惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

酷 壳 – CoolShell
酷 壳 – CoolShell
H
Hacker News: Front Page
P
Palo Alto Networks Blog
T
ThreatConnect
Apple Machine Learning Research
Apple Machine Learning Research
博客园_首页
T
True Tiger Recordings
P
Privacy & Cybersecurity Law Blog
B
Blog
IT之家
IT之家
Last Week in AI
Last Week in AI
F
Full Disclosure
Hacker News: Ask HN
Hacker News: Ask HN
C
Comments on: Blog
Microsoft Azure Blog
Microsoft Azure Blog
C
Cybersecurity and Infrastructure Security Agency CISA
Microsoft Security Blog
Microsoft Security Blog
博客园 - 【当耐特】
N
News and Events Feed by Topic
NISL@THU
NISL@THU
腾讯CDC
雷峰网
雷峰网
Security Latest
Security Latest
李成银的技术随笔
M
Microsoft Research Blog - Microsoft Research
L
LangChain Blog
L
Lohrmann on Cybersecurity
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
Check Point Blog
Y
Y Combinator Blog
Recent Announcements
Recent Announcements
博客园 - Franky
N
News | PayPal Newsroom
V
V2EX
A
About on SuperTechFans
The Register - Security
The Register - Security
月光博客
月光博客
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Google Online Security Blog
Google Online Security Blog
MyScale Blog
MyScale Blog
Cisco Talos Blog
Cisco Talos Blog
Vercel News
Vercel News
WordPress大学
WordPress大学
C
Cyber Attacks, Cyber Crime and Cyber Security
The Hacker News
The Hacker News
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
爱范儿
爱范儿
A
Arctic Wolf
L
LINUX DO - 最新话题
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

WeLiveSecurity

The quest for greater tech independence Why geopolitical turmoil is a gift for scammers, and how to stay safe FrostyNeighbor: Fresh mischief and digital shenanigans Eyes wide open: How to mitigate the security and privacy risks of smart glasses Fake call logs, real payments: How CallPhantom tricks Android users Fixing trivial passwords is as easy as 123456 A rigged game: ScarCruft compromises gaming platform in a supply-chain attack This month in security with Tony Anscombe – April 2026 edition The calm before the ransom: What you see is not all there is GopherWhisper: A burrow full of malware New NGate variant hides in a trojanized NFC payment app Ransomware’s back office: What the ransom note won’t say Why that next data breach alert could be a trap Supply chain dependencies: Have you checked your blind spot? Recovery scammers hit you when you’re down: Here’s how to avoid a ‘second strike’ As breakout time accelerates, prevention-first cybersecurity takes center stage Digital assets after death: Managing risks to your loved one’s digital estate This month in security with Tony Anscombe – March 2026 edition RSAC 2026 wrap-up – Week in security with Tony Anscombe A cunning predator: How Silver Fox preys on Japanese firms this tax season Virtual machines, virtually everywhere – but not all protected Cloud workload security: Mind the gaps Move fast and save things: A quick guide to recovering a hacked account EDR killers explained: Beyond the drivers Face value: What it takes to fool facial recognition Cyber fallout from the Iran war: What to have on your radar Sednit reloaded: Back in the trenches What cybersecurity actually does for your business How SMBs use threat research and MDR to build a defensive edge Protecting education: How MDR can tip the balance in favor of schools This month in security with Tony Anscombe – February 2026 edition Mobile app permissions (still) matter more than you may think Faking it on the phone: How to tell if a voice call is AI or not PromptSpy ushers in the era of Android threats using GenAI Is Poshmark safe? How to buy and sell without getting scammed Is it OK to let your children post selfies online? Naming and shaming: How ransomware groups tighten the screws on victims Taxing times: Top IRS scams to look out for in 2026 OfferUp scammers are out in force: Here’s what you should know A slippery slope: Beware of Winter Olympics scams and other cyberthreats This month in security with Tony Anscombe – January 2026 edition DynoWiper update: Technical analysis and attribution Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan Drowning in spam or scam emails lately? Here’s why ESET Research: Sandworm behind cyberattack on Poland’s power grid in late 2025 Children and chatbots: What parents should know Common Apple Pay scams, and how to stay safe Old habits die hard: 2025’s most common passwords were as predictable as ever Why LinkedIn is a hunting ground for threat actors – and how to protect yourself Is it time for internet services to adopt identity verification? Your information is on the dark web. What happens next? Credential stuffing: What it is and how to protect yourself This month in security with Tony Anscombe – December 2025 edition A brush with online fraud: What are brushing scams and how do I stay safe? Revisiting CVE‑2025‑50165: A critical flaw in Windows Imaging Component LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan ESET Threat Report H2 2025 Black Hat Europe 2025: Was that device designed to be on the internet at all? Black Hat Europe 2025: Reputation is currency – even in the ransomware economy Locks, SOCs and a cat in a box: What Schrödinger can teach us about cybersecurity Seeking symmetry during ATT&CK® season: How to harness today’s diverse analyst and tester landscape to paint a security masterpiece The biggest catch: How whaling attacks target top executives Phishing, privileges and passwords: Why identity is critical to improving cybersecurity posture MuddyWater: Snakes by the riverbank Oversharing is not caring: What’s at stake if your employees post too much online This month in security with Tony Anscombe – November 2025 edition What parents should know to protect their children from doxxing Influencers in the crosshairs: How cybercriminals are targeting content creators MDR is the answer – now, what’s the question? The OSINT playbook: Find your weak spots before attackers do PlushDaemon compromises network devices for adversary-in-the-middle attacks What if your romantic AI chatbot can’t keep a secret? Can password managers get hacked? Here’s what to know Why shadow AI could be your biggest security blind spot In memoriam: David Harley The who, where, and how of APT attacks in Q2 2025–Q3 2025 ESET APT Activity Report Q2 2025–Q3 2025 Sharing is scaring: The WhatsApp screen-sharing scam you didn’t see coming How social engineering really works | Unlocked 403 cybersecurity podcast (S2E6) Ground zero: 5 things to do after discovering a cyberattack This month in security with Tony Anscombe – October 2025 edition Fraud prevention: How to help older family members avoid scams Cybersecurity Awareness Month 2025: When seeing isn't believing Recruitment red flags: Can you spot a spy posing as a job seeker? How MDR can give MSPs the edge in a competitive market Cybersecurity Awareness Month 2025: Cyber risk thrives in the shadows Gotta fly: Lazarus targets the UAV sector SnakeStealer: How it preys on personal data – and how to stay safe Cybersecurity Awareness Month 2025: Building resilience against ransomware Minecraft mods: When ‘hacking’ your game becomes a security risk IT service desks: The security blind spot that may put your business at risk Cybersecurity Awareness Month 2025: Why software patching matters more than ever AI-aided malvertising: How chatbots can help spread scams How Uber seems to know where you are – even with restricted location permissions Cybersecurity Awareness Month 2025: Passwords alone are not enough Beware of threats lurking in booby-trapped PDF files Manufacturing under fire: Strengthening cyber-defenses amid surging threats New spyware campaigns target privacy-conscious Android users in the UAE Cybersecurity Awareness Month 2025: Knowledge is power This month in security with Tony Anscombe – September 2025 edition
The case for cybersecurity: Why successful businesses are built on protection
2025-10-07 · via WeLiveSecurity

Business Security

Company leaders need to recognize the gravity of cyber risk, turn awareness into action, and put security front and center

07 Oct 2025  •  , 5 min. read

The case for cybersecurity: Why successful businesses are built on protection

These are nervy times for many business leaders. Persistently high interest rates, geopolitical tensions, supply chain disruption and abrupt changes to trade policies have created a new climate of uncertainty. Against this backdrop, many could be forgiven for stalling investment and looking for areas in which to cut costs. There are several reasons why cybersecurity should not be among them.

As an IT or security leader, you will already know why. But does your CEO, or your board? Research reveals that only 29% of CISOs believe they have enough budget to achieve their security goals. Yet 41% of board members think budgets are appropriate. If such a gap exists in your organization, it’s time to make a stronger case for cybersecurity. And since October is Cybersecurity Awareness Month, there’s no better time to recognize the gravity of cyber risk, close perception gaps and put security front and center, and ultimately turn awareness into action.

SMBs are still putting out fires

Cybersecurity is certainly better understood and appreciated at senior levels than it used to be. But it’s still viewed as a cost center rather than a strategic necessity, especially by SMBs. According to the Global Technology Industry Association (GTIA), nearly half (46%) of small and medium enterprises describe cyber as an area only of “moderate importance.” A further 12% of SMB respondents admit they’re still in tactical/reactive mode. In other words, they’re constantly putting out fires, rather than spending time and money upfront to stop fires starting in the first place.

There are two ways to change this mindset. First, articulate more clearly how cybersecurity can help your board avoid potentially critical business risk. And second, make the case more forcefully for cyber as a business enabler.

Counting the cost of inadequate cybersecurity

The good news is that there’s no shortage of case studies you could use to convince the board of the potential cost of insufficient cybersecurity spend:

  • M&S predicts lost operating profit of £300 million from a recent ransomware attack that forced its e-commerce systems offline for several weeks.
  • UnitedHealth Group estimates the cost of a ransomware attack on Change Healthcare to be nearly $2.9 billion in 2024.
  • Background check specialist National Public Data was forced to file for bankruptcy following a 2024 breach which exposed nearly three billion records.

Another good resource is IBM’s Cost of a Data Breach report, which not only outlines the average cost of a breach ($4.4m), but also how much specific technology investments or cybersecurity strategies can shave off this amount. The bottom line is that the longer threat actors are allowed to remain inside your network, the more expensive it could end up being. So products like SIEM, SOAR and threat intelligence all rank high for potential cost savings. Even better, it also lists more strategic endeavors, like DevSecOps, the appointment of a CISO, and board-level oversight.

This kind of intelligence can hopefully start to shift the conversation away from reactive spend to the development of a more considered, security-by-design culture in your organization.

From cost center to business enabler

If the risk of financial and reputational damage isn’t enough to shift the perception of cybersecurity in your organization, maybe the compliance argument will help to get these conversations over the line.

The likes of NIS2 and DORA in the EU now demand cybersecurity be treated as an ongoing risk management program designed to enhance business resilience. Senior leadership is expected to directly define, approve, and oversee these programs, and undergo mandatory training so members understand the risks and make informed decisions. They are to be held personally liable for implementation.

However, not all SMBs will be covered by such progressive regulations. So how do you persuade executives that don’t believe their organization is big enough to be a breach victim, that “good enough” security really isn’t good enough? Appeal to their business instincts. In this way, there’s a strong case for saying that an effective cybersecurity strategy could:

  • Help to protect IP and competitive differentiation. This will be particularly important in certain sectors like manufacturing, technology and media.
  • Enable expansion into new markets where rigorous regulations may apply, like the EU, or some US states (e.g., California’s CCPA data protection law).
  • Protect digital transformation. If your organization suffers a critical cyberattack, it might halt projects, divert resources, erode stakeholder trust and cause business priorities to shift.
  • Help to build customer loyalty and drive profits by bringing innovative products to market. All companies are to an extent software companies today. But if you release an insecure product, it might destroy reputation and customer loyalty.

The message and the messenger

So you have the right ideas, but the board still isn’t listening. What could be the problem? The disconnect can come from both sides. On the one hand, business leaders are often culturally predisposed to think of cyber as an “IT issue” divorced from the serious business of running an organization. But on the other, sometimes CISOs can undermine their cause, by failing to speak the language of the business.

To overcome this challenge, consider:

  • Framing cybersecurity as a business risk; ditching the technical jargon and talking about the business impact of various scenarios.
  • Using financial and business aligned metrics rather than security-centric ones. The IBM study could be useful here, as might Total Economic Impact studies for coveted solutions.
  • Using real-world examples and cautionary tales (like the ones above) when trying to persuade the board to sanction specific investments.
  • Putting your organization’s security posture into context. In other words, use intelligence on what similar companies are investing in and why, and what they’ve achieved. This will help leaders to understand where you may be falling behind.
  • Reporting little and often to the board. They don’t want to be drowned in data, so keep presentations short and sweet to get their attention. But equally, the threat landscape moves so fast that regular updates are important.
  • Building personal relationships with board members and/or senior executives. It always helps to have an advocate at the top table.

The most resilient companies are those that shift from viewing cybersecurity as a cost of doing business to a driver of trust and long-term value. Ultimately, it’s far cheaper to build security by design into new business projects and product offerings than to retrofit it when something goes wrong. You already know this. It’s now your job to persuade the board.


Let us keep you
up to date

Sign up for our newsletters