{"id":3949,"date":"2026-08-03T04:09:52","date_gmt":"2026-08-03T04:09:52","guid":{"rendered":"https:\/\/futureknowledge.in\/?p=3949"},"modified":"2026-08-03T04:09:52","modified_gmt":"2026-08-03T04:09:52","slug":"making-sense-of-cybersecurity-part-1-seeing-through-complexity","status":"publish","type":"post","link":"https:\/\/futureknowledge.in\/?p=3949","title":{"rendered":"Making Sense of Cybersecurity \u2013 Part 1: Seeing Through Complexity"},"content":{"rendered":"<p><span style=\"font-weight: 400\">At the <a href=\"https:\/\/www.blackhat.com\/eu-24\/\">Black Hat Europe<\/a> conference in December, I sat down with one of our senior security analysts, <a href=\"https:\/\/gigaom.com\/analyst\/stringfellow-paul\/\">Paul Stringfellow<\/a>. In this first part of our conversation we discuss the complexity of navigating cybersecurity tools, and defining relevant metrics to measure ROI and risk.<\/span><\/p>\n<p><b>Jon:<\/b><span style=\"font-weight: 400\"> Paul, how does an end-user organization make sense of everything going on? We\u2019re here at Black Hat, and there\u2019s a wealth of different technologies, options, topics, and categories. In our research, there are 30-50 different security topics: posture management, service management, asset management, SIEM, SOAR, EDR, XDR, and so on. However, from an end-user organization perspective, they don\u2019t want to think about 40-50 different things. They want to think about 10, 5, or maybe even 3. Your role is to deploy these technologies. How do they want to think about it, and how do you help them translate the complexity we see here into the simplicity they\u2019re looking for?<\/span><\/p>\n<p><b>Paul:<\/b><span style=\"font-weight: 400\">\u00a0I attend events like this because the challenge is so complex and rapidly evolving. I don\u2019t think you can be a modern CIO or security leader without spending time with your vendors and the broader industry. Not necessarily at Black Hat Europe, but you need to engage with your vendors to do your job.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Going back to your point about 40 or 50 vendors, you\u2019re right. The average number of cybersecurity tools in an organization is between 40 and 60, depending on which research you refer to. So, how do you keep up with that? When I come to events like this, I like to do two things\u2014and I\u2019ve added a third since I started working with GigaOm. One is to meet with vendors, because people have asked me to. Two, go to some presentations. Three is to walk around the Expo floor talking to vendors, particularly ones I\u2019ve never met, to see what they do.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">I sat in a session yesterday, and what caught my attention was the title: \u201cHow to identify the cybersecurity metrics that are going to deliver value to you.\u201d That caught my attention from an analyst\u2019s point of view because part of what we do at GigaOm is create metrics to measure the efficacy of a solution in a given topic. But if you&#8217;re deploying technology as part of SecOps or IT operations, you&#8217;re gathering a lot of metrics to try and make decisions. One of the things they talked about in the session was the issue of creating so many metrics because we have so many tools that there\u2019s so much noise. How do you start to find out the value?<\/span><\/p>\n<p><span style=\"font-weight: 400\">The long answer to your question is that they suggested something I thought was a really smart approach: step back and think as an organization about what metrics matter. What do you need to know as a business? Doing that allows you to reduce the noise and also potentially reduce the number of tools you&#8217;re using to deliver those metrics. If you decide a certain metric no longer has value, why keep the tool that provides it? If it doesn\u2019t do anything other than give you that metric, take it out. I thought that was a really interesting approach. It\u2019s almost like, \u201cWe\u2019ve done all this stuff. Now, let\u2019s think about what actually still matters.\u201d<\/span><\/p>\n<p><span style=\"font-weight: 400\">This is an evolving space, and how we deal with it must evolve, too. You can\u2019t just assume that because you bought something five years ago, it still has value. You probably have three other tools that do the same thing by now. How we approach the threat has changed, and how we approach security has changed. We need to go back to some of these tools and ask, \u201cDo we really need this anymore?\u201d<\/span><\/p>\n<p><b>Jon:<\/b><span style=\"font-weight: 400\">\u00a0We measure our success with this, and, in turn, we\u2019re going to change.<\/span><\/p>\n<p><b>Paul:<\/b><span style=\"font-weight: 400\">\u00a0Yes, and I think that\u2019s hugely important. I was talking to someone recently about the importance of automation. If we\u2019re going to invest in automation, are we better now than we were 12 months ago after implementing it? We\u2019ve spent money on automation tools, and none of them come for free. We\u2019ve been sold on the idea that these tools will solve our problems. One thing I do in my CTO role, outside of my work with GigaOm, is to take vendors\u2019 dreams and visions and turn them into reality for what customers are asking for.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Vendors have aspirations that their products will change the world for you, but the reality is what the customer needs at the other end. It\u2019s that kind of consolidation and understanding\u2014being able to measure what happened before we implemented something and what happened after. Can we show improvements, and has that investment had real value?<\/span><\/p>\n<p><b>Jon:<\/b><span style=\"font-weight: 400\">\u00a0Ultimately, here\u2019s my hypothesis: Risk is the only measure that matters. You can break that down into reputational risk, business risk, or technical risk. For example, are you going to lose data? Are you going to compromise data and, therefore, damage your business? Or will you expose data and upset your customers, which could hit you like a ton of bricks? But then there\u2019s the other side\u2014are you spending way more money than you need, to mitigate risks?\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">So, you get into cost, efficiency, and so on, but is this how organizations are thinking about it? Because that\u2019s my old-school way of viewing it. Maybe it\u2019s moved on.<\/span><\/p>\n<p><b>Paul:<\/b><span style=\"font-weight: 400\">\u00a0I think you\u2019re on the right track. As an industry, we live in a little echo chamber. So when I say &#8220;the industry,&#8221; I mean the little bit I see, which is just a small part of the whole industry. But within that part, I think we are seeing a shift. In customer conversations, there\u2019s a lot more talk about risk. They\u2019re starting to understand the balance between spending and risk, trying to figure out how much risk they\u2019re comfortable with. You\u2019re never going to eliminate all risk. No matter how many security tools you implement, there\u2019s always the risk of someone doing something stupid that exposes the business to vulnerabilities. And that\u2019s before we even get into AI agents trying to befriend other AI agents to do malicious things\u2014that\u2019s a whole different conversation.<\/span><\/p>\n<p><b>Jon:<\/b><span style=\"font-weight: 400\">\u00a0Like social engineering?<\/span><\/p>\n<p><b>Paul:<\/b><span style=\"font-weight: 400\">\u00a0Yeah, very much so. That\u2019s a different show altogether. But, understanding risk is becoming more common. The people I speak to are starting to realize it\u2019s about risk management. You can\u2019t remove all the security risks, and you can\u2019t deal with every incident. You need to focus on identifying where the real risks lie for your business. For example, one criticism of CVE scores is that people look at a CVE with a 9.8 score and assume it\u2019s a massive risk, but there\u2019s no context around it. They don\u2019t consider whether the CVE has been seen in the wild. If it hasn\u2019t, then what\u2019s the risk of being the first to encounter it? And if the exploit is so complicated that it\u2019s not been seen in the wild, how realistic is it that someone will use it?<\/span><\/p>\n<p><span style=\"font-weight: 400\">It&#8217;s such a complicated thing to exploit that nobody will ever exploit it. It has a 9.8, and it shows up on your vulnerability scanner saying, \u201cYou really need to deal with this.\u201d The reality is that you have already seen a shift where there\u2019s no context applied to that\u2014if we\u2019ve seen it in the wild.<\/span><\/p>\n<p><b>Jon:<\/b><span style=\"font-weight: 400\">\u00a0Risk equals probability multiplied by impact. So you\u2019re talking about probability and then, is it going to impact your business? Is it affecting a system used for maintenance once every six months, or is it your customer-facing website? But I\u2019m curious because back in the 90s, when we were doing this hands-on, we went through a wave of risk avoidance, then went to, &#8220;We\u2019ve got to stop everything,&#8221; which is what you&#8217;re talking about, through to risk mitigation and prioritizing risks, and so on.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">But with the advancement of the Cloud and the rise of new cultures like agile in the digital world, it feels like we&#8217;ve gone back to the direction of, \u201cWell, you need to prevent that from happening, lock all the doors, and implement zero trust.\u201d And now, we\u2019re seeing the wave of, \u201cMaybe we need to think about this a bit smarter.\u201d<\/span><\/p>\n<p><b>Paul:<\/b><span style=\"font-weight: 400\">\u00a0It\u2019s a really good point, and actually, it\u2019s an interesting parallel you raise. Let\u2019s have a little argument while we\u2019re recording this. Do you mind if I argue with you? I\u2019ll question your definition of zero trust for a moment. So, zero trust is often seen as something trying to stop everything. That\u2019s probably not true of zero trust. Zero trust is more of an approach, and technology can help underpin that approach. Anyway, that\u2019s a personal debate with myself. But, zero trust&#8230;<\/span><\/p>\n<p><span style=\"font-weight: 400\">Now, I\u2019ll just crop myself in here later and argue with myself. So, zero trust&#8230; If you take it as an example, it\u2019s a good one. What we used to do was implicit trust\u2014you\u2019d log on, and I\u2019d accept your username and password, and everything you did after that, inside the secure bubble, would be considered valid with no malicious activity. The problem is, when your account is compromised, logging in might be the only non-malicious thing you&#8217;re doing. Once logged in, everything your compromised account tries to do is malicious. If we\u2019re doing implicit trust, we\u2019re not being very smart.<\/span><\/p>\n<p><b>Jon:<\/b><span style=\"font-weight: 400\">\u00a0So, the opposite of that would be blocking access entirely?<\/span><\/p>\n<p><b>Paul:<\/b><span style=\"font-weight: 400\">\u00a0That\u2019s not the reality. We can\u2019t just stop people from logging in. Zero trust allows us to let you log on, but not blindly trust everything. We trust you for now, and we continuously evaluate your actions. If you do something that makes us no longer trust you, we act on that. It\u2019s about continuously assessing whether your activities are appropriate or potentially malicious and then acting accordingly.<\/span><\/p>\n<p><b>Jon:<\/b><span style=\"font-weight: 400\">\u00a0It\u2019s going to be a very disappointing argument because I agree with everything you say. You argued with yourself more than I\u2019m going to be able to, but I think, as you said, the castle defense model\u2014once you\u2019re in, you\u2019re in.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">I\u2019m mixing two things there, but the idea is that once you\u2019re inside the castle, you can do whatever you like. That\u2019s changed.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">So, what to do about it? Read <a href=\"https:\/\/gigaom.com\/2025\/01\/09\/making-sense-of-cybersecurity-part-2-delivering-a-cost-effective-response\/\">Part 2<\/a>, for how to deliver a cost-effective response.\u00a0<\/span><\/p>\n<p>The post <a href=\"https:\/\/gigaom.com\/2025\/01\/09\/making-sense-of-cybersecurity-part-1-seeing-through-complexity\/\">Making Sense of Cybersecurity &#8211; Part 1: Seeing Through Complexity<\/a> appeared first on <a href=\"https:\/\/gigaom.com\">Gigaom<\/a>.<\/p>\n<p><em>Source: <a href='https:\/\/gigaom.com\/2025\/01\/09\/making-sense-of-cybersecurity-part-1-seeing-through-complexity\/' target='_blank'>Read the original article on gigaom.com<\/a><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>At the Black Hat Europe conference in December, I sat down with one of our senior security analysts, Paul Stringfellow. In this first part of our conversation we discuss the complexity of navigating cybersecurity tools, and defining relevant metrics to measure ROI and risk. Jon: Paul, how does an end-user organization make sense of everything [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3950,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-3949","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/posts\/3949","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3949"}],"version-history":[{"count":0,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/posts\/3949\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/media\/3950"}],"wp:attachment":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3949"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3949"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3949"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}