Rapid adoption of AI, cloud platforms and other emerging technologies is helping organisations innovate, but inadequate planning and security controls can create serious protection gaps. Effective cybersecurity requires more than deploying new tools. Leadership must embed security across business operations while enabling teams to work efficiently.
Moses Frost, Senior Instructor at SANS Institute, discusses the importance of executive-led security culture, simplifying cybersecurity for business leaders and prioritising vulnerabilities according to their exploitability. He also explains how organisations can combine AI and cloud technologies to develop resilient security policies without restricting innovation.
Why do organisations continue to repeat familiar cybersecurity mistakes, and what lessons should leaders take from previous failures?
Organisations often prioritise rapid technology adoption because they want to remain competitive or improve business performance. Security gaps emerge when teams deploy new technologies without fully understanding the problem being addressed or the associated risks. A technology functioning correctly does not necessarily mean it has been securely integrated into the organisation.
Leaders should begin by identifying critical systems, data and business processes before determining which protections are required. Security should enable the organisation to operate more safely rather than prevent the business from moving forward.
Experience from penetration testing and red-team exercises also shows that technology alone does not determine resilience. Organisations with strong executive support and a security-conscious culture are generally much harder to compromise. Senior leaders across business, finance, operations and IT must therefore treat cybersecurity as a shared organisational responsibility.
How can organisations build cybersecurity strategies aligned with their specific business operations, risks and regulatory responsibilities?
Every organisation has different technologies, operational requirements, risk profiles and regulatory obligations. Cybersecurity strategies should reflect those specific conditions rather than rely on a standard set of controls applied without context.
Organisations should identify their most critical assets and understand how a disruption or compromise would affect business operations. Security controls can then be built around those priorities. Regulatory requirements should provide a framework for responsible operations, but compliance alone should not define the entire strategy.
Management support remains essential. Executives must give security and IT teams the authority, resources and organisational backing required to implement appropriate safeguards. Embedding security gradually across everyday processes can create sustainable improvements without unnecessarily restricting the business.
How can security teams communicate complex cyber risks to senior management in clear business terms?
Security teams should simplify technical issues and connect them to business outcomes. Senior leaders need to understand how a risk could affect operations, customers, revenue or regulatory responsibilities, along with the practical steps available to reduce that exposure.
Passwordless authentication provides a useful example. Organisations have struggled with password security for decades, but modern passwordless technologies can improve protection while also making access easier for users. Demonstrating that a security measure can reduce risk without adding complexity makes the business case much clearer.
Effective communication should show how security supports productivity and makes people’s work easier. Security professionals also need the skills to translate technical findings into concise, relevant messages that executives can understand and act upon.
How is AI intensifying vulnerability management challenges and increasing pressure on already strained patching processes?
AI is likely to accelerate the discovery of vulnerabilities, creating a significant increase in the volume of issues reported to security teams. Not every vulnerability will be exploitable, however, and organisations may be unable to patch every critical finding immediately.
Security teams should focus on actionable risk. An environment may contain thousands of vulnerabilities, but only a small number might have working exploits or present an immediate pathway for attackers. Prioritising those issues allows teams to direct limited resources towards the exposures most likely to be exploited.
Smaller and medium-sized technology providers may face the greatest pressure because they lack the security resources available to major vendors such as Microsoft or Apple. Attackers could exploit weaknesses in these widely used but less well-funded platforms, making supply-chain visibility and risk-based prioritisation increasingly important.
How can organisations build sustainable, cost-effective cloud and critical infrastructure security strategies in regulated environments?
Regulated organisations may face restrictions on which technologies, services or cloud environments they can use. Those constraints do not prevent them from implementing effective security because sufficient tools and established practices are already available.
Organisations can combine cloud-native capabilities with AI models to strengthen infrastructure configurations and security policies. AI models can help assess cloud-hardening requirements and support the programmatic implementation of suitable controls. Many cloud security building blocks are structured and repeatable, making them well suited to carefully governed automation.
A sustainable strategy should prioritise critical systems, automate repeatable security tasks and apply controls that reflect regulatory obligations. Combining cloud technologies, AI-assisted analysis and strong governance can help organisations improve resilience while controlling cost and operational complexity.
Image Credit: SANS Institute
Source: Tahawul Tech

