Back Issues This Week → Current Issue → Popular →

All issuesVolume 330, Issue 1IT NewsSecurity

Cybersecurity Signals: Connecting Controls And Incident Outcomes

Help Net Security, Monday, September 1st, 2025

There is constant pressure on security leaders to decide which controls deserve the most attention and budget. A new study offers evidence on which measures are most closely linked to lower breach risk and how organizations should think about deploying them.

Marsh McLennan's Cyber Risk Intelligence Center (CRIC) analyzed thousands of organizations' responses to its Cyber Self-Assessment and compared them with claims data. The findings highlight which controls matter most for lowering breach likelihood.

Incident response planning

Incident response planning ranked near the top of the study's findings. Organizations that conduct tabletop exercises and red-team tests consistently showed better outcomes than those that did not. CRIC notes that response planning may have secondary benefits, since the process of running exercises often drives investment in other parts of the program.

more →  ·  More from Security →