Online Exclusive: X is to Y is to Z – Breaches are Cheaper than Security Investments...

One thing to consider, when facing the virtual ban hammer of budget land, is that there are plenty of open source tools available for use.

The term “Too Big To Fail” is a commonly heard saying, made prominent by the economic crash in the 2008-2010 era.  I’ll save you the detailed explanation of where this statement came from, as I am sure you are quite familiar with it.  What is of interest to me is that the general format for this statement, when broken down, is (X is too Y to Z).  The evaluation of this format becomes interesting when we see it being used to form statements relevant to the work that we do as security practitioners. 

 Let’s make some statement examples, using the format above, and see how they feel:

  • X(My budget) is too Y(small) to Z(to implement specific security controls).
  • X(My company) is too Y(obscure) to Z(to be targeted by adversaries)

Just as the statement “Financial institutions are too big to fail” – the examples I gave hopefully stir up a bit of unease.  Yet, it is not uncommon to hear these statements when discussing the need to establish appropriate and often times reasonable information security best practices and standards.

When speaking to colleagues in the field, some common elements come up in conversations.  Luckily many people that I speak to, “get it”.  There are still some outliers in the mist, that will make, what appear to be reasonable at the time, statements using the (X is too Y to Z) format. Bottom-lines, budgets, cost, and ROI – are all valid business justifications for determining acceptable risk thresholds in an organization, and basing decisions on what is considered a good security investment vs a bad security investment.  Assessing risk and mitigating controls to ascertain the true value of an investment takes a bit of operational overhead if it is not already a component of the business culture.  So we end up seeing (X is too Y to Z) as a means justify side-stepping the issues at hand.

How do we shift from the (X is too Y to Z) mindset to one that better serves the organizations that we protect?  I don’t know if there is a single answer to that question, and for most, it takes a breach, or some other security concern to challenge individuals to take the actions that (X is too Y to Z) steered them away from.

One thing to consider, when facing the virtual ban hammer of budget land, is that there are plenty of open source tools available for use.  Many of these tools do great things, with the only investment needed being a little elbow grease and perhaps some fractions of compute.  They can help offset budgets and fill gaps, when you run into roadblocks put up by (X is too Y to Z).  Many of these offer some actionable metrics that should enable you to turn the tables on the (X is too Y to Z) objection and perhaps allow you to use the format to motivate upper management; X(Our exposure to risk) is too Y(great($Metric)) to Z(to continue operating in this manner.)

 In the meantime, we can continue to hope that the (X is too Y to Z) concept will be a passing fad.  That instead of hearing, “My company is too small to be breached… too obscure to be breached… too this or that to be something”, we will see a continued trend of more companies escalating security from merely a perimeter, or infrastructure viewpoint, and coming to understand that the principled exercise of practicing security enables business, instead of disabling it.

About the Author

Corey Wilburn is the Security Practice Manager at DataEndure where he specializes in the design of strategic solutions, aimed at delivering high-value operational intelligence, leveraging best-in-class products as well as services built around current and emerging standards. He has a passion for InfoSec Policies, Processes and Procedures.

Featured

  • Security Industry Association Announces the 2026 Security Megatrends

    The Security Industry Association (SIA) has identified and forecasted the 2026 Security Megatrends, which form the basis of SIA’s signature annual Security Megatrends report defining the top 10 factors influencing both near- and long-term change in the global security industry. Read Now

  • The Future of Access Control: Cloud-Based Solutions for Safer Workplaces

    Access controls have revolutionized the way we protect our people, assets and operations. Gone are the days of cumbersome keychains and the security liabilities they introduced, but it’s a mistake to think that their evolution has reached its peak. Read Now

  • A Look at AI

    Large language models (LLMs) have taken the world by storm. Within months of OpenAI launching its AI chatbot, ChatGPT, it amassed more than 100 million users, making it the fastest-growing consumer application in history. Read Now

  • First, Do No Harm: Responsibly Applying Artificial Intelligence

    It was 2022 when early LLMs (Large Language Models) brought the term “AI” into mainstream public consciousness and since then, we’ve seen security corporations and integrators attempt to develop their solutions and sales pitches around the biggest tech boom of the 21st century. However, not all “artificial intelligence” is equally suitable for security applications, and it’s essential for end users to remain vigilant in understanding how their solutions are utilizing AI. Read Now

  • Improve Incident Response With Intelligent Cloud Video Surveillance

    Video surveillance is a vital part of business security, helping institutions protect against everyday threats for increased employee, customer, and student safety. However, many outdated surveillance solutions lack the ability to offer immediate insights into critical incidents. This slows down investigations and limits how effectively teams can respond to situations, creating greater risks for the organization. Read Now

New Products

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure.

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis.

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.