惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
C
CERT Recently Published Vulnerability Notes
GbyAI
GbyAI
Google DeepMind News
Google DeepMind News
C
CXSECURITY Database RSS Feed - CXSecurity.com
AWS News Blog
AWS News Blog
V
Vulnerabilities – Threatpost
T
Tenable Blog
P
Proofpoint News Feed
C
Check Point Blog
T
The Exploit Database - CXSecurity.com
F
Full Disclosure
P
Privacy & Cybersecurity Law Blog
美团技术团队
U
Unit 42
C
Cyber Attacks, Cyber Crime and Cyber Security
阮一峰的网络日志
阮一峰的网络日志
Simon Willison's Weblog
Simon Willison's Weblog
量子位
AI
AI
Spread Privacy
Spread Privacy
Help Net Security
Help Net Security
Know Your Adversary
Know Your Adversary
IT之家
IT之家
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
P
Proofpoint News Feed
Recent Commits to openclaw:main
Recent Commits to openclaw:main
L
LangChain Blog
I
Intezer
T
The Blog of Author Tim Ferriss
爱范儿
爱范儿
月光博客
月光博客
Recorded Future
Recorded Future
O
OpenAI News
WordPress大学
WordPress大学
Microsoft Security Blog
Microsoft Security Blog
J
Java Code Geeks
Y
Y Combinator Blog
Engineering at Meta
Engineering at Meta
S
Security @ Cisco Blogs
Recent Announcements
Recent Announcements
P
Privacy International News Feed
NISL@THU
NISL@THU
MongoDB | Blog
MongoDB | Blog
W
WeLiveSecurity
B
Blog RSS Feed
Blog — PlanetScale
Blog — PlanetScale
博客园 - Franky
Cyberwarzone
Cyberwarzone
H
Hacker News: Front Page

Help Net Security

Police arrest 10 suspected members of Black Axe cybercrime gang ShinyHunters claims it stole 1.4 million records from Udemy Sevii unveils Cyber Swarm Defense Mode to stop AI-driven attacks at scale Alleged Chinese hacker extradited to US over cyberattacks targeting COVID-19 research Cequence Agent Personas bring granular control and governance to enterprise AI agents NowSecure MARI gives enterprises evidence-based visibility into third-party mobile app risk The metrics killing your SOC, and what to use instead US state privacy fines reached $3.425 billion in 2025 Canada’s first SMS blaster case leads to three arrests Linux storage management tool Stratis 3.9.0 adds online encryption and cache-less pool startup TLS Connect gives SMBs a right-sized automated tool to manage TLS certificates Aptori expands its platform with autonomous offensive testing to reduce security bottlenecks Your IAM was built for humans, AI agents don’t care The AI criminal mastermind is already hiring on gig platforms 25 open-source cybersecurity tools that don’t care about your budget Product showcase: LuLu reveals unauthorized outbound connections from Mac apps Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breach Users advised to drop passwords and make room for passkeys - Help Net Security Indirect prompt injection is taking hold in the wild - Help Net Security Compromised everyday devices power Chinese cyber espionage operations - Help Net Security New Cisco firewall malware can only be killed by pulling the plug - Help Net Security Meta is overhauling how you sign in, manage settings, and protect your accounts - Help Net Security Ubuntu 26.04 LTS delivers memory-safe system tools and live patching for Arm servers - Help Net Security OpenAI’s GPT-5.5 is out with expanded cybersecurity safeguards - Help Net Security AI is speeding up nation-state cyber programs - Help Net Security A study of 1,000 Android apps finds a privacy policy logging gap - Help Net Security IT spending to hit $6.31 trillion record, thanks to AI - Help Net Security Where AI in CI/CD is working for engineering teams - Help Net Security With AI's help, North Korean hackers stumbled into a near-undetectable attack - Help Net Security Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security IP Fabric MCP server adds governance and control to enterprise AIOps workflows - Help Net Security Aqua Compass MCP server enables real-time investigation and containment of runtime threats - Help Net Security Google brings instant email verification to Android, no OTP needed - Help Net Security If cyber espionage via HDMI worries you, NCSC built a device to stop it - Help Net Security Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) - Help Net Security GopherWhisper APT group hides command and control traffic in Slack and Discord - Help Net Security OpenAI tackles a bad habit people have when interacting with AI - Help Net Security A year in, Zoom's CISO reflects on balancing security and business - Help Net Security Scenario: Open-source framework for automated AI app red-teaming - Help Net Security GDPR works, but only where someone enforces it - Help Net Security Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security Google’s Workspace Intelligence promises privacy while running on your data - Help Net Security Cyberattack on French government agency triggers phishing alert - Help Net Security Claude Mythos finds 271 Firefox flaws, Mozilla believes zero-days are numbered - Help Net Security Prove Identity Platform connects verification, authentication, and fraud prevention - Help Net Security New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security Acronis GenAI Protection gives MSPs control over AI usage and data risks - Help Net Security Elastic MCP Apps bring security and observability workflows into AI tools - Help Net Security Progress Software fixes sneaky WAF bypass vulnerability (CVE-2026-21876) - Help Net Security Tencent's QClaw AI agent app arrives on Windows and macOS - Help Net Security Phishing reclaims the top initial access spot, attackers experiment with AI tools - Help Net Security OneDrive updates focus on AI, access control, and compliance - Help Net Security PentAGI: Open-source autonomous AI penetration testing system - Help Net Security Apple Intelligence flaw kept stolen tokens reusable on another device - Help Net Security Shadow AI, deepfakes, and supply chain compromise are rewriting the financial sector threat playbook - Help Net Security Thunderbird 150 arrives with encrypted message search and OpenPGP improvements - Help Net Security VirtualBox 7.2.8 is out with Linux kernel 7.0 support and crash fixes - Help Net Security Ransomware negotiator admits role in attacks he was hired to resolve - Help Net Security Scattered Spider hacker pleads guilty to stealing $8 million in cryptocurrency Meta and PortSwigger drive offensive security further to find what others miss - Help Net Security EU pushes for stronger cloud sovereignty, awards €180 million to four providers - Help Net Security SmokedMeat: Open-source tool shows what attackers do inside CI/CD pipelines - Help Net Security How to spot a North Korean fake in a job interview - Help Net Security Product showcase: Syncthing for secure, private file synchronization - Help Net Security Week in review: Acrobat Reader flaw exploited, Claude Mythos offensive capabilities and limits Google wipes out 602 million scam ads with Gemini on duty Researcher drops two more Microsoft Defender zero-days, all three now exploited in the wild GitLab 18.11 brings agentic AI to security fixes, CI pipelines, and delivery analytics Liongard upgrades LiongardIQ with AI access, live asset data, and deeper discovery Mozilla challenges enterprise AI providers with Thunderbolt, open-source AI client under your control Codex can now operate between apps. Where are the boundaries? Android 17 Beta 4 arrives with post-quantum cryptography and new memory limits Apple AirTag tracking can be misled by replayed Bluetooth signals Social media bans might steer kids into riskier corners of the internet Workplace stress in 2026 is still worse than before the pandemic New infosec products of the week: April 17, 2026 - Help Net Security ImmuniWeb brings AI upgrades, post-quantum detection and more in Q1 2026 NIST admits defeat on NVD backlog, will enrich only highest-risk CVEs going forward Anthropic releases Claude Opus 4.7 with automated cybersecurity safeguards - Help Net Security Fortinet fixes critical FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808) - Help Net Security Google Play is changing how Android apps access your contacts and location Tails 7.6.2 patches vulnerability that could expose saved files Cargo theft malware actor spent a month inside a decoy network before researchers pulled the plug OpenAI updates Agents SDK, adds sandbox for safer code execution Anthropic tests user trust with ID and selfie checks for Claude GitHub lays out copyright liability changes and upcoming DMCA review for developers EU cybersecurity standards are at risk if supplier ban passes Command integrity breaks in the LLM routing layer The fully free Linux OS Trisquel gets a major update with version 12.0 Ecne Week in review: Windows zero-day exploit leaked, Patch Tuesday forecast ClickFix campaign delivers Mac malware via fake Apple page Poisoned “Office 365” search results lead to stolen paychecks Gmail’s end-to-end encryption comes to mobile, no extra apps required To counter cookie theft, Chrome ships device-bound session credentials Product showcase: Session, a messenger without phone numbers or metadata Little Snitch for Linux shows what your apps are connecting to - Help Net Security Apiiro CLI turns AI coding assistants into full-stack security engineers - Help Net Security April 2026 Patch Tuesday forecast: Spring-cleaning of a preview - Help Net Security What vibe hunting gets right about AI threat hunting, and where it breaks down - Help Net Security Health insurance lead sites sell personal data within seconds of form submission - Help Net Security
Communicating cyber risk in dollars boards understand
Mirko Zorz · 2026-05-20 · via Help Net Security

In this Help Net Security interview, Nick Nieuwenhuis, Cybersecurity Architect at Nedscaper, explains why cybersecurity has not delivered the resilience that decades of investment have promised. He argues that spending has leaned too heavily on technical controls while neglecting people, processes, and organizational dynamics.

He unpacks the gap between security teams and boards, pointing to weak risk communication and a reliance on qualitative heatmaps over hard evidence. He pushes back on root cause analysis as a reductionist habit, makes the case for treating resilience as a serious capability, and outlines what stronger organizations do differently, including investment in communication, rehearsed playbooks, and continuous learning across the security function.

cyber resilience strategy

Why has cybersecurity not delivered the expected resilience despite decades of investment?

I think we have optimised cyber security for control effectiveness, but not for system behaviour.

Most organizations approach cybersecurity through a mechanistic lens: identify threats, map them to controls, implement those controls, and demonstrate compliance. That model is deeply embedded in frameworks, audits, and even how we structure our teams. It has value, but it assumes that risk behaves in a relatively linear and predictable way. This is not the case, as cyber risk is dynamic, unpredictable and ambiguous in nature.

Cyber risk emerges from complex socio-technical systems. Incidents are rarely caused by a single missing control; they result from (missing) interactions between technology, people, processes, and organizational constraints. Academic work increasingly points out that most cyber resilience frameworks are still overly techno-centric and fail to account for these socio-technical dynamics.

So, what we have done well historically is build controls to mitigate known, predictable risks. What we have not done equally well is ensure that those controls collectively produce resilient behaviour under stress. Partially this is because we forgot to include the human element in security design. This is highlighted by the various methods of multi-factor authentication we have seen over the past 10 years, ranging from SMS codes to passkeys. All these methods work technically well, but adoption is lacking because security professionals are not good in communicating why security controls are needed and how they work. Our tools should guide secure behaviour, but we have failed to implement that adequately over the past.

In this sense, the discipline hasn’t failed due to lack of investment. Rather, that investment has been disproportionately focused on technical controls, while underinvesting in the broader socio-technical conditions that determine and improve resilience.

Where does the disconnect between cybersecurity and executive decision-making originate?

I believe this originates in how we translate cyber risk into something decision-makers can work with. Many security professionals still talk technical to their business leaders. We talk about threats like phishing and ransomware, but we forgot to accentuate the actual risk these threats pose to the business.

Besides that, when we do include a sound risk management process, we usually communicate risks in qualitative manners: “high probability, medium impact.” This is great for internal discussions, but the risk evaluation process is not grounded in evidence. There is a nice book on cyber risk quantification called ‘from heatmaps to histograms’ that highlights this gap fantastically.

Additionally, there is also a capability gap. Many boards recognize cyber as a business risk, but relatively few have deep expertise, and governance structures are not always set up to bridge that gap effectively. CISOs and other security directors need to communicate cyber risk more effective in terms of business risk, including financial impact in actual dollars, without overstating their confidence in either qualitative or quantitative methods. The beauty of good cyber risk management lies in between and balances both methods to have good narrative that resonated with boards. So, the current disconnect lies with poor cyber risk management, communication, and reporting capabilities.

What is wrong with focusing on specific failure points after incidents?

The instinct to find a root cause is understandable, but it is fundamentally a reductionist approach to what is often a systemic problem.

Traditional failure analysis assumes linear causality: something went wrong because a component failed, and if we fix that component, we prevent recurrence. This is the classic “Safety-I” perspective described by Hollnagel, where safety is defined as the absence of failure.

In complex systems, that assumption does not hold up. Failures emerge from actions (or lack thereof) by people, failed internal processes, system or technology failures or external events. But in most cases, it is a combination of the above factors that cascade the risk, so it’s difficult to point to one single failure. There are just too many unknown factors involved. This means that we need to look further than system and technology failures and include people, organizational, cultural and process factors. This will lead to changes in the security architecture and underlying processes that are more sustainable and systemic, eventually improving resilience.

How do you argue for resilience without sounding like you are lowering the bar?

Everyone needs to understand that resilience implies that something can and will go wrong. This also means that we can’t over rely on prevention alone. Cyber resilience is about withstanding, recovering from, and adapting to shocks caused by cyber events.

What helps in making that case is moving away from abstract concepts and focusing on tangible organizational capabilities. In practice, more resilient organizations invest in a number of structural and behavioural elements that go well beyond technical controls.

First, they pay deliberate attention to the people side. That includes selecting, training, and retaining individuals who can operate under pressure and deal with ambiguity. Second, they invest in communication. Resilient organizations treat communication as a primary control. Enterprise Architecture is a good mechanism to improve communication. Third, they design and rehearse playbooks. I have seen so many incident response and business continuity plans that look good on paper but break down in real crises. Finally, resilient organizations invest in a culture of continuous learning and feedback loops that feed back into security architecture and strategy. So, lowering the bar and solely focusing on prevention is not an option if you want to be able to navigate the complex world we live in.

Why are human and organizational factors still underfunded?

Technical controls are easier to define, procure, implement, and audit. They map to frameworks and can be somewhat expressed in measurable terms. Organizational dynamics are a lot messier because they are dynamic and you have to deal with perspectives, norms, values, beliefs of other people. Socio-technical research highlights that vulnerabilities emerge precisely at the intersection of human behavior and system design, not in isolation. I strongly believe that it is very hard, if not impossible, to accurately quantify security investments from a human, organizational and technological perspective when the (cyber) landscape is continuously changing and on the move.

Until we treat cybersecurity as a socio-technical system, that gap will persist. This is where the difference lies between cybersecurity and cyber resilience; cybersecurity is mostly about preventing attacks from happening, cyber resilience aims to ensure organizations are still able to perform acceptably under pressure. This indirectly implies that we cannot know it all and must be able to adapt under ever-changing circumstances.

Nick Nieuwenhuis is a speaker at Span Cyber Security Arena 2026.