Basics Before Tools in Cyber Defense
A longtime CISO argues that asset visibility, identity management, and recovery planning matter more than the newest security products.
A security leader who has run programs at Hyatt and United Airlines has a message that runs against the grain of the vendor-driven security conversation: the newest tools are not the answer. In a first-person analysis, the author describes watching cybercriminals grow more creative and watching security teams respond by reaching for novel technology instead of locking down the controls that actually determine whether an attacker succeeds.
The argument is that foundational controls are what move the needle, and that emerging capabilities such as AI deliver value only when built on a solid base of security basics. The piece lays out five areas the author considers worth the investment, each drawn from experience managing risk inside large enterprises.
Visibility Starts With Knowing What You Own
The first problem the author identifies is a lack of visibility. If an organization does not know where an asset sits in its environment, it cannot protect that asset. If it does not know the asset exists at all, the situation is worse. Modern businesses are expected to secure on-premises servers, cloud and multicloud environments, individual devices and endpoints, third-party applications, and a long list of other potential targets.
Without an up-to-date inventory that is actively maintained across all of those systems, the author writes, a business is carrying unnecessary risk. Comprehensive discovery across every digital environment is described as the critical first step.
The advice comes with a practical account of how hard that is at scale. Working inside larger enterprises, the author found physical and digital asset inventories scattered across the organization. The biggest wins came from two moves: identifying which platform should serve as the single source of truth, and then integrating the scattered data points, ensuring the data is accurate, and updating it as things change.
Identity Management Still Gets Overlooked
Security leaders have repeated the phrase “identity is the new perimeter” for close to a decade, according to the author, yet identity management remains overlooked or taken for granted. The scale of the problem has grown: the average organization now manages tens, if not hundreds, of thousands of human identities, machine identities, applications, AI agents, and other identity types.
The author points to time spent at Hyatt as an illustration, describing the difficulty of managing a constant churn of visitor identities alongside full-time staff, part-time workers, and contractors. At that volume, manual management is impossible, which makes an effective identity platform essential.
The recommended starting point is the most basic layer. Multifactor authentication has been known for decades to significantly reduce the likelihood that an identity will be compromised. The author is direct that MFA isn’t a magic bullet and will not solve every problem, but cites research showing that accounts with MFA are 99% less likely to be hacked.
From there, the author would go a step further by implementing passkeys, describing them as even more effective and noting that they also remove the friction of remembering and entering passwords. The author frames this as a win-win, since many security enhancements introduce unwanted friction and this one does the opposite.
Right-Sizing Security to the Business
Organizations get caught up chasing the latest and greatest security technology, the author writes, when the more useful exercise is determining what the business actually needs. That begins with understanding risk appetite.
The author suggests asking which products or services represent the crown jewels of the organization and what data it cannot afford to lose access to. Protecting those areas from disruption should be the top priority and should absorb most of the attention. From there, teams can move down the ladder, assigning priority tiers to specific risks and deciding which are acceptable and which are not.
Size does not change the requirement. The author argues that any organization, large or small, needs a common security framework that can be understood and digested at every level. That framework gives the organization a clear picture of how well its security program is performing. The suggested entry point is to start small with a widely used framework such as CIS CSC and use it to open the conversation, then strengthen the foundation by identifying what is working and what is not.
The underlying point is that every organization takes risks based on its business appetite; the goal is to have the data needed to make informed decisions about what to prioritize.
Resilience and Recovery Move Up the List
Security and risk management historically leaned heavily on prevention. The author argues that is no longer sufficient. Given the complex and sprawling nature of the modern digital landscape, a determined attacker with enough time and resources will find a vulnerability to exploit.
That does not mean abandoning prevention, which the author still calls worthwhile as a way to make the attacker’s life as hard as possible. It means resilience and recovery have to be prioritized alongside it.
The starting point is having the right systems and processes to react to a breach. The faster a breach in progress can be identified, the faster it can be shut down. If a serious breach does occur, the organization needs a recovery plan. Secure backups for both systems and data are a must, but the author is explicit that technology alone is not enough. The processes have to exist, and they have to be practiced. Too many organizations skip that step, the author writes, leaving employees unsure what to do in a crisis.
A Common Language for Risk
The final area is described as possibly the most important. The biggest obstacle to more effective risk management is often poor communication between the security side and the business side of an organization. Business leaders frequently lack the technical expertise to parse the details of specific security risks, while risk management professionals are not always fluent in the language of business.
Bridging that gap calls for quantifying risk in a meaningful way, assigning a dollar value wherever possible. The author acknowledges the difficulty of estimating the cost of a breach or incident that did not happen, but points to defensible metrics that can assign value to risks based on projected lost business, regulatory penalties, reputational damage, and other factors.
The Un-Sexy Work That Actually Reduces Risk
The author ties the five areas together with a caution about AI. Rapid adoption of the technology is unlocking potential across industries, but even the most cutting-edge tool cannot solve every problem on its own. Meaningful cyber risk reduction, the author argues, comes from building a strong foundation of security fundamentals: doing the unglamorous work of closing visibility gaps, prioritizing resilience, and improving communication between departments.
The closing note from a longtime CISO is that security is not always exciting and, in the author’s view, should not be. The most effective action available is to focus effort on the everyday vulnerabilities that real-world attackers commonly exploit. That framing is consistent with the earlier point that AI investments pay off only when they sit on a rock-solid foundation of security basics, and that budget is better spent strengthening baseline capabilities than cycling through expensive new tools every quarter.
- 99% — the cited reduction in the likelihood of an account being hacked when MFA is enabled.
- Tens (if not hundreds) of thousands — the number of human identities, machine identities, applications, AI agents, and other identity types the average organization now manages.
- Almost a decade — how long security leaders have been saying “identity is the new perimeter,” according to the author.
What This Means for Security Teams
For security leaders, the piece reads as a case for spending discipline and prioritization. The author’s argument suggests that budgets directed at new tool categories may deliver less risk reduction than the same money put toward asset discovery, identity management, and tested recovery processes. That is an uncomfortable position for teams under pressure to show they are adopting the latest technology, but the author’s experience at large enterprises is offered as evidence that the baseline controls are where the measurable impact lives.
The identity discussion also carries a practical implication for workforce planning. If an organization manages tens of thousands of identities across human, machine, and AI agent categories, manual processes cannot keep up, and the case for an identity platform becomes a question of operational necessity rather than preference. Passkeys are presented as the direction of travel beyond MFA, with the added benefit of reducing user friction rather than adding to it.
The resilience argument implies a shift in how teams should think about their own success metrics. If a determined attacker will eventually find a way in, then prevention alone cannot be the only measure of a program’s health. Recovery planning, secure backups, and practiced response procedures become part of the baseline, not an afterthought once a breach has occurred.
Perhaps the most consequential suggestion is the call to quantify risk in dollars. Translating technical exposure into projected lost business, regulatory penalties, and reputational damage gives business leaders a basis for decisions they can defend, and it gives security teams a vocabulary that travels across the organization. The author’s framing suggests that the communication gap, more than any missing product, may be the constraint that keeps risk management from improving.
None of this is presented as a claim that new technology has no place. The author’s position is narrower and more practical: tools, including AI, operate on top of whatever foundation exists, and the foundation determines how much value they can deliver. That is a reminder that the most consequential security decisions may be the least glamorous ones.
Sources
- CSO Online Original source
- 99% less likely Also reporting
- lack of visibility Also reporting
- MFA isn’t a magic bullet Also reporting
- implementing passkeys Also reporting
- even more effective Also reporting
Continue Reading
SecurityNewWhat Microsoft's AI Patch Wave Means
Microsoft patched 18 vulnerabilities across Azure and Copilot products, all rated critical, with fixes applied server-side so customers need not act.
Check Point's Fifth Critical Flaw Since July
A new 9.8-severity stack overflow lets unauthenticated attackers hit Security Management Servers as root, and it's not the first this summer.
Docker Fixes macOS Sandbox Escape Flaws
Two Docker Sandboxes vulnerabilities let malicious guest code read or modify macOS host files, with fixes shipped in version 0.42.0.