ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Measuring cyber security: from reactive to proactive

Christine Bejerasco at WithSecure describes how to unlock the business value of outcome-based infosec

 

With security threats continually evolving, it’s easy to be stuck in a vicious cycle of daily firefighting. This is still the case for most organisations – research carried out by Forrester and commissioned by WithSecure found that 60% of businesses respond to threats individually on a reactive basis.

 

But whilst this approach may be commonplace, it’s increasingly evident that it’s not enough to deliver reliable security. It leaves organisations perpetually vulnerable, jumping from one incident to the next, never finding time to think about long term business growth and innovation.

 

The last few years have seen a significant shift in how security is perceived by business leaders, from a defensive mechanism to a strategic enabler that touches every facet of a business. Whether organisations are rolling out new services, enhancing customer experiences, or empowering a more productive workforce, cyber-security is the bedrock upon which modern business units are built.

 

More organisations are now realising this truth. Indeed, 75% of respondents to Forrester’s research stated that their business directors recognised security as a priority.

 

Bringing out the full potential of cyber-security as a business enabler requires a more proactive, outcome-based security model that aligns closely with broader business objectives and delivers tangible value.

 

A business-centric approach to cyber-security

Cyber-security has traditionally been a siloed operation, with teams often feeling quite isolated from the business’ other functions. But as the level of cyber-risk continues to grow, this approach has become increasingly untenable. Difficult economic times mean there is a greater emphasis on ROI for all investments and companies are no longer comfortable simply allocating separate budgets for security. 

 

Instead, security needs to be fully aligned with business goals, and to move beyond just threat mitigation and increase focus on driving key business objectives. This requires a shift to an outcome-based mindset, defined by Forrester as an approach that focuses on producing planned and measurable results rather than simply reacting to whatever threats rear their heads.

 

So, what key business outcomes should be in sync with cyber-security strategies? Our research indicates that more than 40% of decision-makers prioritise reduced risk and enhanced customer or partner experience as top cyber-security goals. Revenue growth, improved governance, and operational resilience were other key objectives.

 

Though many businesses are only beginning to realise it, security has always played an essential role in these core business objectives. Let’s consider customer experience, a cornerstone for any business. Cyber-security is not just about protecting data; it’s an integral part of the customer journey. A breach not only erodes trust but can also result in client attrition.

 

Conversely, a seamless customer experience, facilitated by quick authentication and optimised mobile and web interactions, can significantly boost customer engagement and, by extension, revenue.

 

This shift in perspective establishes what we could term a "golden thread"—a continuous link that weaves cyber-security into the very fabric of business operations. It’s not just about averting risks; it’s about enabling opportunities. Cyber-security, therefore, evolves into a proactive strategy to achieve business goals.

 

Adopting outcome-based security

Achieving this perfect interweaving of security and business goals won’t happen overnight. Forrester found that most IT and security decision makers recognise the need for this shift but face challenges ranging from gaining visibility into cyber-risks to marshalling the right skills and resources for effective response.

 

Notably, 40% of respondents cited the complexity of the IT environment as a significant barrier to aligning cyber-security with business outcomes. The ever-expanding digital attack surface exacerbates this complexity. When IT growth has far outstripped security capabilities, even routine cyber-security activities can be challenging. 

 

So, how can organisations surmount these obstacles? Getting there requires a combination of advanced technology and good old-fashioned communication. 

 

On the technical side, comprehensive visibility across the IT landscape is essential, identifying risks and correlating security activity with creating business value. Advanced tools with real-time monitoring capabilities can offer invaluable insights into the network, making it easier to map out these connections and enabling the early detection and mitigation of threats.

 

Moreover, the advent of machine learning and artificial intelligence in cyber-security solutions provides a promising avenue for predictive threat analysis. These technologies enable organisations to anticipate potential threats and respond more effectively, a concern cited by 34% of survey respondents as a key challenge.

 

Moving towards a more structured approach to security and achieving better visibility will often reveal gaps in the current security stack. Firms should also undertake a structured audit of their security capabilities and put those side by side with the assets they have and the threats those are facing.

 

Technologies that don’t contribute to achieving the desired outcomes should be phased out and those resources be redirected towards more efficient solutions that will help meet business goals. Monitoring mechanisms should also be established to confirm that efforts yield the desired security outcomes. 

 

Lastly, a robust incident response plan is non-negotiable. This should outline roles, responsibilities, and procedures for managing cyber-security incidents and be regularly reviewed and updated to ensure its continued efficacy.

 

Aligning stakeholders and refining the security approach

Having the right tools for the job is only half the answer - the shift also requires a strong focus on collaboration. A successful transition to outcome-based security starts with stakeholder consensus.

 

When CISOs sit at the executive table, they are able to fully understand the business’ goals and needs. While it’s understandable that many organisations don’t yet feel the need, they should consider elevating their top cyber-security role to emphasise that cyber-security goes beyond just IT and R&D. It also means security in Finance, HR, Sales, Marketing, and other functions. On this level, CISOs would then need to step up and likewise be able to communicate the technical side of things in a relatable way.

 

It’s crucial to shift the narrative from merely stating, "This security measure is superior," to articulating the specific benefits of each security investment to other business objectives. For example, employing risk-based authentication in e-commerce bolsters security and streamlines low-risk transactions, enhancing customer experience.

 

Furthermore, cross-departmental collaboration is indispensable. Security doesn’t operate in isolation; it’s a function that de-risks and supports broader business objectives. Regular interactions with stakeholders beyond the IT and security teams can offer invaluable insights for aligning cyber-security strategies with business outcomes.

 

Legal and procurement teams play particularly pivotal roles in this transition. Contracts for outcome-based security will differ from traditional ones, as vendors commit to delivering specific security outcomes. Early coordination with these departments can pre-empt last-minute roadblocks and ensure a smoother implementation process.

 

The shift to an outcome-based security model is not just a technological transition but a cultural one. It requires a holistic approach that involves stakeholders across the organisation, from the boardroom to the server room.

 

By embracing this model, businesses can fortify their defences and unlock new avenues for growth and competitiveness, making cyber-security a strategic asset rather than a necessary burden.

 


 

Christine Bejerasco is the Chief Information Security Officer at WithSecure

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543