I once met a student at a networking event who told me she'd been shut out of her own campus apartment for weeks because of a cyberattack.
She had everything ready, including her keycard, to move into her new apartment. When the day came, the door wouldn't open. It turned out the lock was tied to a system that had been shut down after a breach at her university. She couldn’t get into her own room for weeks.
Nothing was stolen from her. Yet, a breach somewhere else in the system left her, in practice, without a place to live.
I think about that story often. Because it captures the part of cybersecurity most people never picture.
We often imagine stolen data and locked screens instead of a locked front door, or some ordinary process we assumed would simply work grinding to a halt.
Coming into cybersecurity from a different perspective
Before my time at Aftra, I sold software that helped large companies find the best talent. My buyers were in HR, and they wanted to do more to improve the bottom line. They were always able to make a business case for the budget, and were looking for ways to improve efficiency.
Security has been a different world.
Now I am often talking to buyers who need to ask for a budget from someone above them who has no interest in cybersecurity at all. And many buyers are struggling to make the case for obtaining the budget they need.
That contrast taught me what I now believe sits underneath the whole field.
We keep filing cybersecurity in the wrong drawer.
When nobody owns cybersecurity
For years, it lived inside the IT department, near the passwords, printers and software updates. In many companies, cybersecurity still sits in that very same department.
A CEO once told me that security matters had nothing to do with them. Many leadership suites still think along the same line. But that’s the wrong lens to look at security.
If you’re in charge of keeping the business alive, then it IS your responsibility. When something goes wrong, it doesn’t land on the security team in the corner — it lands on you.
Cybersecurity has moved beyond what IT was built to handle a long time ago. It is a business risk now, and it belongs on the same table as every other business risk.
Too few leaders treat it that way.
You can see it in what we measure
The misfiling shows up most clearly in what companies choose to measure.
Think about how much a normal business tracks. We set goals, report, and review, on nearly everything. Yet, we skip including cybersecurity in what we measure.
My read is that no one is asking for the result or what a breach costs.
Leaders often don’t know what to ask beyond "that security thing is handled, right?" And if no one asks for the report, no one does the work to produce it.
But that is starting to shift.
There is a simpler way to look at cybersecurity
When I’m in a room with executives who don't work in security, I always lead with one number — a security score.
This same number measures how attractive you look to an attacker. The lower it is, the easier a target you are. A technical score becomes a business signal, and people who never wanted to talk about the plumbing of their systems start to lean in.
A number on its own says little. It needs context to mean anything to a leader: what it means for their business, industry, and the kind of information they hold.
There is a simpler test any leader can apply. Instead of asking "is that handled?", ask:
- Where do we stand in terms of our security?
- What would an incident cost us?
Those are business questions, and anyone in charge can ask them.
The five comfortable myths that get in the way
Once you treat cybersecurity as a business risk, a set of comfortable myths shows up. I meet the same ones again and again.
Myth 1: "We're already covered."
This is the most worrisome myth I keep hearing. Anyone doing this work in security knows you are never fully covered. There are criminal groups with a hundred times a company's resources, and they only need one way in. Doing your best is fair. Claiming you are untouchable is a different thing, and no one's setup earns it.
Myth 2: "We're compliant, so we're safe."
An attacker does not check whether you are compliant before deciding to come after you.
Compliance is a label that adds urgency, which helps, because new rules like the EU's NIS2 directive bring a fresh group of leaders to the table who used to look the other way.
But it doesn't change the underlying game, and it can become a place to hide.
You can tick every box and still be a step behind because real security asks for more than any rulebook spells out. So the question I would put to any board is simple:
Is your compliance score the same as your resilience score?
They are not the same thing.
Myth 3: "Attacks are so sophisticated now."
Yes and no. A great many of them are just logging in, using stolen or reused passwords. That points to a password problem or a habit problem more than a criminal mastermind.
If people are walking through the front door with a valid key, the answer is not more alerts and more dashboards. The real fix is in the unglamorous work. Know what you have, close what is open, and fix the basics first.
Myth 4: "We're too small to matter."
All it took was a quick scan and two minutes for me to find 30 open ports during a call with a prospect, and I’m not even a hacker.
Their IT provider was probably doing fine work elsewhere, but they were certainly unaware of these open doors.
The math is simple.
If I can find an open door in two minutes without being a hacker, what does someone find when they really go looking for it?
Myth 5: "We have multi-factor authentication on everything"
Are you sure everything is covered and nothing else is missed?
Cybersecurity will keep surprising us in different ways until we file it in the right drawer
I have let go of two beliefs since I started doing this.
The first is that you can ever be 100% secure, or that anyone can sell you 100% security. Businesses will always be a step behind. The honest stance is to accept that, do more than the rules require, and keep improving anyway.
The second is that cybersecurity is an IT problem and only an IT problem. It sits so far outside what the IT team was built to do that treating it as a technical footnote is how companies end up blindsided.
If I could change one thing, it is that leaders would stop asking "is that handled?" and start asking what they would ask about any other risk.
Aftra is built to give that clear overview across a wide field, instead of ten disconnected dashboards and a report pieced together by hand at midnight. For a business that is busy, stretched and short on budget, that is the whole point.
But the tool comes second. Your mindset around cybersecurity comes first.
While the student at the beginning of this story didn’t lose a file, she did lose access to her front door. Until we treat cybersecurity as the business risk it is, we’ll keep being surprised by where the damage turns up.