Back to the module/Cyber risk, from finding count to board dollars
The point

A finding count cannot be compared to the cost of fixing it, so it cannot be governed.

The queue is not the risk

A typical quarter-end view of a mid-size estate, as most tools present it.

Open findings this quarter

Aggregated across scanners, cloud posture and endpoint

Critical

4,212

High

11,804

Quarter on quarter

−6%

fewer criticals than last quarter

Why it matters

Every number here went down, and not one of them tells you whether the business is safer. There is no unit in common with the budget that would fix them.

What the board actually asked

Are we exposed beyond the appetite we approved, and what would it cost us if the worst of it landed? Neither question can be answered from a count, however accurate the count is.

Cyber risk, from finding count to board dollars | GeneSecure