TENSION BETWEEN SECURITY AND PRODUCTIVITY Security and productivity are often diametrically opposed Security measures tend to drive up costs, slow down progress, and add steps Vendors often claim their security technology is seamless and invisible to users, but it requires installation, upgrades, and operation It is almost impossible to add security to an enterprise without impacting productivity in some way MAXIMUM ALLOWABLE RISK Cutting the security budget and balancing security capabilities against risks encompass the concept of maximum allowable risk (in other words, how much security risk is acceptable?). Enterprises use metrics (such as probes, attacks, and intrusions), in part, to show management how the security risks are being stopped/mitigated Metrics help everyone understand how close the enterprise is operating to a potential cybersecurity disaster. SECURITY EFFECTIVENESS OVER TIME An enterprise’s security posture effectiveness is not static and is subject to f...