ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Oops, I did it again

Robert Leong from HCLSoftware’s Big Fix explains how to balance cyber-risk with business goals

 

It’s common to think of cyber-security as a zero-sum game — a contest between attackers and defenders where only one side can triumph and the stakes are winner-take-all.

 

But as tempting as it is to think in absolutes, it’s more useful in the real world to treat cyber-security as a business problem — one where risks are measured and managed with business goals in mind.

 

From that pragmatic POV, the goal of measuring cyber-risk is not to achieve “zero risk,” but to reduce risk to a justifiable level. Specifically, it must be reduced to a level that is justifiable before your stakeholders — your customers, investors, employees, co-workers.

 

That practical goal corresponds to a real-world truth: you can’t secure everything. This, in turn, means security risks are like every other business risk: you must prioritise which cyber-risks you manage.

 

Don’t misunderstand. The quality and quantity of threat intelligence available to security teams today — along with the tools and techniques available — provide a great starting point for cyber-defenders.

 

In practice, though, the number of threats and amount of information about them are overwhelming. Every year, hundreds of adversarial campaigns are launched by skilled, professional attackers — often organised crime syndicates or state-sponsored threat actors. Faced with this complex and constantly evolving threat landscape, you have to prioritise your response.

 

That prospect may sound daunting. However, when push comes to shove, for every threat, there are three key questions you must ask and answer:

  • Should we worry? Is this threat a priority? If so, why?
  • Are we OK? Can we effectively stop or mitigate against this threat? Have we minimised our threat surface?
  • If we’re not OK, what should we do? Precisely what action should we take if we’re not OK?

If you can answer these questions, you’ll be able to assess, prioritise, and address the threats coming your way. The trick is to maximise the effectiveness of your defences, balancing costs against risks to find the “sweet spot” that is justifiable before stakeholders.

 

“Oops, I did it again…”

Let’s talk about what is likely the most overlooked area of cyber-risk. Exploitable computer vulnerabilities are essentially “mistakes in programming” or “Oops” — and with the massive shift to a remote or hybrid workforce and the massive changes to the computing ecosystem which made that shift possible, the number of “mistakes in programming” is at a record high and still increasing.

 

Yes indeed, “Oops” keeps happening over and over again. Did you know that the infamous Conti Ransomware leverages numerous different vulnerabilities? The question is, what will we do about it? 

 

Consider this astonishing stat: nearly 60% of organisations surveyed said they suffered at least one recent data breach because a patch available for a known vulnerability wasn’t applied. In related news, only 9% of security and IT leaders rate themselves as “effective at vulnerability remediation.” — and one-third of all detected vulnerabilities remain unremediated after a year.

 

Clearly, an area of focus for security and IT teams is to develop a system to make threat intelligence actionable — and then make sure to take action.

 

Automation: a cyber-security gamechanger

Automation is critically important in addressing these procedural deficits. No one alive could track the tsunami of threat intelligence crashing down on us day after day — but there are ways to address more of those threats without direct attention or effort.

 

Automating threat intelligence analysis and action — leveraging the right framework, tools, and procedures — can transform your security practice by:

  • Immediately reporting your attack surface posture against attackers, the vulnerabilities they’re known to exploit, and where your weak spots are.
  • Quickly collecting everything you need to remediate those vulnerabilities.
  • Pragmatically prioritising the vulnerabilities, and identifying and presenting the least disruptive, most efficient strategies for doing so.
  • Efficiently remediating those prioritised vulnerabilities and measuring the actual reduction of cyber-risk in a way that everyone can understand.

In short, automation can transform your cyber-security capabilities — enabling immediate action and vastly increasing the range and volume of threats you can address, all with minimal attention and effort on the part of your team.

 

Treating cyber-security as a business problem — leveraging automation and integrating security with business IT processes — empowers you to address cyber-threats rationally and manage cyber-risk pragmatically.

 

By combining the power of automation with reliable threat intelligence, security best practices, and a prioritised and efficient approach, you can answer and act on those three key questions quickly and efficiently — keeping cost and effort to a minimum and protecting your organisation at scale.

 


 

Robert Leong is a cyber-security expert at HCLSoftware’s Big Fix

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543