Cyber Risk Management IS Portfolio Management.


Imagine asking a CFO to manage an investment portfolio without knowing the value, risk or purpose of the individual investments within it. It would be absurd, right?
Yet we frequently manage cyber risk in something approaching this way. As cyber professionals we often;
Look across enormous technology environments.
Measure overall maturity.
Count vulnerabilities.
Identify control gaps.
Compare ourselves with peers.
Consider the latest threats.
Then, somehow, we try to turn all of this into an organisation-wide cybersecurity budget.
Perhaps there is a better way.
In Article 4, I argued that cyber risk management should start with what matters: the critical assets that make the business work and, ultimately, make the money go around.
Once we do that, something interesting happens. We no longer have one enormous thing called "cyber risk". Instead, we have a portfolio of critical assets, each with its own financial exposure and each requiring decisions about risk reduction, transfer, acceptance and avoidance.
Cyber risk management starts to look remarkably like portfolio management.
The Problem With the Enterprise-Wide View
There is nothing inherently wrong with assessing an entire technology environment. Sometimes that is precisely what is required. But it can be a poor starting point for investment decisions.
Consider two applications. The first processes most of the organisation's revenue. The second supports an internal administrative function that could comfortably be unavailable for several days.
Both might sit on similar technology. They might both have similar vulnerabilities. They may also receive the same security score. But they are highly unlikely to represent the same business risk.
If we begin with the technology environment, that distinction can become obscured. However, if we begin with the critical assets, it becomes obvious. One asset matters more and therefore, decisions concerning it deserve correspondingly greater attention.
Benchmarking is Often Useless
The cybersecurity and cyber insurance community often uses benchmarking in an effort to clarify - and simplify - cyber risk. For this they use benchmarking. Business leaders are told that they have a lot of risk because other organisations in their sector also have a lot of risk.
On the face of it, such an approach would seem logical. However, it is misleading. There are too many variables for such an approach to be useful.
Consider two companies in the same sector. When you ask business leaders at Company A what they consider would be the impact should 'Critical Asset X' suffer an outage or a breach their views - even when collaborative and objective - will vary wildly from executives at Company B. Even if the exposure to attack is similar. And that can also be questioned. The perceived loss magnitude will be different. Thus the risk will be different.
Build the Risk From the Assets Up
The answer is to build the organisation's specific cyber risk picture from the bottom up. Use the following process:
Identify the critical assets.
Understand each one.
Estimate the plausible financial consequences of outage and data breach.
Determine what risk is being mitigated.
Determine what is being transferred.
Determine what can be accepted.
Determine whether anything should be avoided.
Do that consistently across the critical assets and the organisation begins to develop something far more useful than an overall security score. It develops a financial portfolio of cyber risk.
Now management can see where financial exposure is concentrated. And concentration matters.
Five applications each carrying £500,000 of plausible exposure create a very different management problem from one application carrying £20 million. An aggregate figure alone doesn't tell us that. The portfolio does.
But Critical Assets Don't Exist in Isolation
This is where portfolio thinking becomes particularly important. If every critical asset had completely independent technology and controls, we could assess each one separately and simply add everything together.
Real organisations don't work like that. Critical assets share infrastructure. They share networks and identity systems. They share people. Most importantly, they share controls.
A firewall might protect twenty critical applications, an EDR platform might protect hundreds. A SOC might monitor almost the entire estate yet an identity platform might provide authentication across the organisation.
The same is true of risk transfer. A single cyber insurance policy may transfer elements of financial exposure associated with dozens of critical assets. A contractual indemnity may apply to multiple services yet a supplier agreement may allocate liability across an entire business relationship.
The portfolio therefore contains not only shared risks. It contains shared treatments.
The Economics of Shared Controls
For me this creates an important investment issue.
Suppose an organisation spends £500,000 on an EDR capability protecting ten critical assets. It would clearly be wrong to treat that as £500,000 of investment against every asset. That would turn a £500,000 control into an apparent £5 million investment.
Equally, assigning the entire cost to one asset would distort the economics of the other nine.
Portfolio thinking allows us to recognise that the control is shared. The investment occurs once yet its benefit occurs many times.
This is where the economics of cybersecurity become interesting. Some controls are highly localised yet others provide protection across large parts of the critical-asset portfolio. That means two controls costing exactly the same amount may have very different portfolio value. And that leads naturally to a much better executive question:
Where will the next pound of investment provide the greatest benefit across the critical assets that matter?
We cannot answer that question by looking at products in isolation. We need the portfolio.
The Same Applies to Insurance
Cyber insurance is often discussed separately from cybersecurity investment. I think that is a mistake.
Insurance is simply another recognised mechanism for treating risk: risk transfer.
Suppose an organisation has ten critical assets whose financial exposure is partly covered by the same cyber insurance policy. The premium shouldn't conceptually be viewed ten times. It is one portfolio-level investment that transfers defined elements of risk across multiple assets.
The same principle applies to contracts, indemnities and other mechanisms that allocate financial liability.
This is why I believe the cybersecurity budget and the cyber insurance budget should ultimately be part of the same conversation. Both consume finite resources and both exist to manage financial risk. The mechanisms are different but the objective is shared.
From Toolsets to Decisions
Cybersecurity budgeting often starts with tools. Typical questions include:
Do we renew the SIEM?
Should we replace the EDR?
Do we need another attack-surface management platform?
Should we increase SOC coverage?
These may all be sensible questions but they are downstream questions.
The upstream question should be:
What financial risk exists across our portfolio of critical assets, and how do we want to treat it?
Only then should we ask which controls, contracts or insurance arrangements best support those decisions.
In this way we can reverse the traditional conversation. Instead of:
Technology → Budget → Hope it reduces risk
we move towards:
Critical Assets → Financial Risk → Risk Treatment → Investment
I believe that is a much more defensible chain of reasoning.
Portfolio Thinking Also Reveals Economies of Scale
There is another benefit. Once controls and transfer mechanisms are mapped across critical assets, management can begin to see where investment creates economies of scale.
Perhaps strengthening identity management reduces risk across fifteen critical assets. Or it may be that improving one backup capability materially improves resilience across six.
Perhaps one contractual change transfers risk affecting several business services.
Conversely, perhaps an expensive security control benefits only one relatively low-risk asset.
Without the portfolio view, these relationships can be difficult to see. With it, they become investment information. This is where I think cyber risk management begins to move towards something much more interesting. It is cyber investment economics.
It changes the narrative from, "How much does this control cost?", to "How much financial risk does this investment help us manage across the portfolio?"
I don't think our profession can yet answer that second question particularly well but I do believe it is where we need to go.
Don't Lose the Individual Asset
I would like to highlight an important caution. Portfolio management does not mean returning to an aggregated enterprise score. Quite the opposite.
The portfolio only has meaning because the individual critical assets retain their identity.
Management should still be able to see:
which assets carry the greatest exposure;
which treatments apply to each;
where controls are shared;
where risk transfer applies;
what remains accepted.
The portfolio is therefore not a replacement for critical-asset analysis. It is the consequence of it.
The key is to understand the risks that the critical assets may suffer individually yet manage them collectively.
The Portfolio Is Never Finished
There is one final complication. The portfolio doesn't stand still.
Businesses change. Threats change. Applications change. Insurance changes. Controls change.
And controls that were effective when implemented do not remain equally effective indefinitely. They degrade - the subject of an article I wrote a few years back.
That means today's portfolio is not next year's portfolio. Cyber risk management cannot therefore be a periodic exercise in producing another static assessment. It requires revision and it requires maintenance.
Increasingly, I think we should treat that maintenance in exactly the same way that engineers treat maintenance in other systems: as something planned rather than something triggered only when failure occurs.
That is the subject of the next paper.
Thought for the week
"Understand critical assets individually. Manage cyber risk as a portfolio."
