Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementCyber Tactics ColumnSecurity Leadership and ManagementCybersecurity News

Taking AIM at “Reasonable” Cybersecurity

SEC0818-career-feat-slide1_900p
SEC0818-cyber-feat-slide2_900
SEC0818-career-feat-slide1_900p
SEC0818-cyber-feat-slide2_900
August 1, 2018

The fact that legislators and regulators widely consider cybersecurity to be a risk management issue rather than a compliance exercise is a good news, bad news story.

On the upside, in the absence of clear legal or contractual obligations, cybersecurity generally dismisses checklist requirements (which may have little to no applied value) in favor of informed judgments. There are choices. The downside of enjoying this flexibility, however, is the second-guessing that invariably begins should something go wrong: what could have been done to prevent the incident, and was it reasonable not to have done so?

Yet, what exactly is reasonable?  The answer is known to the State of California to include the Top 20 Critical Security Controls published by the Center for Internet Security. According to the Golden State, “the failure to implement all the Controls that apply to an organization’s environment constitutes a lack of reasonable security.” California also expressly calls for companies to encrypt personal data and to make multi-factor authentication available to consumers.

At the national level, the Federal Trade Commission looks to various factors to determine reasonableness, “including the size and complexity of a company’s operations, the amount and sensitivity of data it collects, and the availability of low-cost tools to mitigate threats.” The FTC also supports the NIST Cybersecurity Framework, believing it can be “a model for companies of all sizes to conduct risk assessments and mitigation.”

Significantly, the FTC has acknowledged, “Just because a company experiences a breach does not mean its data security practices were unreasonable.” Still, it remains difficult to know what security failings the FTC considers reasonable since the FTC does not bring enforcement actions in those situations. We do know that for an organization’s security to be considered unfair and deceptive, it must cause or be likely to cause substantial injury “not reasonably avoidable by consumers and not outweighed by the benefits to consumers or competition.” Note that FTC cost-benefit analysis in this context focuses on consumer outcomes rather than the company’s self-interest in saving money.

With these considerations in mind, a good rule of thumb to ensure reasonable cybersecurity is to take AIM: Align, Implement and Measure.

Align. Whether it’s the NIST Frame-work, the CIS Top 20, ISO, or any other standard, it is advisable to pick one. There may not be correct answers for cybersecurity, but aligning against industry standards helps organizations ensure they considered the right questions.

Implement. Having policies and assessing risk are necessary steps, but they are not sufficient. Organizations must then implement appropriate physical, administrative and technical controls to mitigate the highest ranked business and victim-centric risks, and should consider creating risk registers to accept, track and manage remaining material risks.

Measure. In addition to conducting periodic penetration tests and vulnerability assessments, organizations should monitor for emerging threats and perform routine program audits. If the cybersecurity program isn’t measured, does it reasonably exist?

As a closing thought, consider this sobering, yet motivational phrase for achieving reasonable cybersecurity: ready, AIM, and you won’t get fired.

 


 

KEYWORDS: cyber risk management cybersecurity compliance data breach NIST cyber security framework

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Security Leadership and Management
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Education & Training
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Opened padlock on computer keyboard

10 Data Breaches to Know About (April 2026)

Laptop with desktop screen showing

Research: Microsoft Edge Loads Stored Passwords in Cleartext

Diverse Team Collaborating on Business Analysis

12 Tips for Building an Effective Security Budget

Laptop in darkness

Reframing MFA Bypass: Four Identity Gaps Attackers Exploit

Nurse

Why De-Escalation Must Be Part of a Layered Safety Strategy in Healthcare

SEC 2026 Benchmark Banner

Events

June 3, 2026

The Role of AI and Video in Measuring Health, Safety, and Security Standards

OSHA fines grab headlines, but most compliance issues start with everyday operational gaps: missed protocols, unsecured areas, or slow response. Learn how emerging technologies & AI can be leveraged towards a more proactive model of compliance.

June 10, 2026

Applying Agentic AI in Security Operations for Faster Decisions & Better Outcomes

Security teams have never had more visibility. We’ll explore how a new decision layer is helping security teams move from detection to decision. Turn alerts into decision-ready context, reducing reliance on manual triage and enabling faster action.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products
Solutions by Sector webinar promo


The Role of AI and Video - Free Webinar - June 3, 2026

Related Articles

  • Next Hacker Target? They Will Aim at Car Computer Systems; Hold on to Your Steering Wheel

    See More
  • Illinois-tech-research

    Researchers at Illinois Tech aim to unveil anonymous online extremists using ML and OSINT software

    See More
  • White Powder Attacks Aim at Politicians and Residents Alike

    See More
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing