Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
ColumnsCybersecurityManagementCyber Tactics ColumnSecurity Enterprise ServicesSecurity Leadership and ManagementSecurity & Business Resilience

Cyber Tactics

Flaming torches and cybersecurity

Being a security leader while juggling business priorities and daily operations is a challenge that requires pragmatic solutions.

By John McClurg
man on elephant

CreativaImages / iStock / Getty Images Plus via Getty Images

cyber tactics
man on elephant
cyber tactics
September 6, 2022

Some days, being a cybersecurity leader can feel particularly arduous — like following in the footsteps of Anthony Gatto. Who is he? According to Guinness World Records, Anthony has juggled more flaming torches at one time than anyone else on the planet.

As chief information security officers (CISOs), we, with increasing frequency, just want to get through the day without getting burned as we help our teams juggle security and business priorities and operational exigencies.

Perhaps, if one has a large team, there are enough hands to go around. But what of that larger number of us who are part of IT or security at a small or medium-sized business (SMB)? The juggling routine can prove significantly more onerous. I will share some pragmatic solutions for this in a moment, but first, let’s review some of the flaming objects now commanding our attention.

Cybersecurity Challenges Organizations Currently Face

  • Finding security talent: The 2021 (ISC)² Cybersecurity Workforce Study reported a global shortage of 2.72 million cybersecurity professionals. And the U.S. Bureau of Labor Statistics lists “cybersecurity analyst” as one of the fastest growing roles, with demand increasing 33% by the end of the decade.
  • Budgeting for training and talent retention: A recent Ponemon Institute Study found that more than half of IT & security professionals find their security operation centers (SOCs) to be ineffective, and 65% are considering quitting in the next year.
  • Staying ahead of the evolving threat landscape: The number of specialized updates the Cybersecurity and Infrastructure Security Agency (CISA) issues about increasingly sophisticated nation-state threat actors continues to grow. And a growing number of cybercriminals are implementing sophisticated tactics, techniques and procedures (TTPs) that used to be reserved for nation-states.
  • Coping with increasing “tool sprawl” and decentralization: Many organizations — and vendors — keep “bolting on” point solutions to address specific types of threats. However, this often results in too much complexity and a fragmented approach to security, which reduces the effectiveness of the overall security program.
  • A growing number of attacks we are seeing are designed to reach large targets by compromising SMBs in the target’s supply chain: They know SMBs typically are under-resourced in cybersecurity, and that many small and medium-sized organizations lack the expertise to defend against anything beyond what their firewalls can keep out. Therefore, as I’ve argued in previous columns, all boats must rise together in security, regardless of their size — or they’ll sink together instead.
  • Grappling with the reality that “always-on” coverage is nearly impossible: Even those with whom I speak that have decent-sized teams still face chunks of time where their security has gaps, based on employees being out on vacation, getting sick, or going on various types of leave and holidays. In this shortage-of-talent-environment, the continuous coverage organizations need is hard to come by.


Two Strategies for Continuous & Robust Cybersecurity

I suggest two main strategies that can help organizations of all sizes, but especially SMBs with limited budgets and staff.

First and foremost, take a close look at managed extended detection and response (XDR). XDR represents the next generation of endpoint detection and response (EDR) that expands visibility across the entire environment you operate in. It’s a holistic approach that eliminates blind spots, but it can be expensive and unwieldy — even for large enterprises with extensive security staff and in-house expertise. Managed XDR makes this advanced level of security accessible because you rely on a trusted partner or specialist to implement it. And it can be more cost-effective than building and maintaining XDR capabilities in-house. A key point here: Only consider a managed XDR partner that can augment your security team every single day of the year, around-the-clock, with highly trained staff, using tools that you know and trust.

Secondly, find technology that can prevent attacks before they happen, through proven predictive artificial intlligence (AI) techniques. Traditional antivirus typically detects threats that are underway, then quarantines them, forcing a response. With predictive AI, for example, you can block up to 99% of attacks before they execute. This saves time, saves money, and reduces the pressure on your internal security team.

So, the juggling effort within cybersecurity can be burdensome. But there are strategies that can help us handle the flaming torches, while reducing the chance of getting burned. We may not end up in Guinness World Records anytime soon, but we can sleep easier at night. That is reward enough.

KEYWORDS: cyber security information security ransomware risk management security vulnerabilities threat intelligence

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

John mcclurg

John McClurg served as Sr. Vice President, CISO and Ambassador-At-Large in BlackBerry's/Cylance’s Office of Security & Trust. McClurg previously was CSO at Dell; Vice President of Global Security at Honeywell International, Lucent Technologies/Bell Laboratories; and in the U.S. Intelligence Community, as a twice-decorated member of the Federal Bureau of Investigation.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Security Leadership and Management
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Leadership and Management
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Person in red hoodie

When Metal Theft Becomes a Life Safety Crisis

Stacked books

Safe Learning 101 Program Supports Schools in Strengthening Campus Security

Diverse Team Collaborating on Business Analysis

12 Tips for Building an Effective Security Budget

Nurse

Why De-Escalation Must Be Part of a Layered Safety Strategy in Healthcare

Security guard

Connected Security: How Proactive Real-Time Tech Keeps Security Workers Safe

SEC 2026 Benchmark Banner

Events

May 21, 2026

From Referral to Response: Managing Domestic Violence Threats in the Workplace

Domestic violence remains a complex driver of workplace violence, creating high-risk scenarios that require coordination across departments without clear ownership. Learn how threat management teams can manage domestic violence referrals from the start.

June 3, 2026

The Role of AI and Video in Measuring Health, Safety, and Security Standards

OSHA fines grab headlines, but most compliance issues start with everyday operational gaps: missed protocols, unsecured areas, or slow response. Learn how emerging technologies & AI can be leveraged towards a more proactive model of compliance.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products
Solutions by Sector webinar promo


The Role of AI and Video - Free Webinar - June 3, 2026

Related Articles

  • Cyber tactics

    2023: The year for contextual cyber threat intelligence

    See More
  • cyber security

    Reflections on 35 years in the trenches

    See More
  • Cyber

    Have we declared “open season” on CISOs?

    See More
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing