On 18 April, teissTalk host Tom Langford was joined by Alan Jenkins, Principal Consultant, Cyber Security Navigator Ltd; Garrett Smiley, Adjunct Dissertation Chair / Distinguished Core Part-Time Professor, National University; and Dom Lucas, Head of Security, British International Investment.
Views on news
A substantial 93% of enterprises admitting to a breach have suffered significant consequences, ranging from unplanned downtime to data exposure or financial loss. Pentera’s latest report, meanwhile, also highlights significant gaps in security testing frequency compared to the pace of changes in the IT environment. While 73% of enterprises undergo IT changes at least quarterly, only 40% conduct pen testing with similar regularity. Figures quoted in news on breaches usually don’t include the amount of human effort invested in incident response and recovery. There are the mandatory procedures that you need to follow when your company is breached, but, In the US, informing your customers must be done state by state. Also, there is no GDPR, so legal experts must play a much bigger role in the incident response.
How to change the perception of infosec
Information security is about mitigating risks and managing it when an incident happens. The approach to data privacy is rather different in the EU and the US. However, penalties are converging. Semantics do matter for business leaders, so it’s better to frame risks in the context of what the business is going to gain if it implements controls, rather than saying “this is what you have to lose if you don’t.” If you talk to them about downsides, they tend to shut down.
Companies in the UK are now mandated to include their data security posture in their annual reports, which makes it easier for cyber security experts to argue that security controls can raise a business’s share price. If your business is on a competitive market and your competitors invest in their cyber security, it’ll be easier for your infosec professionals to get cyber security deployments sponsored. The cost of implementing cyber security controls depends on the business level – existing spend, whether the business is regulated or unregulated or is a critical infrastructure business. What’s challenging for businesses assessing their suppliers is asking the right questions – and that’s where CIS 18 comes in handy, also because it’s community developed and less slanted towards the service provider or the vendor.
However, the utmost challenge still is to get the business own the risk. But nowadays, when an incident happens, the question of due diligence comes up increasingly.
The panel’s advice
To read about the 18 CIS security controls, click here.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543