Infoglobez
Live Coverage
Sign in Sign up
Trending: Champions League Transfer News Premier League World Cup
Infoglobez
AI & ML

Mastering Cybersecurity: Prioritizing Fundamentals Over Flashy Tools

Effective cybersecurity hinges on solid foundational practices rather than chasing the latest technologies. Here are key areas to address for improved security.

Sep 18, 2026 | 3 min read
Sign in to save

Risk management in cybersecurity has grown increasingly complex as cybercriminals adopt sophisticated tactics and technologies. From my experience leading cybersecurity at prominent organizations like Hyatt and United Airlines, it’s clear that many security professionals mistakenly believe that new tools will solve their problems. In actuality, focusing on core cybersecurity principles is often more effective.

New technologies naturally attract attention, yet many lack the impact of robust foundational practices. For instance, while artificial intelligence can enhance security measures, its benefits manifest only when built on strong security basics. Instead of constantly pursuing expensive security tools that may not deliver, organizations should focus on optimizing their existing security capabilities.

Here are five essential areas to strengthen your cybersecurity posture:

1. Enhance Asset Discovery and Management

A significant problem for many organizations is the inability to maintain visibility over their digital assets. Without an accurate inventory, protecting assets becomes nearly impossible. As companies expand into cloud and hybrid environments, it’s critical to have comprehensive asset management in place.

Conducting thorough asset discovery across your digital landscape is a fundamental step towards enhancing security. In my experiences, I've noted that asset inventories often exist in silos, making effective management challenging. A centralized system, where all relevant data is integrated and regularly updated, can significantly mitigate risks.

2. Optimize Identity Management

As the saying goes, "identity is the new perimeter." However, identity management continues to be underestimated in cybersecurity strategies. Organizations today manage a diverse array of identities, including human, machine, and application identities. When I worked at Hyatt, managing a multitude of visitor identities alongside employees highlighted the need for a streamlined identity solution.

Implementing strong identity security practices is crucial. Multifactor authentication (MFA) is a well-known method to reduce the chances of identity theft; those using MFA are statistically much less likely to suffer from breaches. Considering alternatives like passkeys can further enhance security while simplifying the user experience.

3. Tailor Your Security Strategy

Organizations frequently feel the pressure to adopt the latest security technology without assessing actual needs. Understanding your risk tolerance is vital. Focus first on the most sensitive data and services that your organization relies on—these are your "crown jewels."

A tiered approach to risk—highlighting priorities and acceptable risks—is essential. Regardless of organization size, a universally understood security framework should be established to provide clarity and accountability regarding security measures.

4. Focus on Resilience and Recovery

Historically, security strategies have emphasized prevention, but the changing threat landscape necessitates a shift towards resilience. It's imperative to recognize that, despite best efforts, breaches can and do occur. Therefore, having a well-defined response and recovery plan in place is vital.

Identifying breaches swiftly can minimize damage. Nonetheless, equally important is preparing a comprehensive recovery strategy that includes secure backups and practiced response protocols. Many organizations falter here, leaving employees uncertain about how to react during incidents.

5. Establish a Shared Security Language

Poor communication can hinder effective security management. Often, business leaders lack the technical know-how to understand specific security risks, while security professionals may not communicate these risks in business terms. Bridging this communication gap is essential for aligning security strategies with business objectives.

Security and risk management teams must develop a way to quantify risks, often assigning financial implications to potential breaches. This helps to articulate risks meaningfully and can facilitate more informed decision-making across the organization.

Building Strong Cybersecurity Fundamentals

The bullish adoption of AI opens many opportunities, yet it won’t replace the need for foundational cybersecurity practices. A solid security foundation forms the basis for any advanced technology implementation. Organizations must focus on the ‘un-sexy’ aspects of cybersecurity, like assessing visibility gaps, reinforcing recovery processes, and improving cross-departmental communication.

From years of experience, I can assert that effective cybersecurity isn’t about excitement. The best way to minimize your exposure to attacks is to concentrate on the everyday vulnerabilities that malicious actors commonly exploit. It’s this commitment to foundational security practices that will yield substantial long-term results.

Source: Richard Garcia · www.csoonline.com
Sign in to join the discussion.