The emergence of AI as a threat actor and the growing list of vulnerabilities and risks is rattling boardrooms globally.
But Caesar Tonkin, MD of Armata Cyber Security, believes it’s not time to panic – it’s time to structure.
The statistics and numbers associated with global cybersecurity spending are in the high billions, varying depending on the survey data and location. The cost of a breach is equally high, with South African companies looking at an average of R44,1-million.
Then there’s the changing nature of risk as AI becomes as much a threat actor as a vulnerability and challenges companies to find new ways of protecting their assets and people. Companies are spending more and more on proactive measures such as identity management, incident response, recovery and protection, but the gap between what they are protecting and what they are spending continues to widen. More money is going out, more breaches are coming in – something in the equation is broken.
The crack in the security façade is the decision-making process behind it. Whenever the threat landscape changes – a major incident, a new vulnerability, a technology that reinvents the rules – the market’s default response is to move fast with new solutions and policies. Boards demand immediate action, and security teams are under pressure to see that they are doing something tangible and measurable to protect against the threat. And everyone is an ambulance chasing the next security fix.
The result is that procurement is driven by alarm rather than by measured and steady assessment of a company’s security posture and so they end up owning a collection of tools that overlap or potentially contradict one another while leaving the actual gaps untouched. Panic-buying security tends to address the threat that made the news rather than the exposure risks that exist within the environment. And the shouts of panic are doing very little to change the organisation’s security posture.
A more calculated security stance bypasses the panic entirely and instead starts at a single point – risk analysis. What systems haven’t been patched in five years? What legacy vulnerabilities have been deprioritised because they weren’t as much a concern? What has been left unchecked because nothing bad happened? It’s these systems that sit in the dark corners of the business, unpatched because they aren’t a priority, that present the real risk to your company’s security posture. The threat landscape has evolved so much over the past few years that systems considered a low priority last year may have become your most exploitable entry point in your environment today.
Risk assessments are systemic, unglamorous and painstaking. They dig in the depths of the business to find every last potential entry point and problematic system. They should also be focused on identities and access – determining what credentials have access and which identities may have been compromised. These are the basics that tend to get deprioritised when you’re responding to the last crisis instead of auditing your current security state.
The relationship between the CIO and the CISO is critical. The CIO sleeps well at night because the CISO is structured, calculated and doesn’t panic the organisation. It’s a leadership posture that converts threat intelligence into structured action rather than reactive spend. If the CISO can walk into the boardroom with a risk analysis, a 30-day remediation plan and a 90-day defensive roadmap, they are doing something fundamentally different. It is more important for the business to undertake a security journey instead of investing in additional security solutions because then each step is one taken towards a comprehensive risk-averse security posture built on proactive rather than reactive measures.
For the most exposed organisations, those with sensitive environments, legacy infrastructure or limited visibility into architecture, the endpoint of this roadmap is an air-gapped zero-trust architecture. It is entirely possible to achieve this, especially if security is seen as a starting point. Assess your systems, understand what is potentially exploitable, and close the gaps meticulously with an integrated security approach that leverages the technology you already have in place. Risk-ready doesn’t mean panic, it means the right tools in the right place at the right time. Not when dictated by a headline.