The board rejected our $50K security budget request. Again. "Show us the business case," they said. So I did something different. Instead of talking about vulnerabilities and patches, I spoke their language. Money. Here's the framework that changed everything: Revenue at Risk: I calculated our average deal size ($25K) and showed how a data breach could kill 6 months of new sales. Suddenly $50K seemed small. Regulatory Reality: I researched actual fines in our industry. $2.8M average for companies our size. The room got quiet. Competitive Edge: I showed how security certifications help close deals 40% faster. Security wasn't just protection anymore. It was sales acceleration. The breakthrough was ranking risks by financial impact, not technical severity. High: Customer data exposure ($2M+ liability) Medium: Internal system downtime ($10K/hour) Low: Non-critical server vulnerabilities ($500 fix) I also included recovery costs they never considered: - Legal fees - Customer notification requirements - Lost productivity during incident response - Reputation management The biggest challenge? Getting executives to think in probabilities, not absolutes. I used simple terms: "This isn't about IF we'll face a cyberattack. Industry data shows companies our size face attempts monthly. This is about WHEN and how prepared we'll be." Result? Full budget approval in two weeks. Plus an additional $25K for proactive measures. Stop speaking tech. Start speaking business impact. Disclaimer: Not every board is the same. Some more technical than others. Choose accordingly. P.S. What resonates more with your board: technical severity ratings or dollar amounts at risk? Share it in a comment below.
Cybersecurity Investment Insights
Explore top LinkedIn content from expert professionals.
-
-
CRR3 and DORA now speak the same language. Cyber incidents must be part of your loss dataset. Here’s what the new EBA RTS means in practice: 1. Every cyber incident = operational risk. If a cyberattack causes disruption, it must be captured — even if systems recover fast. That includes financial loss, reputational damage, and remediation costs. 2. Two new required flags: ↳ ICT risk — cyber: for attacks, exploits, and data compromise ↳ ICT risk — other than cyber: for internal tech failures or outages 3. DORA only mandates reporting major incidents. But CRR3 requires you to record all ICT incidents internally. Your internal register must go beyond what regulators see. 4. Third-party impact? Dual flag it. If a SaaS vendor goes down and you’re hit, flag it as both ICT risk and third-party risk. 5. Cyber losses now count in capital calculations. The RTS makes it clear: cyber events can affect your annual operational loss figure and your regulatory capital buffer. If you're a fintech CTO and your InfoSec and Risk teams aren't speaking the same language yet, you're likely to fail your next audit. 🙊 Want a quick sanity check on your cyber loss reporting setup? Let’s talk.
-
It was a privilege to contribute to the World Economic Forum’s Global Cybersecurity Outlook 2026. While the report highlights a widening gap between the cyber-secure and the cyber-vulnerable, my takeaway is one of optimism. We have the tools to close that gap, but it requires a fundamental shift in mindset. I see how the most forward-thinking organizations are responding. They aren't just buying tools; they are building partnerships. They are operationalizing threat intelligence to move faster than the adversary. Three critical imperatives based on our contributions to this year's findings: 1️⃣ Democratize Resilience: We must look beyond our own four walls. If our supply chain partners and SMEs are vulnerable, so are we. Public-private partnership isn't a buzzword; it's our shield. 2️⃣ Lead with AI, Don't Follow: The report validates what we see at Palo Alto Networks Unit 42: attackers are leveraging AI. We must do the same. Effective defense now requires machine-speed detection and response. 3️⃣ Culture Over Compliance: Resilience is a boardroom discipline. It requires leaders who are willing to ask the hard questions about their true ability to recover from a systemic shock. The organizations that win in 2026 will be the ones that operationalize AI to recover faster and stronger.
-
Cybersecurity leaders are going to have to get good at saying “no” again. Over the years there’s been a lot of talk about cybersecurity saying no too much and impeding the business. The problem is that the counter-behavior of saying yes to everything can be just as bad. Telling stakeholders that you can do something you’re not resourced for—with the right people, processes, and/or technologies—is almost guaranteed to harm all parties involved. One of the takeaways from yesterday’s draft release of the SANS AI Security briefing was “prepare for burnout.” For the past year we’ve seen more and more security roles cut to pad profitability margins. Many are functioning with a fraction of the people needed to be sustainable. And yet some of our top industry experts are sounding the alarm that vulnerabilities and subsequent attacks are going to increase exponentially. I believe it. As a senior advisor to federal agencies who also provides hands-on-keyboard support for incidents, I’m seeing the cases tick up. As a result of this stress and strain on cybersecurity programs, our people are having heart attacks. Our women are being squeezed out by increasingly inflexible policies returning to our workplaces. Talented, experienced people with necessary skills are leaving the industry because they know and do deserve better. If we’re going to be successful in this next era of cybersecurity, CISOs and executives need to start pushing back. They need to negotiate, and identify their non-negotiables. They need to put aside people-pleasing tendencies, avoidance of conflict, and learn how to say no when the circumstances ultimately call for it. If you’re going to do effectively protect the organization from cybercriminals, it starts with protecting your people who do the security work. It starts with making sure the expectations are sustainable, priorities are clear, and boundaries involving capacity and scope are enforced. Before AI, everyone agreed that security can’t defend against everything—and yet many, many organizations still tried. Now with AI, it is literally impossible. CISOs, cybersecurity leaders, and companies must move now to operate by this reality or they are going to become rapidly overwhelmed even more than they likely already are.
-
Yesterday, I read National Cyber Director Sean Cairncross's remarks that the biggest threat to U.S. critical infrastructure right now is the access and leverage China has already built quietly inside the systems that power our daily life. Intelligence agencies have warned about this extensive campaign. Chinese hackers have placed tools that let them monitor and, if needed, disrupt core networks for power, water, and communications. Three things that I would think about as board and leadership: 1: Learn, train on AI to meet the velocity of the adversaries. I believe that disruptions to fundamental infrastructure and services would have severe business consequences, and the only way to realistically keep pace with these threats is by security teams deploying and training on AI-powered security solutions to help meet the scale and volume of today's attacks. AI can surface suspicious signals, automate routine response, and help analysts catch intrusions people miss. Start training your security teams to use AI to meet at eye level with those who would harm the business. 2: Watch supply chains, those already inside your networks. I think boards and CEOs are underestimating how quickly offensive AI tooling can weaponize a single third-party connection, and the idea that suppliers and partners are already a part of their effective network perimeter. Things you could discuss with security leadership focus on third-party and supply chain threats: - How would our systems handle a sustained network outage? - Do partners and vendors know how their networks connect to ours? - How do our vendors handle their own readiness? - Could they isolate attacks if needed? 3: We need policies that keep pace with today's threats. I also appreciate how Cairncross pressed Congress to renew the Cybersecurity Information Sharing Act. The lapse has added to the complexity security leaders face in managing the volume of threats they face every day. More from CyberScoop and Tim Starks: https://lnkd.in/d-fxejBb Would love to hear how others in the community are thinking about these threats.
-
Last year, the average data breach costed MILLIONS. $4.44M, to be exact. The companies getting breached have state of the art compliance tech. Despite that, their compliance is held together with spreadsheets, screenshots, and institutional knowledge. I’m not a CISO, but here’s what I learned from speaking to over 500 of them: ✪ 𝐒𝐢𝐧𝐠𝐥𝐞 𝐩𝐨𝐢𝐧𝐭𝐬 𝐨𝐟 𝐡𝐮𝐦𝐚𝐧 𝐟𝐚𝐢𝐥𝐮𝐫𝐞 A fintech's entire SOC 2 surveillance depended on one engineer's Python script. This was on this laptop, with no documentation in place. When he went on leave, they failed their audit. 𝑭𝒊𝒙: For every compliance process, write down who knows how it works. If only one name appears, that's a critical vulnerability. ✪ 𝐄𝐯𝐢𝐝𝐞𝐧𝐜𝐞 𝐰𝐢𝐭𝐡𝐨𝐮𝐭 𝐯𝐞𝐫𝐬𝐢𝐨𝐧 𝐜𝐨𝐧𝐭𝐫𝐨𝐥 A healthcare company lost their HITRUST renewal because it couldn't prove which encryption policy version was active in Q2. 𝑭𝒊𝒙: Use version control for policies and procedures. Implement centralised compliance repositories with automated version tracking, approval workflows, and access controls. Each document revision must include change logs, approval signatures, and clear identification of superseded versions. ✪ 𝐈𝐧𝐭𝐞𝐠𝐫𝐚𝐭𝐢𝐨𝐧 𝐟𝐚𝐢𝐥𝐮𝐫𝐞𝐬 𝐝𝐮𝐫𝐢𝐧𝐠 𝐚𝐮𝐝𝐢𝐭𝐬 A SaaS company's Jira integration broke 72 hours before their ISO audit. They manually reconstructed 6 months of tickets from Slack screenshots. 𝑭𝒊𝒙: For every critical integration: document the manual fallback process, test it quarterly, and maintain a secondary data export that's no more than 48 hours stale. Automate evidence bundles (logging status, access reviews, policy compliance, backup tests) for rapid audit response. ✪ 𝐑𝐞𝐬𝐩𝐨𝐧𝐬𝐞 𝐭𝐢𝐦𝐞 𝐚𝐬 𝐚 𝐜𝐨𝐦𝐩𝐞𝐭𝐢𝐭𝐢𝐯𝐞 𝐝𝐢𝐬𝐚𝐝𝐯𝐚𝐧𝐭𝐚𝐠𝐞 A cybersecurity vendor took 3 weeks to respond to a 300 question security questionnaire. A questionnaire sitting idle for 3 days can push a deal into the next quarter - $50K to $500K in delayed revenue. They lost a $2M deal to a competitor who responded in 48 hours. 𝑭𝒊𝒙: Track time-to-answer. Traditional GRC metrics focus on activity volume (number of controls tested, issues logged, or assessments completed). Shift this to outcome based metrics. It should NOT take more than 24 hours to answer any questionnaire, even if it has 300 questions. What are some "hard-learned lessons" you would add to this list?
-
𝗚𝗹𝗼𝗯𝗮𝗹 𝗖𝘆𝗯𝗲𝗿𝘀𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗢𝘂𝘁𝗹𝗼𝗼𝗸 𝟮𝟬𝟮𝟲 — 𝗮 𝗰𝗮𝗹𝗹 𝗳𝗼𝗿 𝗿𝗲𝗮𝗹𝗶𝘀𝗺 This snapshot captures what many of us are already experiencing on the ground. Yes, AI is accelerating everything — both defense and offense. But the bigger shift is how uncertainty is compounding across technology, geopolitics, and human behaviour. A few signals that stood out to me: • AI is now a risk amplifier, not just a capability • AI-related vulnerabilities are growing faster than governance models • Cyber-enabled fraud and phishing continue to impact people directly — not just systems • Geopolitics is no longer “context”; it’s an explicit threat driver • Confidence in national preparedness varies sharply by region, which attackers will exploit What I find most telling is the CEO vs CISO gap: • CEOs worry most about fraud, phishing, and business impact • CISOs remain focused on ransomware, supply chain, and vulnerabilities Both are right — but misalignment here slows decision-making when it matters most. 🔑 My takeaway for 2026: Cybersecurity is shifting from a technical problem to a resilience and leadership problem. • Faster tech cycles • More fragmented geopolitics • Higher expectations from boards and regulators • Real human impact when controls fail For critical infrastructure and OT environments, this means moving earlier: • Earlier risk visibility • Earlier executive alignment • Earlier investment in resilience, not just detection What do you see as the single biggest blind spot organizations are carrying into 2026? #Cybersecurity #OTSecurity #CriticalInfrastructure #AIinSecurity #Geopolitics #CISO #CyberResilience
-
The recent cyberattack on X (formerly Twitter) has reignited concerns about the growing weaponization of digital platforms. With over 40,000 users affected and indications of a coordinated Distributed Denial-of-Service (DDoS) attack, this incident raises a critical question: Are social media platforms becoming the new frontlines of cyber warfare, particularly involving nation-state actors? Are Enterprises prepared to handle such attacks? For enterprises, this incident serves as a stark reminder of the vulnerabilities inherent in today’s interconnected digital ecosystem. The implications are profound and multifaceted: ✅ Economic Fallout: Cyberattacks can lead to immediate financial losses through downtime, ransom payments, and operational disruptions. For publicly traded companies, the repercussions can be even more severe—stock prices drop by an average of 7.5% following a breach, with some firms losing billions in market value within days. (HBR article) ✅✅Reputational Damage: Trust is hard-earned but easily lost. A single cyber incident can erode customer confidence and tarnish a brand’s reputation for years. For example, Target’s infamous data breach in 2017 led to a 30% reduction in earnings before interest and taxes. (NBER Working Paper) ✅✅✅Regulatory and Legal Risks: The cost of compliance, legal fees, and potential fines following an attack can cripple even the largest organizations. Companies with poor cybersecurity practices may also face credit rating downgrades, increasing borrowing costs. ✅✅✅✅Operational Disruptions: Beyond financial losses, cyberattacks often paralyze operations. From supply chain breakdowns to compromised customer-facing systems, the ripple effects can disrupt entire ecosystems. Enterprises must move beyond reactive measures to adopt proactive strategies for crisis management- and focus on building resilience should be at the heart of it. Here are four key strategies to help enterprises thrive: 👍 Build Resilience: Embed a culture of preparedness across your organization to withstand disruptions and maintain operational continuity. 👍👍Stress Test Capabilities: Conduct regular stress tests to evaluate your response strategies under pressure. This helps identify vulnerabilities and refine business continuity plans. 👍👍👍Realistic Simulations: Use immersive simulations to mimic real-world crisis like cyberattacks or supply chain disruptions. These exercises enhance decision-making and ensure readiness. 👍👍👍👍Leverage AI: Deploy AI-driven anomaly detection systems to identify and mitigate threats in real time, staying ahead of sophisticated cyberattacks. As cyber threats grow more sophisticated and pervasive, organizations must prioritize resilience to safeguard their operations, reputation, and bottom line. In this era of escalating cyber warfare, preparedness is not optional—it’s essential. #CyberWarfare #EnterpriseResilience #CrisisManagement #CyberSecurity
-
For years, the cybersecurity industry talked about the "Golden Hour"—that window of time to detect an attacker, respond, and stop them before they moved deeper into your environment. That window is fast disappearing. Today, the average breakout time is around 29 minutes. In some cases, it's been measured in seconds. That's why I believe we need to rethink the conversation. Cybersecurity isn't just about preventing a breach anymore. It's about assuming one will eventually happen and asking a different question: How quickly can you contain it? That was the focus of our recent executive roundtable in Kuala Lumpur. It was encouraging to see leaders from banking, aviation, energy, insurance, and other critical industries having honest conversations about resilience rather than just prevention. I've said it many times before: prevention is important, but resilience is what determines the outcome. When the perimeter is breached, your ability to contain the blast radius is what keeps a cyber incident from becoming a business crisis. I'm encouraged by the number of organisations now looking beyond traditional perimeter security and asking what comes next. To me, that's where the industry needs to go.
-
Too often, cybersecurity is seen as something to fix after a breach happens. But this reactive mindset is no longer sustainable. In a digital economy where every process depends on connectivity, cyber risk becomes business risk. This means we need to stop treating cybersecurity as a purely technical task and start recognizing its strategic nature. A cyber-resilient organization does not just deploy protections—it understands how risk impacts operations, finances, and reputation. It aligns cybersecurity with business priorities and embeds it in governance structures. What I find essential is the integration of security thinking into organizational design. When boards include cybersecurity expertise, when teams collaborate across departments, and when leaders understand the economic drivers of cyber threats, resilience becomes part of how the company functions every day, not just during a crisis. Cyber resilience is not about being perfectly secure. It is about being ready, adaptable, and aligned. That shift must begin at the top. #CyberResilience #Leadership #CyberRisk #BusinessContinuity #CyberGovernance