How to Align Your Cybersecurity Posture and Cyber Risk Tolerance

By Aaron Branson, Netsurion

Your business’s IT network is constantly connected to the Internet, includes countless SaaS applications and API connections, and is accessed by employees and vendors located anywhere in the world. As a result, your business is always exposed to cyber-risk, some of which is avoidable, but also some of which is unavoidable.

Your cyber-risk tolerance, the types and amount of risk, on a broad level, an organization is willing to accept in its pursuit of value, governs your cybersecurity spend and correspondingly your cybersecurity posture. In simpler times, deploying a firewall to guard the network and installing signature-based anti-virus at the endpoints was considered appropriate to get a medium level of cybersecurity. The evolution of the threatscape makes such a posture antiquated and consequently exposes the organization to very high levels of cyber-risk. 

Avoidable risks are those you can address by implementing standard cybersecurity practices (i.e. patch management, multi-factor authentication, strong password policies, least privilege access, security awareness training, and more). The big question to ask yourself and your organization is “what is acceptable exposure to unavoidable risk (our cyber-risk tolerance) and how do we best align to it (our cybersecurity posture)? 

 
What Are These Unavoidable Cyber Risks?

They basically fall into these three camps: 

Mitigating these risks essentially require: 

 
What’s the Best Way To Improve Your Cybersecurity Posture?

Managed Detection & Response (MDR) services are enjoying high rates of acceptance with organizations that accept that such services are a must for modern threat defense.  

Not to be confused with simply Managed Endpoint Detection & Response software, MDR services can have a wider scope of coverage.  

The global MDR market size is expected to grow from an estimated value of USD 2.6 billion in 2022 to USD 5.6 billion by 2027, at a Compound Annual Growth Rate (CAGR) of 16.0% from 2022 to 2027. Some of the factors that are driving the market growth includes addressing the shortage of skilled cybersecurity professionals and budget constraints, government regulations, and strict regulatory compliance.  

What benefits do MDR services provide in terms of risk reduction? In a nutshell, this service reduces unavoidable cyber-risk. 

 
Is There a Scalable MDR Approach for Your Business’s Needs Today and Tomorrow?

Your organization is not static. It’s always changing – and hopefully growing. As organizations grow, typically their cyber-risk tolerance shrinks. How do you invest in a proper MDR solution to solve for today’s risk tolerance while avoiding a future rip-and-replace to meet a more stringent risk tolerance in the future? 

There are two axes on which your MDR solution should flex with your organization’s cyber-risk tolerance to deliver an aligned cybersecurity posture. 

 
What Other Characteristics of MDR Can Impact Cyber Risk Tolerance and Cybersecurity Posture Alignment?

There are three primary characteristics to dive into when selecting an MDR solution: