on risk management, and to simplify and refine security metrics. And for vendors, the takeaway is to understand the customer&#8217;s challenges before pitching a solution. By listening to the customer&#8217;s problems and needs, vendors can provide relevant and effective solutions, rather than simply selling their aspirations. Thanks, Paul!<\/span><\/p>\n<p>The post <a href=\"https:\/\/gigaom.com\/2025\/01\/09\/making-sense-of-cybersecurity-part-2-delivering-a-cost-effective-response\/\">Making Sense of Cybersecurity &#8211; Part 2: Delivering a Cost-effective Response<\/a> appeared first on <a href=\"https:\/\/gigaom.com\">Gigaom<\/a>.<\/p>\n<p><em>Source: <a href='https:\/\/gigaom.com\/2025\/01\/09\/making-sense-of-cybersecurity-part-2-delivering-a-cost-effective-response\/' target='_blank'>Read the original article on gigaom.com<\/a><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>At Black Hat Europe last year, I sat down with one of our senior security analysts, Paul Stringfellow. In this section of our conversation (you can find the first part here), we discuss balancing cost and efficiency, and aligning security culture across the organization. Jon: So, Paul, in an environment with problems everywhere, and you\u2019ve [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3948,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[36,3],"tags":[14,29,33],"class_list":["post-3947","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-share-suggestions","category-technology","tag-impact-meta","tag-signal-avoid","tag-stage-stage-4"],"_links":{"self":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/posts\/3947","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3947"}],"version-history":[{"count":0,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/posts\/3947\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/media\/3948"}],"wp:attachment":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3947"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3947"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3947"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}