Managing security for today’s enterprises is an increasingly complex task. But being comfortable with failure is an important skill. Credit: Thinkstock Managing security for today’s enterprises is an increasingly complex task. Just look at the environment you work in: threats both inside and out, legacy technologies that may be exposing your systems through unknown or unpatched vulnerabilities, new technologies being rapidly adopted by the business (often without any input of the security team), and users, acknowledged as the greatest risk of all. It’s a Sisyphean task – you keep pushing that boulder up the hill, only to have it roll back down to the bottom where you must start all over again. But how best should you approach this complex risk environment?The threats you address today are a moving target, but so are the ways you mitigate those risks. In 2002, there were 730 some odd vendors offering security solutions to companies like yours. Today there are more than 1,600. So many options that most security teams struggle to even know where to begin. It’s made deciding which options are best for your business (pardon the continuing Greek mythological references) a Herculean task. The same holds true for best practices. At CSOonline we’ve been writing about best practices in security for more than 16 years, but the reality is that few best practices can be applied universally. What’s right for one company, is not always right for another.The greatest challenge, of course, is that no one can afford to hit the pause button, even if there were such a thing. Business is not going to come to a grinding halt while you figure out the right course of action, nor should it do so. This may sound odd, but security needs to act a little more like devops – it must be developing, deploying and managing solutions all at the same time. You’ve heard the analogy before, but you need to be building the car while it’s still driving down the road. And, you need to fail fast. In my many conversations with leading organizations I’ve heard the most successful of them say that one of the keys to their success has been a willingness, almost an eagerness, to fail fast. They embrace it, in fact, as a testament that they are building an effective security environment for their organizations. Failing fast allows them to learn from their mistakes, avoid future similar mistakes, and address risks far more quickly than the traditional model of solution deployment. Failing fast is also important because it can help an organization move from a tactical posture to a strategic one. Constantly putting out fires is a giant suck that eats time, budget and resources. We also know from our own research that businesses that can be more strategic about security reap significant benefits, including fewer security incidents, less downtime and fewer losses.Driving to reduced risks is, in and of itself, risky. But if you’re afraid to fail you’ll never learn what works best. Related content feature The CSO guide to top security conferences Tracking postponements, cancellations, and conferences gone virtual — CSO Online’s calendar of upcoming security conferences makes it easy to find the events that matter the most to you. By CSO Staff 30 Aug 2024 8 mins Technology Industry IT Skills Events news F5, Intel team up to boost AI delivery, security F5 and Intel are working together to combine security and traffic-management capabilities from F5’s NGINX Plus suite with Intel’s OpenVINO open-source toolkit for optimizing AI inference and Intel IPU hardware accelerators. By Michael Cooney 29 Aug 2024 1 min Network Security Artificial Intelligence Security news Cisco snaps up AI security player Robust Intelligence Plans call for integrating Robust Intelligence's AI security platform with Cisco Security Cloud to streamline threat protection for AI applications and models and increase visibility into AI traffic. By Ann Bednarz 28 Aug 2024 1 min Mergers and Acquisitions Artificial Intelligence Security feature What is OWASP? A standard bearer for better web application security The Open Web Application Security Project (OWASP) is an international nonprofit dedicated to providing free documentation, tools, videos, and forums for anyone interested in improving the security of their web applications. By Linda Rosencrance 28 Aug 2024 8 mins Internet Security IT Skills Application Security PODCASTS VIDEOS RESOURCES EVENTS SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe