惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

B
Blog
Blog — PlanetScale
Blog — PlanetScale
酷 壳 – CoolShell
酷 壳 – CoolShell
GbyAI
GbyAI
M
MIT News - Artificial intelligence
T
Tailwind CSS Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 聂微东
C
Check Point Blog
云风的 BLOG
云风的 BLOG
aimingoo的专栏
aimingoo的专栏
V
Visual Studio Blog
U
Unit 42
Microsoft Azure Blog
Microsoft Azure Blog
Spread Privacy
Spread Privacy
博客园 - Franky
Vercel News
Vercel News
月光博客
月光博客
罗磊的独立博客
博客园 - 叶小钗
腾讯CDC
A
About on SuperTechFans
P
Privacy International News Feed
V
V2EX
L
LINUX DO - 最新话题
K
Kaspersky official blog
P
Privacy & Cybersecurity Law Blog
D
DataBreaches.Net
D
Darknet – Hacking Tools, Hacker News & Cyber Security
有赞技术团队
有赞技术团队
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Stack Overflow Blog
Stack Overflow Blog
T
Tor Project blog
MyScale Blog
MyScale Blog
Y
Y Combinator Blog
G
GRAHAM CLULEY
V
Vulnerabilities – Threatpost
Recorded Future
Recorded Future
大猫的无限游戏
大猫的无限游戏
P
Proofpoint News Feed
L
LangChain Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
雷峰网
雷峰网
Project Zero
Project Zero
G
Google Developers Blog
博客园 - 【当耐特】
C
Cisco Blogs
Cisco Talos Blog
Cisco Talos Blog
C
CXSECURITY Database RSS Feed - CXSecurity.com
The GitHub Blog
The GitHub Blog

Help Net Security

ChatGPT advanced account security adds passkeys and hardware keys Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months Automating Pentest Delivery: A Step-by-Step Guide - PlexTrac Open-source privacy proxy masks PII before prompts reach external AI services Shadow AI risks deepen as 31% of users get no employer training Identity is the control plane for distributed infrastructure AI traffic is getting bigger, louder, and less predictable New infosec products of the month: April 2026 cPanel zero-day exploited for months before patch release (CVE-2026-41940) Cisco releases open-source toolkit for verifying AI model lineage Met Police face criticism for using AI to spy on their own officers Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security IP Fabric MCP server adds governance and control to enterprise AIOps workflows - Help Net Security Aqua Compass MCP server enables real-time investigation and containment of runtime threats - Help Net Security Google brings instant email verification to Android, no OTP needed - Help Net Security If cyber espionage via HDMI worries you, NCSC built a device to stop it - Help Net Security Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) - Help Net Security GopherWhisper APT group hides command and control traffic in Slack and Discord - Help Net Security OpenAI tackles a bad habit people have when interacting with AI - Help Net Security A year in, Zoom's CISO reflects on balancing security and business - Help Net Security Scenario: Open-source framework for automated AI app red-teaming - Help Net Security GDPR works, but only where someone enforces it - Help Net Security Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security Google’s Workspace Intelligence promises privacy while running on your data - Help Net Security Cyberattack on French government agency triggers phishing alert - Help Net Security Claude Mythos finds 271 Firefox flaws, Mozilla believes zero-days are numbered - Help Net Security Prove Identity Platform connects verification, authentication, and fraud prevention - Help Net Security New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security Acronis GenAI Protection gives MSPs control over AI usage and data risks - Help Net Security Elastic MCP Apps bring security and observability workflows into AI tools - Help Net Security Progress Software fixes sneaky WAF bypass vulnerability (CVE-2026-21876) - Help Net Security Tencent's QClaw AI agent app arrives on Windows and macOS - Help Net Security Phishing reclaims the top initial access spot, attackers experiment with AI tools - Help Net Security OneDrive updates focus on AI, access control, and compliance - Help Net Security PentAGI: Open-source autonomous AI penetration testing system - Help Net Security Apple Intelligence flaw kept stolen tokens reusable on another device - Help Net Security Shadow AI, deepfakes, and supply chain compromise are rewriting the financial sector threat playbook - Help Net Security Thunderbird 150 arrives with encrypted message search and OpenPGP improvements - Help Net Security VirtualBox 7.2.8 is out with Linux kernel 7.0 support and crash fixes - Help Net Security Ransomware negotiator admits role in attacks he was hired to resolve - Help Net Security Scattered Spider hacker pleads guilty to stealing $8 million in cryptocurrency Ivanti Neurons AI automates IT operations, reducing manual work and security risk Silobreaker Mimir adds agentic AI to intelligence workflows with governance and transparency - Help Net Security OpenAI’s Chronicle feature lets Codex read your screen, raising privacy concerns CISA flags another Cisco Catalyst SD-WAN Manager bug as exploited (CVE-2026-20133) A single platform powers SIM farm proxy networks across 17 countries - Help Net Security NGate NFC malware targets Android users through trojanized payment app - Help Net Security Meta and PortSwigger drive offensive security further to find what others miss - Help Net Security EU pushes for stronger cloud sovereignty, awards €180 million to four providers - Help Net Security SmokedMeat: Open-source tool shows what attackers do inside CI/CD pipelines - Help Net Security How to spot a North Korean fake in a job interview - Help Net Security Product showcase: Syncthing for secure, private file synchronization - Help Net Security Week in review: Acrobat Reader flaw exploited, Claude Mythos offensive capabilities and limits Google wipes out 602 million scam ads with Gemini on duty Researcher drops two more Microsoft Defender zero-days, all three now exploited in the wild GitLab 18.11 brings agentic AI to security fixes, CI pipelines, and delivery analytics Liongard upgrades LiongardIQ with AI access, live asset data, and deeper discovery Mozilla challenges enterprise AI providers with Thunderbolt, open-source AI client under your control Codex can now operate between apps. Where are the boundaries? Android 17 Beta 4 arrives with post-quantum cryptography and new memory limits Apple AirTag tracking can be misled by replayed Bluetooth signals Social media bans might steer kids into riskier corners of the internet Workplace stress in 2026 is still worse than before the pandemic New infosec products of the week: April 17, 2026 - Help Net Security ImmuniWeb brings AI upgrades, post-quantum detection and more in Q1 2026 NIST admits defeat on NVD backlog, will enrich only highest-risk CVEs going forward Anthropic releases Claude Opus 4.7 with automated cybersecurity safeguards - Help Net Security Fortinet fixes critical FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808) - Help Net Security Google Play is changing how Android apps access your contacts and location Tails 7.6.2 patches vulnerability that could expose saved files Cargo theft malware actor spent a month inside a decoy network before researchers pulled the plug Two US nationals jailed over scheme that generated $5 million for the North Korean regime Product showcase: Ente Auth encrypts, backs up, and syncs 2FA Wi-Fi roaming security practices for access network providers and identity providers European AI spending set to hit $290 billion by 2029 Windows is getting stronger RDP file protections to fight phishing attacks Capsule Security debuts with $7 million funding to secure AI agent behavior Hackers hijacked CPUID downloads, served STX RAT to victims $12 million frozen, 20,000 victims identified in crypto scam crackdown Rockstar Games receives “pay or leak” warning after cyberattack Google makes it harder to exploit Pixel 10 modem firmware Siemens expands Industrial Automation DataCenter with edge AI and cybersecurity Adobe issues emergency fix for Acrobat Reader flaw exploited in the wild (CVE-2026-34621) Seized VerifTools servers expose 915,655 fake IDs, 8 arrested Fixing vulnerability data quality requires fixing the architecture first ZeroID: Open-source identity platform for autonomous AI agents MITRE releases a shared fraud-cyber framework built from real attack data The fully free Linux OS Trisquel gets a major update with version 12.0 Ecne Week in review: Windows zero-day exploit leaked, Patch Tuesday forecast ClickFix campaign delivers Mac malware via fake Apple page Poisoned “Office 365” search results lead to stolen paychecks Gmail’s end-to-end encryption comes to mobile, no extra apps required To counter cookie theft, Chrome ships device-bound session credentials Product showcase: Session, a messenger without phone numbers or metadata Little Snitch for Linux shows what your apps are connecting to - Help Net Security Apiiro CLI turns AI coding assistants into full-stack security engineers - Help Net Security April 2026 Patch Tuesday forecast: Spring-cleaning of a preview - Help Net Security What vibe hunting gets right about AI threat hunting, and where it breaks down - Help Net Security Health insurance lead sites sell personal data within seconds of form submission - Help Net Security
Communicating cyber risk in dollars boards understand
Mirko Zorz · 2026-05-20 · via Help Net Security

In this Help Net Security interview, Nick Nieuwenhuis, Cybersecurity Architect at Nedscaper, explains why cybersecurity has not delivered the resilience that decades of investment have promised. He argues that spending has leaned too heavily on technical controls while neglecting people, processes, and organizational dynamics.

He unpacks the gap between security teams and boards, pointing to weak risk communication and a reliance on qualitative heatmaps over hard evidence. He pushes back on root cause analysis as a reductionist habit, makes the case for treating resilience as a serious capability, and outlines what stronger organizations do differently, including investment in communication, rehearsed playbooks, and continuous learning across the security function.

cyber resilience strategy

Why has cybersecurity not delivered the expected resilience despite decades of investment?

I think we have optimised cyber security for control effectiveness, but not for system behaviour.

Most organizations approach cybersecurity through a mechanistic lens: identify threats, map them to controls, implement those controls, and demonstrate compliance. That model is deeply embedded in frameworks, audits, and even how we structure our teams. It has value, but it assumes that risk behaves in a relatively linear and predictable way. This is not the case, as cyber risk is dynamic, unpredictable and ambiguous in nature.

Cyber risk emerges from complex socio-technical systems. Incidents are rarely caused by a single missing control; they result from (missing) interactions between technology, people, processes, and organizational constraints. Academic work increasingly points out that most cyber resilience frameworks are still overly techno-centric and fail to account for these socio-technical dynamics.

So, what we have done well historically is build controls to mitigate known, predictable risks. What we have not done equally well is ensure that those controls collectively produce resilient behaviour under stress. Partially this is because we forgot to include the human element in security design. This is highlighted by the various methods of multi-factor authentication we have seen over the past 10 years, ranging from SMS codes to passkeys. All these methods work technically well, but adoption is lacking because security professionals are not good in communicating why security controls are needed and how they work. Our tools should guide secure behaviour, but we have failed to implement that adequately over the past.

In this sense, the discipline hasn’t failed due to lack of investment. Rather, that investment has been disproportionately focused on technical controls, while underinvesting in the broader socio-technical conditions that determine and improve resilience.

Where does the disconnect between cybersecurity and executive decision-making originate?

I believe this originates in how we translate cyber risk into something decision-makers can work with. Many security professionals still talk technical to their business leaders. We talk about threats like phishing and ransomware, but we forgot to accentuate the actual risk these threats pose to the business.

Besides that, when we do include a sound risk management process, we usually communicate risks in qualitative manners: “high probability, medium impact.” This is great for internal discussions, but the risk evaluation process is not grounded in evidence. There is a nice book on cyber risk quantification called ‘from heatmaps to histograms’ that highlights this gap fantastically.

Additionally, there is also a capability gap. Many boards recognize cyber as a business risk, but relatively few have deep expertise, and governance structures are not always set up to bridge that gap effectively. CISOs and other security directors need to communicate cyber risk more effective in terms of business risk, including financial impact in actual dollars, without overstating their confidence in either qualitative or quantitative methods. The beauty of good cyber risk management lies in between and balances both methods to have good narrative that resonated with boards. So, the current disconnect lies with poor cyber risk management, communication, and reporting capabilities.

What is wrong with focusing on specific failure points after incidents?

The instinct to find a root cause is understandable, but it is fundamentally a reductionist approach to what is often a systemic problem.

Traditional failure analysis assumes linear causality: something went wrong because a component failed, and if we fix that component, we prevent recurrence. This is the classic “Safety-I” perspective described by Hollnagel, where safety is defined as the absence of failure.

In complex systems, that assumption does not hold up. Failures emerge from actions (or lack thereof) by people, failed internal processes, system or technology failures or external events. But in most cases, it is a combination of the above factors that cascade the risk, so it’s difficult to point to one single failure. There are just too many unknown factors involved. This means that we need to look further than system and technology failures and include people, organizational, cultural and process factors. This will lead to changes in the security architecture and underlying processes that are more sustainable and systemic, eventually improving resilience.

How do you argue for resilience without sounding like you are lowering the bar?

Everyone needs to understand that resilience implies that something can and will go wrong. This also means that we can’t over rely on prevention alone. Cyber resilience is about withstanding, recovering from, and adapting to shocks caused by cyber events.

What helps in making that case is moving away from abstract concepts and focusing on tangible organizational capabilities. In practice, more resilient organizations invest in a number of structural and behavioural elements that go well beyond technical controls.

First, they pay deliberate attention to the people side. That includes selecting, training, and retaining individuals who can operate under pressure and deal with ambiguity. Second, they invest in communication. Resilient organizations treat communication as a primary control. Enterprise Architecture is a good mechanism to improve communication. Third, they design and rehearse playbooks. I have seen so many incident response and business continuity plans that look good on paper but break down in real crises. Finally, resilient organizations invest in a culture of continuous learning and feedback loops that feed back into security architecture and strategy. So, lowering the bar and solely focusing on prevention is not an option if you want to be able to navigate the complex world we live in.

Why are human and organizational factors still underfunded?

Technical controls are easier to define, procure, implement, and audit. They map to frameworks and can be somewhat expressed in measurable terms. Organizational dynamics are a lot messier because they are dynamic and you have to deal with perspectives, norms, values, beliefs of other people. Socio-technical research highlights that vulnerabilities emerge precisely at the intersection of human behavior and system design, not in isolation. I strongly believe that it is very hard, if not impossible, to accurately quantify security investments from a human, organizational and technological perspective when the (cyber) landscape is continuously changing and on the move.

Until we treat cybersecurity as a socio-technical system, that gap will persist. This is where the difference lies between cybersecurity and cyber resilience; cybersecurity is mostly about preventing attacks from happening, cyber resilience aims to ensure organizations are still able to perform acceptably under pressure. This indirectly implies that we cannot know it all and must be able to adapt under ever-changing circumstances.

Nick Nieuwenhuis is a speaker at Span Cyber Security Arena 2026.