Start With What Matters
- Neil Hare-Brown

- Aug 12
- 6 min read

Cybersecurity has a scope problem. Ask an organisation what needs protecting and the technically correct answer is usually:
Everything.
Every endpoint.
Every server.
Every application.
Every user.
Every cloud service.
Every network.
Every third party.
Every piece of data.
While technically, that may be true, from a business or investment perspective, it isn't particularly helpful. Resources are finite. Organisations cannot invest equally in everything, and security teams cannot protect everything to exactly the same degree.
Business leaders already understand this. Ask a good business leader what really makes the organisation work, what makes the money go around, and their attention will quickly converge on a relatively small number of things.
The applications that process the transactions.
The systems that deliver the service.
The platforms that enable production.
The information upon which the business depends.
The functions without which the organisation cannot operate.
These are the things that really matter. They are the critical assets.
Business Leaders Already Know What Matters
Every business leader worth their salt has a keen focus on the applications, services and functions that are core to their business. They may not call them "critical assets" or think of them in a technical sense. They may not know their vulnerability count, CVSS scores or patching status.
But they do know what happens when those assets stop working. They know which application generates revenue. They know which system customers depend upon. They know which production platform cannot be unavailable for more than a few hours and which information would cause serious problems if it became public.
Most importantly, they understand the business consequences when something goes wrong. That expertise is extraordinarily valuable to cyber risk management yet traditional cybersecurity assessment often, perhaps inadvertently, exclude precisely these people by beginning with questions about technologies, controls, vulnerabilities and threats.
I have found that when you shift the assessment to critical assets something important happens. You get the attention of the decision-makers. And we need them.
Not All Assets Are Equal
Cybersecurity frequently looks horizontally across an entire environment.
We measure overall maturity, count vulnerabilities, assess compliance, review control coverage and calculate (and present) security scores. These approaches can provide valuable information about the security environment, but they can obscure something fundamental.
The organisation doesn't experience cyber loss uniformly. Loss occurs because something that matters to the business has been disrupted, compromised, altered or exposed.
A customer-facing application might generate most of the organisation's revenue. A manufacturing control system might determine whether a production facility can operate. A database might contain commercially sensitive intellectual property or a relatively small application might support a business process without which the organisation simply cannot function.
For each of these examples - and there are many others, the technical footprints may be very different. However, their importance to the business may be enormous.
That is why I believe cyber risk assessment and management should begin with critical assets.
What Is a Critical Asset?
I use the term deliberately broadly. A critical asset could be an application, a data store, a technology platform, a business service or a business function.
In practice, applications are often particularly useful because so many modern business services are delivered through digital technology. However, the definition shouldn't be constrained by technology. The important question is:
If this asset were seriously disrupted or compromised, would the consequences materially matter?
If the answer is yes, we have something worth understanding properly.
Start With the Asset, Not the Toolset
I recommend changing the conversation. Instead of beginning with, "How good is our EDR?" try beginning with, "What happens to this critical asset if an endpoint is compromised?"
Instead of, "How mature is our vulnerability management programme?", try asking, "How confident are we that vulnerabilities affecting this critical asset are being identified and managed?".
Try replacing, "Which firewall do we have?", ask "How accessible is this critical asset to attack?"
These distinctions matter. For example, an Internet-facing application is not necessarily insecure. It may be exceptionally well protected but it is directly exposed to attack.
Conversely, an internally hosted system may be inaccessible from the Internet but poorly maintained and highly vulnerable.
Accessibility is not security and vulnerability is not risk and possessing a control is not the same thing as that control being effective.
Separating these concepts helps us understand the asset without prematurely collapsing everything into a subjective risk score.
Now We Have the Right People in the Room
This is where I think the critical-asset approach becomes particularly powerful. Cybersecurity professionals understand threats, vulnerabilities and controls. However, they are often not the people best placed to estimate the business impact of losing a critical asset.
The people who operate the business are.
Consider two simple cyber incident scenarios:
An outage: the critical asset becomes unavailable.
A data breach: information associated with the critical asset is compromised.
What would the impact on the organisation be?
How much productivity is lost?
What will response and recovery cost?
What might need replacing and at what cost?
Could fines, judgements or other liabilities arise?
Could the incident damage competitive advantage?
What might be the financial consequence of reputational harm?
These are not questions a CISO should - or even can, answer alone. Nor should they be.
They require the expertise of the people who understand how the business actually works.
Business-unit leadership.
Finance.
Operations.
Legal.
Technology.
Risk.
And, where appropriate, the Board.
This changes the nature of the assessment and cyber risk stops being something the cybersecurity team calculates and presents to the business. Instead, it becomes something the business actually helps determine.
Objectivity Doesn't Mean Certainty
None of those business leaders can tell us exactly what a future incident will cost. Nobody can.
But that isn't what we need from them. We need informed judgement.
A CFO may not know whether an outage will cost exactly £3.7 million.
But together, the management team may be able to say with reasonable confidence:
"Below £2 million seems unrealistic. Above £6 million would require several things to go badly wrong."
That is valuable information. Instead of pretending uncertainty doesn't exist, we can describe it. Instead of asking for false precision, we can establish plausible financial ranges.
And because those estimates have been developed by the people who actually understand the asset and the business consequences of losing it, they are considerably more defensible than a subjective risk score generated by the security or IT team alone.
From Assets to a Portfolio
Once an organisation identifies several critical assets, something else happens. Cyber risk stops looking like one enormous, subjective problem. It starts looking like a portfolio.
Each critical asset has its own characteristics. Its own exposure. Its own potential financial consequences. Its own risk treatment decisions.
However, the assets are also connected. A firewall may protect several of them. An EDR platform may protect hundreds. A cyber insurance policy may transfer elements of financial risk across the entire portfolio.
Investment decisions therefore begin to move away from individual technologies and towards a much more useful question:
Which investments provide the greatest benefit across the critical assets that matter most?
We will return to this later in the series because I believe cyber risk management is fundamentally portfolio management (of critical assets).
But first we need the portfolio and that means identifying what matters.
Focus Is Not Oversimplification
There is an understandable temptation when assessing cyber risk to collect everything we can. But as I argued in the previous paper; Information that does not improve the decision being supported is noise.
The same principle applies here. We don't need to model every device, process and dependency before making a useful decision. We need sufficient information about the things that matter to understand their exposure and the plausible consequences of their loss.
That is not an argument for superficial assessment but it is an argument for focused assessment.
Complexity can always be added and perhaps the difficult engineering problem is determining how much complexity is actually necessary to support a good decision.
Bring Cyber Risk Back to the Business
After decades and many hundreds of cybersecurity reviews and assessments, many of which were based on industry standards, I now consider that perhaps cybersecurity has spent too much time looking horizontally across entire technology environments.
There is another way. Start with what makes the business work. Identify the critical assets.
Bring together the people who understand them. Understand how those assets are delivered and exposed. Then ask what happens if one becomes unavailable or its information is compromised.
This approach helps to build something remarkably valuable. The attention of the decision-makers, the expertise of the business and a shared understanding of the things whose loss would actually matter.
Only then should we start trying to put numbers around the consequences.
Now, I do appreciate that many reading this may rightly point out that advocating this engagement is nothing new. They would be right! Many management consultancies advocate this approach. The problem there is that, in doing so, they often exclude the technical expertise of the cybersecurity specialists. Strategy is not connected to tactics and operations.
In the next paper, I want to explore why I believe we spend too much time trying to predict the cyber incidents that might happen and not enough time understanding the financial consequences when they do.
Thought for the week
"Start with what makes the business work. That is where cyber risk becomes a business decision."
