Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementCyber Tactics ColumnSecurity Leadership and ManagementCybersecurity News

Taking AIM at “Reasonable” Cybersecurity

SEC0818-career-feat-slide1_900p
SEC0818-cyber-feat-slide2_900
SEC0818-career-feat-slide1_900p
SEC0818-cyber-feat-slide2_900
August 1, 2018

The fact that legislators and regulators widely consider cybersecurity to be a risk management issue rather than a compliance exercise is a good news, bad news story.

On the upside, in the absence of clear legal or contractual obligations, cybersecurity generally dismisses checklist requirements (which may have little to no applied value) in favor of informed judgments. There are choices. The downside of enjoying this flexibility, however, is the second-guessing that invariably begins should something go wrong: what could have been done to prevent the incident, and was it reasonable not to have done so?

Yet, what exactly is reasonable?  The answer is known to the State of California to include the Top 20 Critical Security Controls published by the Center for Internet Security. According to the Golden State, “the failure to implement all the Controls that apply to an organization’s environment constitutes a lack of reasonable security.” California also expressly calls for companies to encrypt personal data and to make multi-factor authentication available to consumers.

At the national level, the Federal Trade Commission looks to various factors to determine reasonableness, “including the size and complexity of a company’s operations, the amount and sensitivity of data it collects, and the availability of low-cost tools to mitigate threats.” The FTC also supports the NIST Cybersecurity Framework, believing it can be “a model for companies of all sizes to conduct risk assessments and mitigation.”

Significantly, the FTC has acknowledged, “Just because a company experiences a breach does not mean its data security practices were unreasonable.” Still, it remains difficult to know what security failings the FTC considers reasonable since the FTC does not bring enforcement actions in those situations. We do know that for an organization’s security to be considered unfair and deceptive, it must cause or be likely to cause substantial injury “not reasonably avoidable by consumers and not outweighed by the benefits to consumers or competition.” Note that FTC cost-benefit analysis in this context focuses on consumer outcomes rather than the company’s self-interest in saving money.

With these considerations in mind, a good rule of thumb to ensure reasonable cybersecurity is to take AIM: Align, Implement and Measure.

Align. Whether it’s the NIST Frame-work, the CIS Top 20, ISO, or any other standard, it is advisable to pick one. There may not be correct answers for cybersecurity, but aligning against industry standards helps organizations ensure they considered the right questions.

Implement. Having policies and assessing risk are necessary steps, but they are not sufficient. Organizations must then implement appropriate physical, administrative and technical controls to mitigate the highest ranked business and victim-centric risks, and should consider creating risk registers to accept, track and manage remaining material risks.

Measure. In addition to conducting periodic penetration tests and vulnerability assessments, organizations should monitor for emerging threats and perform routine program audits. If the cybersecurity program isn’t measured, does it reasonably exist?

As a closing thought, consider this sobering, yet motivational phrase for achieving reasonable cybersecurity: ready, AIM, and you won’t get fired.

 


 

KEYWORDS: cyber risk management cybersecurity compliance data breach NIST cyber security framework

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

security

6 Crisis Response Best Practices (That Actually Hold Up When Things go Sideways)

Photograph of apartment complex patios

Enhancing Residential Building Security

Man in suit looking out window at city

Why GSOCs and Protective Intelligence Are the Cornerstone of Executive Protection

5 Minutes with Johnson

Can Organizations Trust Their Own AI?

Patient in bed

When Cyberattacks Hit Medical Devices, Patients Pay the Price

Events

August 27, 2026

Leveraging AI & Mobility to Advance Your Security Domain

LIVE: August 27, 2026 at 2 PM EDT Explore how AI-driven cloud security solutions can elevate your security domain enhancing threat detection, streamlining operations, and delivering the resilience modern organizations demand.

September 10, 2026

So, You Have an Emergency Management Plan… Now What?

LIVE: September 10, 2026 at 2 PM EDT Turning an emergency management plan into an actionable program that prepares staff, students, and partners to respond effectively is a challenge. Learn to move beyond compliance and build a resilient school safety program.
View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • Next Hacker Target? They Will Aim at Car Computer Systems; Hold on to Your Steering Wheel

    See More
  • White Powder Attacks Aim at Politicians and Residents Alike

    See More
  • Medication Tracking System Takes Aim at Counterfeit Drugs

    See More
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing