That's right, businesses should have security controls in place commensurate with the size and extent of its threats and vulnerabilities. It is not pragmatic for most organisations to spend enough money to implement the most protective security possible. Traditionally we call this determining your risk appetite.
Overall, my experience from auditing the cyber security of many organisations is that they're not actually taking a risk based approach. They're not identifying their IT & Cyber Security risks and they're not identifying their specific threats and vulnerabilities. This leads to many organisations make poor security decisions by implementing technology controls that either aren't mitigating any of their risks or isn't reducing their residual risk to a comfortable level.
Comments
That's right, businesses should have security controls in place commensurate with the size and extent of its threats and vulnerabilities. It is not pragmatic for most organisations to spend enough money to implement the most protective security possible. Traditionally we call this determining your risk appetite.
Overall, my experience from auditing the cyber security of many organisations is that they're not actually taking a risk based approach. They're not identifying their IT & Cyber Security risks and they're not identifying their specific threats and vulnerabilities. This leads to many organisations make poor security decisions by implementing technology controls that either aren't mitigating any of their risks or isn't reducing their residual risk to a comfortable level.