Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - The Brain Of Security
Articles

The Brain Of Security

Miles TappinBy Miles TappinDecember 18, 2020Updated:February 20, 20234 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Great decision making requires the ability to review different options while simultaneously considering the risks associated.   

As humans, think about the risk calculations we make every day: when driving a car, walking across the road, or even deciding on whether to get out of bed in the morning. There is a risk of missing an important business opportunity by blowing off that early meeting if you decide to sleep through your alarm. Without us even consciously trying, the brain is instinctively weighing the impact of each decision we make. 

Risk is a term that is used a lot in cybersecurity. However, most organisations aren’t using risk in any meaningful way in their understanding of how much risk the organisation is exposed to, how much risk they are willing to accept, or how much risk they are minimising with their security programme? What if they changed something – then how much risk would they have? Can we honestly say that these are questions that organisations have the answers to – or that have been driving their decision making in security these past decades? 

Aligning security to your business 

In fairness security analysts are seeking to make risk-informed decisions, as the human brain does this instinctively. However, they can only do that based on the information they are provided. There are not many security programmes where business context was provided to the analyst to aid in decision making. 

Recognising this reality, organisations are seeking to quantify their cyber risk to better align security to the business, drive remediation and response activities, support investment decisions and demonstrate return on security investment. Many have already embraced the move to a quantified understanding of risk – only to be let down as current approaches require too much manual data collection, too much training and professional services support, don’t connect this newfound understanding with the ability to take action and fail to meet the need to efficiently and cost-effectively mitigate risk. 

The move to Cyber Risk Quantification  

Organisations need to acknowledge that understanding and quantifying risk is critical to building an effective security programme in this day and age. Solely orchestrating and automating security actions with an intelligence-led approach is not enough. As the Cyber Risk Quantification movement has taken off over the last few years, evolving approaches to security need to be considered to aid organisations in the long term. More has to be done to change the way security works. 

In a holistic sense, the marriage of risk, threat and response is the only way to achieve the primary goal of cybersecurity – reducing risk to the organisation. Therefore, it’s a no brainer that organisations should start to rely on cyber risk mathematical models and rules engine to quantify cyber risk. 

Cyber risk quantification is the process of evaluating the cyber risks that have been identified and then validating, measuring and analysing the available data using mathematical modelling techniques to represent the organisation’s security posture. 

Adopting this new model will give organisations the ability to prioritise response activities based upon their efficacy in reducing the risk of financial loss or operational impact, allow them to more confidently apply security dollars for the greatest return on investment by seeing the risk you buy down and will ultimately make it easier for organisations to justify  spending decisions by talking in terms that CISOs and Boards will understand. 

By adopting cyber risk quantification, organisations will be able to understand which solutions might be the most effective at reducing the chance of certain threats or attacks succeeding against high-value assets, targets, lines of business or missions, based on their value to the organisation. This is key as organisations don’t want to spend a substantial amount of money trying to mitigate risks of attacks that don’t cause as much harm as others may. 

Using a risk-led approach to cybersecurity makes prioritisation easy for security teams, enabling them to focus on what matters most. By adopting cyber risk quantification coupled with threat intelligence and security orchestration, automation and response, the security team’s actions around the most critical risks will be unified and streamlined, which can ultimately strengthen the entire security ecosystem.  

Miles Tappin

VP of EMEA

  • Miles Tappin
    Post-Pandemic Critical Infrastructure – What’s Next?
  • Miles Tappin
    A Spotlight On Critical Infrastructure: A Long Overdue Conversation About Risk
  • Miles Tappin
    Cyber Security is in Denial, That’s Why it Needs the Lean Six Sigma Approach
  • Miles Tappin
    5 Reasons CISOs Need Security Operations, Automation, And Orchestration (SOAR)

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}