The cybersecurity backlog is not a security problem

Summary

The article argues that cybersecurity teams should focus on risk oversight rather than executing every corrective action. A more effective model assigns remediation responsibilities to technology and business operations owners, with security acting as an overseer responsible for risk inventory, prioritization, standards, escalation, and verification. The current model, where security teams are often assigned all remediation tasks, leads to backlogs and a failure to genuinely reduce risk.

IFF Assessment

FRIEND

This article promotes a more efficient and effective security operating model, which ultimately strengthens an organization's ability to manage and reduce risk, benefiting defenders.

Defender Context

Defenders need to advocate for clear ownership of remediation tasks. Assigning security teams the sole responsibility for patching and fixing vulnerabilities creates an unsustainable backlog and shifts focus away from strategic risk management. Organizations should implement a model where infrastructure and application owners are accountable for implementing fixes, with security providing guidance and oversight.

Read Full Story →