A threat-based approach to security
Will Semple · Computer Fraud & Security · 2015
Traditionally, security practitioners are taught to evaluate security in terms of risk to their organisations, and security policies and practices are put in place purely to minimise these risks. Traditionally, security practitioners are taught to evaluate security in terms of risk to their organisations, and security policies and practices are put in place purely to minimise these risks. The problem with this approach is that, by focusing on the ‘worst case scenarios’, we forget about the actual threats that exist. Security professionals and organisations need to change the focus from a risk- to a threat-based approach in order to stand the best chance against cyber-criminals, explains Will Semple of Alert Logic.