Focus on Likelihood, Not Headlines

▶ Watch (2:37)

68% of breaches stem from non-malicious human factors. 98% of those would stop with MFA enabled. Midnight Blizzard and MGM both fell to missing MFA, not zero days. Security teams chase CVSS 10s while the biggest risk sits in unenforced authentication. Sean calls this risk illiteracy: prioritizing headlines over likelihood. Framing these attacks as revenue loss, not technical jargon, gets executive attention.

Threat Modeling Starts With Inventory and Data Flow

▶ Watch (4:44)

A complete inventory is impossible but necessary. Data flow diagrams must be layered: one high-level overview with sub-diagrams for complex services. Label trust boundaries and directional information. As security people talk to teams, threat modeling happens naturally. Document every question and answer immediately. The context will be lost in six months. Understanding business operations and how revenue is generated is key to connecting technical risks to impact.

Translate Risk to Money to Win Executive Buy-In

▶ Watch (11:52)

Executives view risk in money, not CVSS scores. Present business impact: if a CRM outage stops sales, the cost is revenue lost per day. Ransomware is abstract; “customers cannot purchase” is concrete. Document the threat model and the anticipated loss. If an executive accepts the risk, get it in writing with business context. Present alternative mitigations with different cost and time trade-offs. Find a middle manager who can translate risks into business terms. That peer relationship with executives amplifies impact.

Don’t Chase CVSS 10s — Prioritize by Business Relevance

▶ Watch (18:49)

More than one CVE releases every minute. Prioritizing by raw CVSS leads to drowning in vulnerabilities. Focus on exploitability, likelihood, and impact for your specific business. What matters to your tech stack and market segment may not matter to a friend’s company in a different industry. Sean’s analogy: building better locks while the safe is open. Stop chasing headlines and look at your own risk picture first.

Q&A

For small companies without business language, should we find a middle manager ally to translate? Yes, find a strategic ally with a peer relationship to executives who can translate risks into business impact. ▶ 21:44

How to convince executives that breaches are inevitable? Use analogies to business risks they already accept, like tax increases or vendor cost changes; breaches have likelihood too and are inevitable, so focus on impact reduction. ▶ 22:41

If executives ignore FUD for ransomware, how to get buy-in? Explain in likelihoods and cite industry peers who suffered similar losses; check their LinkedIn for past breach experience. ▶ 23:55

Are there mathematical models for exploitability at scale? You will build from scratch using open source pieces; you need to do your own research tailored to your market segment. ▶ 24:56

Notable Quotes

68% of experiences of breaches are non-malicious human factors, right? Sean Juroviesky · ▶ 2:37

Risks only exist when there is both a threat and a vulnerability. Sean Juroviesky · ▶ 11:12

your average CEO doesn’t care if you get ransomware. They care that you’re losing a million dollars a day. Sean Juroviesky · ▶ 13:07

you’ll spend all of your time building better locks while your safe is left completely wide open. Sean Juroviesky · ▶ 19:52

Key Takeaways

  • 68% of breaches involve non-malicious human factors; 98% of those stop with MFA.
  • Translate technical risk into monetary impact to get executive buy-in.
  • Prioritize by business likelihood, not CVSS score alone.

About the Speaker(s)

Sean Juroviesky is a dedicated cybersecurity, risk management, and privacy advocate; speaking on those topics at conferences across the world including DEF CON, CypherCon, CornCon, BSides Rochester, SecretCon, Sec-T, and more. Sean also acts as a cybersecurity architect for a large…