Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Boring security controls: what finance leaders actually fund


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: Attackers usually choose the cheapest path, according to Expel’s webinar-based analysis of 300 CISOs and CFOs, while identity incidents still dominated 68.6% of events and 52.3% were blocked by basic controls such as MFA and conditional access. The security case for finance is now about measurable risk reduction, business enablement, and the cost of leaving fundamentals unfinished.

NHIMG editorial — based on content published by Expel: the second part of its CISO-CFO webinar series on security ROI and basic controls

By the numbers:

Questions worth separating out

Q: What breaks when identity controls are only documented and not executed consistently?

A: When identity controls exist only on paper, the organisation loses the ability to prevent or promptly detect bad access, missed approvals, and offboarding gaps.

Q: Why do basic identity controls often outperform advanced threat tooling?

A: Basic identity controls outperform advanced tooling because they interrupt the most common attack paths before compromise spreads.

Q: How can security teams know if cloud identity governance is actually working?

A: The clearest signals are fewer unresolved access findings, shorter evidence-collection cycles, lower counts of stale keys, and reduced reliance on manual review.

Practitioner guidance

  • Baseline identity control coverage first Inventory MFA, conditional access, managed-device enforcement, onboarding, and offboarding coverage across all business units.
  • Translate control performance into avoided-loss metrics Report identity security as blocked compromise attempts, reduced exception counts, and faster offboarding rather than abstract maturity scores.
  • Audit configuration drift across access policies Compare approved identity policy baselines with actual enforcement in production, including tenant-specific overrides and legacy exceptions.

What's in the full article

Expel's full article covers the operational detail this post intentionally leaves for the source:

  • How the webinar participants framed security ROI for CFO audiences, including the language that made budget discussions land.
  • The full breakdown of identity, endpoint, cloud, and third-party control examples that illustrate where fundamentals most often fail.
  • The survey context from 300 CISOs and CFOs, including how the research was used to support the business-case argument.
  • The broader CISO-CFO communication model that Expel and SMBC used to connect security controls to business enablement.

👉 Read Expel's analysis of how boring security controls drive cybersecurity ROI →

Boring security controls: what finance leaders actually fund?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

Boring controls are still the dominant risk-reduction lever in identity security. The market often rewards sophisticated narratives, but most real-world compromise still starts with weak authentication, stale access, or policy gaps. For IAM and PAM leaders, that means the highest-value work is usually the least glamorous work, because it reduces the attack paths that adversaries actually use.

A few things that frame the scale:

A question worth separating out:

Q: Who is accountable when identity risk causes measurable business impact?

A: Accountability sits with the teams that own identity governance, privileged access, and security risk decisions, not with the alerting tool alone. Organisations should define who can translate identity findings into financial exposure, who approves remediation, and who is responsible for containment when a privileged identity is compromised.

👉 Read our full editorial: Boring security controls deliver the clearest cybersecurity ROI



   
ReplyQuote
Share: