Bridging the Visibility Gap: 2025 Global Cybersecurity Maturity Report
尽管安全预算不断增加,数据泄露问题依然严重,主要因企业缺乏对关键资产、漏洞及业务流程的可见性,且基本安全措施执行不到位。过多的安全工具导致团队陷入配置工作和误报中,难以有效应对风险。专家建议从资产测绘、威胁分析入手,精简冗余工具,强化安全卫生,并提升CISO决策权以确保安全与业务目标一致。
2025-7-16 17:14:4
Author: securityboulevard.com(查看原文)
阅读量:14
收藏
Reuven “Rubi” Aronashvili, CEO of CYE, asks a blunt question: Why are breaches still rampant when security budgets have never been larger? Drawing on his journey from leading an Israeli red‑team unit to advising Fortune‑500 boards, Aronashvili argues that most companies are still flying blind. Visibility—knowing exactly which assets, vulnerabilities and business processes are at risk—remains the missing ingredient that no purchase order can fix.
CYE’s 2025 maturity survey reinforces the point. Basic safeguards such as strong passwords, MFA, patch management and clear internet access rules are still the root cause in a majority of real‑world incidents. Yet bigger budgets don’t translate into better outcomes. Spending spikes often add tools, not capability, leaving teams drowning in configuration work and false positives. The median midsize organization now juggles 76 separate security products—a number Aronashvili calls “crazy” because each one generates data that nobody has time to triage.
That overload feeds a deeper risk: more than half of the companies surveyed lack a tested business‑continuity plan, meaning a single ransomware strike could grind operations to a halt for days. Third‑party exposure is similarly under‑analyzed; simple scorecards don’t reveal how a supplier’s weakness could cascade into your own environment.
Aronashvili’s prescription is decidedly low‑glamour. Start by mapping assets, threats and likely attackers, then attach hard dollar values to each scenario so executives can see where every mitigation dollar goes. From there, prune redundant tools, enforce hygiene and elevate the CISO (or equivalent owner) to board‑level authority so security decisions align with business priorities.
The takeaway is clear: resilience isn’t about buying the next “magic bullet.” It’s about disciplined visibility, data‑driven prioritization and a culture that treats people and processes as seriously as technology.

Alan Shimel
Throughout his career spanning over 25 years in the IT industry, Alan Shimel has been at the forefront of leading technology change. From hosting and infrastructure, to security and now DevOps, Shimel is an industry leader whose opinions and views are widely sought after.
Alan’s entrepreneurial ventures have seen him found or co-found several technology related companies including TriStar Web, StillSecure, The CISO Group, MediaOps, Inc., DevOps.com and the DevOps Institute. He has also helped several companies grow from startup to public entities and beyond. He has held a variety of executive roles around Business and Corporate Development, Sales, Marketing, Product and Strategy.
Alan is also the founder of the Security Bloggers Network, the Security Bloggers Meetups and awards which run at various Security conferences and Security Boulevard.
Most recently Shimel saw the impact that DevOps and related technologies were going to have on the Software Development Lifecycle and the entire IT stack. He founded DevOps.com and then the DevOps Institute. DevOps.com is the leading destination for all things DevOps, as well as the producers of multiple DevOps events called DevOps Connect. DevOps Connect produces DevSecOps and Rugged DevOps tracks and events at leading security conferences such as RSA Conference, InfoSec Europe and InfoSec World. The DevOps Institute is the leading provider of DevOps education, training and certification.
Alan has a BA in Government and Politics from St Johns University, a JD from New York Law School and a lifetime of business experience.
His legal education, long experience in the field, and New York street smarts combine to form a unique personality that is always in demand to appear at conferences and events.
alan has 93 posts and counting.See all posts by alan
文章来源: https://securityboulevard.com/2025/07/bridging-the-visibility-gap-2025-global-cybersecurity-maturity-report/?utm_source=rss&utm_medium=rss&utm_campaign=bridging-the-visibility-gap-2025-global-cybersecurity-maturity-report
如有侵权请联系:admin#unsafe.sh