
Robert Leong from HCLSoftware’s Big Fix explains how to balance cyber-risk with business goals
It’s common to think of cyber-security as a zero-sum game — a contest between attackers and defenders where only one side can triumph and the stakes are winner-take-all.
But as tempting as it is to think in absolutes, it’s more useful in the real world to treat cyber-security as a business problem — one where risks are measured and managed with business goals in mind.
From that pragmatic POV, the goal of measuring cyber-risk is not to achieve “zero risk,” but to reduce risk to a justifiable level. Specifically, it must be reduced to a level that is justifiable before your stakeholders — your customers, investors, employees, co-workers.
That practical goal corresponds to a real-world truth: you can’t secure everything. This, in turn, means security risks are like every other business risk: you must prioritise which cyber-risks you manage.
Don’t misunderstand. The quality and quantity of threat intelligence available to security teams today — along with the tools and techniques available — provide a great starting point for cyber-defenders.
In practice, though, the number of threats and amount of information about them are overwhelming. Every year, hundreds of adversarial campaigns are launched by skilled, professional attackers — often organised crime syndicates or state-sponsored threat actors. Faced with this complex and constantly evolving threat landscape, you have to prioritise your response.
That prospect may sound daunting. However, when push comes to shove, for every threat, there are three key questions you must ask and answer:
If you can answer these questions, you’ll be able to assess, prioritise, and address the threats coming your way. The trick is to maximise the effectiveness of your defences, balancing costs against risks to find the “sweet spot” that is justifiable before stakeholders.
Let’s talk about what is likely the most overlooked area of cyber-risk. Exploitable computer vulnerabilities are essentially “mistakes in programming” or “Oops” — and with the massive shift to a remote or hybrid workforce and the massive changes to the computing ecosystem which made that shift possible, the number of “mistakes in programming” is at a record high and still increasing.
Yes indeed, “Oops” keeps happening over and over again. Did you know that the infamous Conti Ransomware leverages numerous different vulnerabilities? The question is, what will we do about it?
Consider this astonishing stat: nearly 60% of organisations surveyed said they suffered at least one recent data breach because a patch available for a known vulnerability wasn’t applied. In related news, only 9% of security and IT leaders rate themselves as “effective at vulnerability remediation.” — and one-third of all detected vulnerabilities remain unremediated after a year.
Clearly, an area of focus for security and IT teams is to develop a system to make threat intelligence actionable — and then make sure to take action.
Automation is critically important in addressing these procedural deficits. No one alive could track the tsunami of threat intelligence crashing down on us day after day — but there are ways to address more of those threats without direct attention or effort.
Automating threat intelligence analysis and action — leveraging the right framework, tools, and procedures — can transform your security practice by:
In short, automation can transform your cyber-security capabilities — enabling immediate action and vastly increasing the range and volume of threats you can address, all with minimal attention and effort on the part of your team.
Treating cyber-security as a business problem — leveraging automation and integrating security with business IT processes — empowers you to address cyber-threats rationally and manage cyber-risk pragmatically.
By combining the power of automation with reliable threat intelligence, security best practices, and a prioritised and efficient approach, you can answer and act on those three key questions quickly and efficiently — keeping cost and effort to a minimum and protecting your organisation at scale.
Robert Leong is a cyber-security expert at HCLSoftware’s Big Fix
Main image courtesy of iStockPhoto.com
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543