{"id":9529,"date":"2026-09-18T08:25:00","date_gmt":"2026-09-18T08:25:00","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9529"},"modified":"2026-09-18T08:25:00","modified_gmt":"2026-09-18T08:25:00","slug":"strong-fundamentals-make-next-gen-security-possible","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9529","title":{"rendered":"Strong fundamentals make next-gen security possible"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Risk management has always been a difficult job, but the current threat landscape has taken the challenge to a new level. I\u2019ve spent years leading cybersecurity efforts at large enterprises, including Hyatt and United Airlines, and in that time I\u2019ve seen cybercriminals grow increasingly creative, leveraging innovative tactics and technology to further their efforts. I\u2019ve also seen security professionals make the mistake of assuming that responding to those new and emerging tactics requires shiny new tech tools. In reality, mastering foundational controls is what moves the needle.<\/p>\n<p class=\"wp-block-paragraph\">New tools are exciting and innovative, so it\u2019s easy to understand the draw. But they\u2019re often less impactful than simply focusing on strong fundamentals. Embracing AI, for example, can provide real value for organizations, but it is <a href=\"https:\/\/www.csoonline.com\/article\/4204101\/ai-is-making-cybersecurity-fundamentals-more-important-than-ever.html\">only effective when built upon a rock-solid foundation<\/a> of security basics. Don\u2019t spend your budget cycling through expensive new security tools each quarter. Get real bang for your buck by strengthening the baseline security capabilities that have a real, measurable impact on attacker success.<\/p>\n<p class=\"wp-block-paragraph\">Here are five areas that fit the bill.<\/p>\n<h2 class=\"wp-block-heading\">1. Gain visibility with better asset discovery and management<\/h2>\n<p class=\"wp-block-paragraph\">One of the most troubling issues plaguing modern businesses is a <a href=\"https:\/\/www.csoonline.com\/article\/4157486\/cisos-tackle-the-ai-visibility-gap.html\">lack of visibility<\/a>. If you don\u2019t know where an asset is located within your digital environment, you won\u2019t be able to protect it. If you don\u2019t know an asset exists in the first place, it\u2019s an even bigger problem.<\/p>\n<p class=\"wp-block-paragraph\">Today\u2019s businesses need to secure on-premises servers, cloud (and multicloud) environments, individual devices and endpoints, third-party applications, and countless other potential targets. If you don\u2019t have an up-to-date, actively maintained inventory of every asset present within those systems, you\u2019re putting your business at unnecessary risk.<\/p>\n<p class=\"wp-block-paragraph\">That means engaging in a comprehensive discovery process that encompasses all your digital environments is a critical first step toward greater security. Working within larger enterprises gave me a greater appreciation for the importance of asset management. Inventory of physical and digital assets often are scattered across the organization. One of my biggest wins is bringing that all together by (1) identifying what platform should be the single source of truth and (2) integrating these data points, ensuring the data is accurate, and updating accordingly.<\/p>\n<h2 class=\"wp-block-heading\">2. Manage your identities more effectively<\/h2>\n<p class=\"wp-block-paragraph\">Security leaders have been saying \u201cidentity is the new perimeter\u201d for almost a decade, but identity management is still overlooked or taken for granted. That\u2019s a real problem, because the average organization now manages tens (if not hundreds) of thousands of human identities, machine identities, applications, AI agents, and countless other identity types.<\/p>\n<p class=\"wp-block-paragraph\">When I worked for Hyatt, I saw firsthand how challenging it could be to manage the endless cycle of visitor identities alongside full-time staff, part-time workers, contractors, and others. Manual management is impossible at this scale, which means an effective identity platform is essential.<\/p>\n<p class=\"wp-block-paragraph\">I have my teams start by ensuring the most basic security measures are in place. For example, we\u2019ve known for decades that multifactor authentication (MFA) significantly decreases the likelihood that an identity will be compromised. <a href=\"https:\/\/www.csoonline.com\/article\/570795\/how-to-hack-2fa.html\">MFA isn\u2019t a magic bullet<\/a> that will solve every problem, but research shows that accounts with MFA are<a href=\"https:\/\/www.cisa.gov\/topics\/cybersecurity-best-practices\/multifactor-authentication\"> <\/a><a href=\"https:\/\/www.cisa.gov\/topics\/cybersecurity-best-practices\/multifactor-authentication\">99% less likely<\/a> to be hacked. Personally, I would go one step further by <a href=\"https:\/\/www.csoonline.com\/article\/4126694\/zero-trust-in-practice-a-deep-technical-dive-into-going-fully-passwordless-in-hybrid-enterprise-environments.html\">implementing passkeys<\/a>, which have proven<a href=\"https:\/\/fidoalliance.org\/fido-alliance-launches-passkey-index-revealing-significant-passkey-uptake-and-business-benefits\/\"> <\/a><a href=\"https:\/\/fidoalliance.org\/fido-alliance-launches-passkey-index-revealing-significant-passkey-uptake-and-business-benefits\/\">even more effective<\/a> and alleviate friction on remembering and entering passwords. It\u2019s a win-win situation, as some security enhancements can create unwanted friction. This is the opposite of that.<\/p>\n<h2 class=\"wp-block-heading\">3. Right-size your approach to security<\/h2>\n<p class=\"wp-block-paragraph\">Too many organizations get caught up in chasing the \u201clatest and greatest\u201d security technology, but it\u2019s important to consider what your business actually needs. That starts with determining your risk appetite.<\/p>\n<p class=\"wp-block-paragraph\">What products or services represent the \u201ccrown jewels\u201d of your organization? What data can you not afford to lose access to? Preventing disruption to those areas should be your top priority, and where most of your attention should be focused. From there, you can move down the ladder, assigning priority tiers to specific risks and determining which are acceptable and which are not.<\/p>\n<p class=\"wp-block-paragraph\">It doesn\u2019t matter how big or small your organization is. It is imperative to create a common security framework that can be understood and digested at all levels in the organization. This will provide your organization a clear picture of how well your security program is doing. Start small and leverage widely used frameworks like <a href=\"https:\/\/www.cisecurity.org\/controls\">CIS CSC<\/a> to initiate the conversation. From there, strengthen your foundation by identifying what is working and what is not.<\/p>\n<p class=\"wp-block-paragraph\">Every organization takes risks based on the business appetite. We just need to have the data to make informed decisions about what to prioritize.<\/p>\n<h2 class=\"wp-block-heading\">4. Prioritize resilience and recovery<\/h2>\n<p class=\"wp-block-paragraph\">Security and risk management used to focus heavily on prevention, but that\u2019s no longer enough in today\u2019s threat environment. The complex, sprawling nature of the modern digital landscape means that, with enough time and resources, a determined attacker will find a vulnerability to exploit. That doesn\u2019t mean security teams should abandon prevention \u2014 it\u2019s always a good idea to make the attacker\u2019s life as hard as possible \u2014 but it <a href=\"https:\/\/www.csoonline.com\/article\/4188186\/cybersecurity-is-no-longer-about-protection-its-about-survival.html\">does mean resilience and recovery must be prioritized<\/a>, too.<\/p>\n<p class=\"wp-block-paragraph\">That starts with having the right systems and processes in place to react to a breach. The quicker you can identify a breach in progress, the quicker you can shut it down. But if the worst does come to pass and your organization suffers a serious breach, it also means <a href=\"https:\/\/www.csoonline.com\/article\/515730\/business-continuity-and-disaster-recovery-planning-the-basics.html\">having a recovery plan<\/a>. Secure backups for both systems and data are a must, but technology alone isn\u2019t enough. You need to have the right processes in place, and you need to <a href=\"https:\/\/www.csoonline.com\/article\/570871\/tabletop-exercises-explained-definition-examples-and-objectives.html\">practice putting them into action<\/a>. Too many organizations overlook this critical step, leaving employees wondering what to do in a crisis.<\/p>\n<h2 class=\"wp-block-heading\">5. Create a common security language<\/h2>\n<p class=\"wp-block-paragraph\">This may sound a bit abstract, but it\u2019s arguably the most important step. Too often, the biggest obstacle preventing organizations from managing risk more effectively is poor communication between those on the security side and those on the business side. Business leaders often lack the technical expertise to understand the details of specific security risks, while risk management professionals aren\u2019t always <a href=\"https:\/\/www.csoonline.com\/article\/3543810\/chief-risk-storyteller-how-cisos-are-developing-yet-another-skill.html\">well versed in the language of business<\/a>. <a href=\"https:\/\/www.csoonline.com\/article\/4080670\/what-does-aligning-security-to-the-business-really-mean.html\">Bridging that communications gap<\/a> is critical.<\/p>\n<p class=\"wp-block-paragraph\">For security and risk management teams, it\u2019s important to be able to <a href=\"https:\/\/www.csoonline.com\/article\/3839272\/what-is-risk-management-quantifying-and-mitigating-uncertainty.html\">quantify risks in a meaningful way<\/a>, assigning a dollar value whenever possible. While it\u2019s admittedly difficult to estimate the cost of a breach or security incident that didn\u2019t happen, there are defensible metrics to assign value to risks based on projected lost business, regulatory penalties, reputational damage, and other factors.<\/p>\n<h2 class=\"wp-block-heading\">Building a strong foundation of security fundamentals<\/h2>\n<p class=\"wp-block-paragraph\">The rapid adoption of AI is unlocking unprecedented potential across every industry, but even the most cutting-edge technology can\u2019t solve every problem on its own. If you really want to reduce your cyber risk in a meaningful way, you need to build a strong foundation of security fundamentals. That means doing the \u201cun-sexy\u201d work in the security trenches, like identifying visibility gaps, prioritizing resilience, and improving interdepartmental communication.<\/p>\n<p class=\"wp-block-paragraph\">Take it from a longtime CISO: Security isn\u2019t always exciting. In fact, it shouldn\u2019t be. The most effective action you can take to reduce your exposure and keep your digital environments secure is to focus your efforts on the everyday vulnerabilities commonly exploited by real-world attackers.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Risk management has always been a difficult job, but the current threat landscape has taken the challenge to a new level. I\u2019ve spent years leading cybersecurity efforts at large enterprises, including Hyatt and United Airlines, and in that time I\u2019ve seen cybercriminals grow increasingly creative, leveraging innovative tactics and technology to further their efforts. I\u2019ve [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9530,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9529","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9529"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9529"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9529\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9530"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9529"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9529"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9529"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}