Rethinking Cybersecurity: Prioritizing Fundamentals for Effective Risk Management

Sep 18, 2026 921 views

Cybersecurity risk management has reached unprecedented levels of complexity, as cybercriminals continuously adapt and refine their tactics. Over the years, my experience in leading security initiatives at major enterprises like Hyatt and United Airlines has taught me that the real challenge lies not in constantly updating technology but in mastering foundational security controls that genuinely influence outcomes.

While adopting new technologies may seem attractive, the reality is that many organizations miss the mark by neglecting essential security practices. For instance, integrating AI into security protocols is beneficial, yet it doesn’t yield desired results unless there's a solid foundation of security fundamentals in place. Instead of pouring resources into the latest tools with little long-term impact, organizations should focus on enhancing core security capabilities that demonstrably reduce risks and improve defenses against cyber threats.

1. Enhance Visibility Through Effective Asset Discovery

A significant challenge for modern businesses is the lack of visibility across their digital environments. Without knowing the location and existence of assets, protecting them becomes nearly impossible.Organizations today must secure a plethora of environments, including on-premises servers, cloud services, devices, third-party applications, and more. A current, comprehensive inventory of these assets is non-negotiable for reducing exposure to threats.

By implementing thorough asset discovery processes, enterprises can create and maintain an active inventory of their digital and physical assets, effectively minimizing risk. My experience emphasizes the significance of unifying disparate data points into a single, reliable source. Identifying the right platform to act as a central repository and ensuring data accuracy through regular updates is crucial for sound asset management.

2. Improve Identity Management Practices

For nearly a decade, cybersecurity experts have been echoing the sentiment that “identity is the new perimeter.” Yet, identity management remains insufficiently addressed in many organizations. With the increasing number of identities—human, machine, application, and AI—the scope of management has become unwieldy.

During my tenure at Hyatt, the overwhelming nature of managing numerous visitor and staff identities became starkly apparent. Manual identity administration simply isn’t feasible at scale; thus, an effective identity management platform becomes essential. Basic security measures like multifactor authentication (MFA) should be the first line of defense; statistics show that MFA can reduce the risk of identity compromise dramatically. Furthermore, transitioning to passkeys presents a more streamlined solution that enhances security while reducing friction.

3. Tailor Your Security Strategy

Organizations frequently find themselves enamored with the latest security technologies, lost in chasing trends rather than focusing on actual needs. Establishing a clear understanding of the organization’s risk appetite should drive security strategies. What elements represent the most critical assets, and what data is indispensable for operations? Prioritizing protections based on these factors is paramount.

No matter the size of an organization, creating an accessible security framework that resonates with all levels of personnel is vital. Initiating discussions with user-friendly frameworks such as CIS Controls can kickstart efforts to reassess and build upon existing security measures. Data collection and analysis are essential for informed decision-making about which risks to prioritize.

4. Focus on Resilience and Recovery

Today's cybersecurity landscape demonstrates that preventing every attack is nearly impossible. Consequently, organizations must balance their focus with an emphasis on resilience and recovery. An impactful response to a breach begins with prompt detection, enabling quick mitigation of threats.

Establishing a comprehensive recovery strategy, inclusive of secure data backups and system restoration protocols, is critical. However, technology alone cannot guarantee recovery; organizations must develop and rehearse these processes rigorously. Many neglect this vital component, leaving their teams uncertain about how to respond effectively in a crisis.

5. Foster a Common Security Language

While it may seem abstract, creating a shared language around security between business and technical teams is perhaps the most essential step toward effective risk management. Miscommunication often stalls progress, with security experts and business leaders failing to relate to one another's terminology and concerns.

For security teams, articulating risks in business-relevant terms is crucial. Assigning dollar values to potential impacts creates a context that business leaders can easily grasp. Although demystifying the cost of risks can be challenging, employing defensible metrics to forecast losses associated with breaches or penalties can bridge communication gaps effectively.

Building a Strong Foundation of Security Fundamentals

The surge in AI adoption presents notable opportunities across industries; however, remarkable technology cannot independently address all challenges. To meaningfully reduce cyber risks, organizations must solidify their security practices by honing in on foundational tasks. This requires investing time in identifying and closing visibility gaps, maximizing resilience, and improving interdepartmental communication.

From the perspective of a seasoned CISO, security's inherent nature should not focus on the thrilling or trendy aspects but rather on the often mundane yet critical daily actions needed to thwart real-world attacks. Fostering an environment where security fundamentals are prioritized lays the groundwork for a more secure digital future.

Source: Thomas Martinez · www.csoonline.com

Comments

Sign in to comment.
No comments yet. Be the first to comment.

Related Articles

Strong fundamentals make next-gen security possible