AI & ML

Mastering Cybersecurity: Why Strong Fundamentals Triumph Over New Tools

Effective cybersecurity relies on foundational measures over flashy tools; enhancing visibility, resilience, and communication is essential.

Sep 18, 2026 3 min read
Sign in to save

Risk management has evolved into an increasingly complex task due to the sophistication of modern cyber threats. Drawing from years of experience in cybersecurity leadership roles at prominent companies such as Hyatt and United Airlines, I’ve seen firsthand how cybercriminals continuously innovate their tactics to exploit vulnerabilities. Security professionals often make the mistake of believing that the latest technologies are the key to staying ahead, while in reality, focusing on fundamental security principles yields more substantial improvements.

While new tools can be enticing, the heart of effective cybersecurity lies in bolstering core security practices. For instance, artificial intelligence can enhance security measures, but its effectiveness hinges on a strong foundation of established security protocols. Organizations should resist the temptation to spend excessively on the latest security gadgets and instead prioritize enhancing their basic security capabilities that have a verified impact on thwarting attackers.

1. Enhance Visibility Through Asset Discovery and Management

A significant challenge for businesses today is the lack of visibility into their digital assets. Without knowing where each asset is, safeguarding it becomes nearly impossible. It’s essential to maintain a comprehensive and up-to-date inventory of all components within your digital ecosystem, encompassing on-premises servers, cloud environments, endpoints, and third-party applications.

Engaging in a thorough asset discovery process is crucial. During my tenure in large enterprises, I observed how fragmented asset inventories could pose risks. One of my key achievements was consolidating these records by identifying a reliable platform for asset management and ensuring data accuracy through integration and consistent updates.

2. Streamline Identity Management

“Identity is the new perimeter” is a phrase that has circulated for nearly a decade, yet many organizations still overlook it. Today's enterprises manage vast numbers of identities, including human users, machinery, applications, and AI entities. The challenge of keeping track of this multitude of identities can be overwhelming, making an efficient identity management system crucial.

During my time at Hyatt, I witnessed the difficulties in managing visitor identities alongside permanent employees and contractors. Given the scale, manual management was impractical, emphasizing the necessity of an effective identity platform. Implementing foundational measures, such as multifactor authentication (MFA), significantly reduces compromise risks, with accounts featuring MFA being dramatically less likely to be hacked. As a forward-thinking step, I recommend adopting passkeys, which prove even more effective while simplifying user experience.

3. Tailor Your Security Approach

A prevalent issue in security management is the fixation on continuously seeking the latest technologies without assessing actual business needs. Organizations must start with a clear understanding of their risk appetite. Identifying which assets are crucial to the business and focusing security efforts there should be paramount. This prioritization helps in developing a tiered risk management strategy.

No matter the organization's size, establishing a common security framework that everyone in the business can grasp is vital. This clarity enables a comprehensive view of the security program's effectiveness. Starting with widely accepted frameworks, like the CIS Controls, can lead to productive discussions about security needs and efficacy.

4. Focus on Resilience and Recovery

Today’s security strategies must extend beyond mere prevention. With an evolving threat landscape, no security barrier is impenetrable. Thus, resilience and recovery plans have become integral components of a well-rounded security approach. The faster an organization can identify and address a breach, the less damage will occur.

A robust recovery plan is essential, including secure backups for systems and data. However, preparation goes beyond technology; it's about processes. Organizations must practice these plans, ensuring employees are aware of their roles in the event of a crisis.

5. Establish a Unified Security Communication Framework

Effective communication between security and business teams is often where organizations falter. Business leaders frequently do not possess the technical knowledge needed to grasp specific risks, while security experts might lack a full understanding of business implications. Bridging this gap is imperative.

Security teams need to quantify risks in a business context, preferably attaching dollar values to potential breaches to make the stakes clear. Although estimating the cost of a theoretical breach is challenging, defensible metrics based on predicted losses, regulatory impacts, and reputational harm can be immensely valuable.

Building a Foundation for Genuine Cybersecurity

The swift rise of AI isn't a silver bullet; it won't solve all cybersecurity challenges alone. To mitigate cyber risks effectively, organizations must focus on the foundational work that may not be glamorous but is crucial for overall security. This includes addressing visibility gaps, building resilience, and enhancing interdepartmental dialogue.

As a veteran CISO, I can assert that security isn’t about flashy innovations; rather, it's about consistently focusing on the vulnerabilities most frequently exploited by attackers. Prioritizing these fundamental measures can significantly reduce exposure to cyber risks and create a more secure digital environment.

Source: Thomas Johnson · www.csoonline.com

Comments

Sign in to join the discussion.