Join our Newsletter — 33% off our NHI Course

What happens when cybersecurity is treated as optional during a recession?

When cybersecurity is treated as optional, teams are more likely to accept shortcuts, defer hygiene, and weaken controls at exactly the moment the organisation is under stress. That can increase operational volatility, expose reputation and revenue to avoidable disruption, and make it harder for the business to keep operating through uncertainty. The article frames recession as a stress test that security must help the organisation survive.

Recession turns security debt into business debt

When budgets tighten, the first damage is usually not a dramatic breach, it is a steady loss of control. Security work gets deferred into the next quarter, visibility drops, and teams keep systems running with older exceptions, stale access, and weaker review discipline. That matters because recession already increases organisational strain, so any control that depends on perfect execution becomes less reliable under load.

This is why treating security as a discretionary expense is risky: the cost is not just a delayed project, it is a higher chance that small failures accumulate into operational disruption. If the business is also cutting headcount or freezing replacement hiring, the remaining teams often absorb both production support and risk management, which makes it harder to spot and correct weak controls before they matter.

One useful way to think about it is through concentration of exposure. The more an organisation postpones maintenance, rotation, review, and recovery preparation, the more a single incident can cascade into downtime, customer impact, or regulatory pain. That is especially true when the weakest controls sit around access, secrets, and system change, because those are the areas attackers and outages tend to exploit first.

For a deeper view of how access and secrets problems compound under stress, The 52 NHI breaches Report is useful reading, and the broader lifecycle patterns are covered in Ultimate Guide to NHIs.

Risk and Threat Considerations

The main risk is that “temporary” cost cutting becomes permanent control erosion. In a recession, that creates a larger attack surface and a weaker recovery posture at the same time, so even routine incidents can take longer to contain and cost more to fix.

Failure mechanism: deferred patching, delayed access reviews, stale secrets, and reduced monitoring create gaps that attackers can exploit, while operational teams lose the margin needed to detect and recover quickly.

Impact: the organisation becomes easier to disrupt, more likely to suffer avoidable outages or data exposure, and less able to prove control to customers, auditors, or regulators when trust is already under pressure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV — Govern Recession-era security decisions require explicit governance over risk, budget, and control prioritisation.
PR.AC — Identity Management, Authentication and Access Control Reduced spending often weakens access reviews, privileged access, and revocation discipline.
RC — Recover The answer centres on keeping the business able to survive disruption during uncertainty.
Recommendation — Set risk-based security governance so budget cuts do not remove controls that protect continuity. Preserve access control and revocation processes when cost pressure increases. Maintain recovery planning and restoration capability as a priority control under recession pressure.
CIS Controls v8 5 — Account Management Deferred reviews and revocation are common recession risks that expand exposure.
6 — Access Control Management The question is about protecting the organisation when shortcuts weaken access discipline.
8 — Audit Log Management Reduced security capacity can hide control drift unless logging and review remain intact.
Recommendation — Keep account review, removal, and privilege cleanup on schedule despite budget constraints. Enforce least-privilege access and timely revocation to limit recession-driven risk growth. Retain logging and review coverage so weakened controls remain visible during stress.
NIST SP 800-63 IAL — Identity Assurance Level If access governance weakens in a downturn, assurance over identity proofing and authentication becomes more consequential.
AAL — Authenticator Assurance Level Stronger authenticators reduce the chance that a stressed organisation is undone by compromised access.
Recommendation — Match identity assurance to the sensitivity of access paths you must keep trustworthy. Use stronger authenticators for high-impact access that cannot tolerate compromise.

Practitioner Guidance

What to prioritise: protect the controls that prevent unrecoverable damage first, especially the ones that govern access, secrets, and recovery paths. In practice, that means distinguishing between spend that can be delayed and controls whose failure would directly threaten continuity or customer trust.

What to verify: verify that the control owner can still answer three questions during a downturn: who can get in, what they can change, and how quickly the organisation can revoke or recover that access if something goes wrong. If those answers depend on heroics, the control is already too weak.

Practitioner takeaway: recession is not a signal to “do less security”, it is the moment to remove low-value work and preserve the controls that keep business operations observable, recoverable, and bounded.