Join our Newsletter — 33% off our NHI Course

Why do cyber events remain a top business risk even when organisations invest more in defence?

Cyber events stay at the top because the threat surface keeps expanding faster than many defences mature. Remote work, personal devices, ransomware services, AI-assisted phishing, and supply chain exposure all create more entry points and more ways to interrupt operations. Businesses also see direct financial and reputational impact, so the risk is measured in lost time, lost trust, and lost revenue, not just control failures.

Why cyber risk stays high even when defences improve

Spending more on security does not remove the business risk because attackers, exposure, and operational dependency are all changing at the same time. Defences can reduce frequency or limit blast radius, but they rarely eliminate disruption. If the organisation depends on digital channels, shared vendors, and always-on access, a cyber event can still interrupt revenue, service delivery, and trust.

A useful way to think about the problem is that security investment often improves control maturity inside the enterprise while the attack surface expands outside it. That gap is why leaders still treat cyber as a top enterprise risk: the question is no longer only whether an intrusion is possible, but how quickly it can spread, which processes stop, and how long recovery takes.

For a practical view of how real compromise patterns translate into business exposure, see The 52 NHI Breaches Report, which shows how credential theft, lateral movement, and supply chain access can turn a technical weakness into operational disruption.

What makes the risk persist even after more spending

More security tools do not automatically mean less risk because modern environments are more interconnected than the control stack is mature. Remote work, personal devices, cloud services, SaaS integrations, and third-party dependencies all add routes around traditional perimeter thinking. In practice, this means one weak trust link or one exposed secret can affect many systems at once.

Cyber risk also persists because attackers increasingly target business continuity, not just systems. Ransomware, account takeover, and phishing are effective precisely because they create downtime, exception handling, and manual workarounds. The loss is therefore measured in interrupted operations, recovery effort, and customer confidence, not only in the presence of malware or a failed control.

For defenders, the hard part is that improvement is often uneven. A stronger endpoint stack does not neutralise weak supplier access, and better awareness training does not stop a misconfigured cloud integration or a compromised account with excessive privilege. Security spending can lower exposure, but business risk remains whenever a single compromise can still disrupt a critical workflow.

The defensive side of that equation is well captured by MITRE D3FEND, which helps map controls to attack techniques, and by CISA Known Exploited Vulnerabilities Catalog, which shows how known weaknesses remain urgent when they are actively exploited.

How executives should judge cyber risk as a business issue

The executive mistake is to equate higher security spend with acceptable risk. What matters is whether the organisation can absorb an event without unacceptable loss of time, trust, or revenue. That means the real benchmark is resilience: can core services keep running, can critical access be controlled, and can recovery happen fast enough to preserve operations?

Risk should also be judged by concentration. A single identity, vendor, application, or integration that can affect many business functions creates outsized exposure even when the rest of the environment is well defended. The most important question is not whether controls exist, but whether the most damaging paths have been narrowed enough to change the business outcome if an incident occurs.

Authoritative guidance on that broader operating model is useful here, especially CISA cyber threat advisories for understanding current attacker priorities, and NIST Cybersecurity Framework 2.0 for structuring governance, protection, detection, response, and recovery as a business resilience problem rather than a tooling problem.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.RM-01 — Risk Management Strategy Cyber risk here is a business risk posture issue.
GV.RM-02 — Risk Management Strategy Oversight Leadership must govern residual risk from expanding attack surface.
RC.RP-01 — Recovery Plan Implemented The question centers on loss of time and continuity when events occur.
Recommendation — Align cyber investment to the enterprise risk appetite and loss scenarios. Assign oversight for residual cyber risk and track it against business impact. Maintain and test recovery plans for critical business services.
CIS Controls v8 CIS-1 — Enterprise Asset Inventory and Control Risk persists when critical assets and dependencies are not fully known.
CIS-17 — Incident Response Management Top business risk depends on response speed and business disruption containment.
Recommendation — Maintain an accurate inventory of systems, data, and exposed dependencies. Exercise incident response for the services that would cause the greatest loss.

Practitioner Guidance

What to prioritise: Focus first on the assets and processes whose outage would immediately affect revenue, safety, customer trust, or regulatory obligation. Those are the paths where cyber risk stays material even if the rest of the estate looks well controlled.

What to verify: Test whether a single stolen credential, supplier compromise, or misconfiguration can reach production systems or interrupt a critical workflow. If the answer is yes, the environment still carries high business risk regardless of how many controls are deployed.

What good looks like: Leadership can point to the small set of business services that would create the greatest loss, the controls that protect them, and the recovery time that is actually achievable. That is a more honest risk posture than a long list of security products.

Practitioner takeaway: Cyber risk remains a top business issue when the organisation can still lose time, trust, or revenue faster than it can contain and recover from compromise.