{"id":16646,"date":"2020-03-31T02:15:25","date_gmt":"2020-03-31T02:15:25","guid":{"rendered":"https:\/\/one.sightlinemg.com\/c4isrnet\/uncategorized\/2020\/03\/31\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\/"},"modified":"2026-08-08T18:04:11","modified_gmt":"2026-08-08T18:04:11","slug":"the-most-resilient-organizations-follow-outcome-based-cybersecurity","status":"publish","type":"post","link":"https:\/\/one.sightlinemg.com\/c4isrnet\/opinion\/2020\/03\/31\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\/","title":{"rendered":"The most resilient organizations follow outcome-based cybersecurity"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">As the cyber landscape changes, new threats arise, old threats evolve, and vulnerabilities are constantly putting companies and agencies at risk. The concept of \u201ccybersecurity\u201d has evolved from total defense, to layered defense, to cyber resiliency, based on risk analysis and a cold calculus of our own risk profiles. One way to approach this is through outcome-based cyber, an emergent practice I have helped shape. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Outcome-based cyber is a more holistic approach to cyber security than compliance-based cyber. Compliance-based cyber is a comforting checklist of determining a risk profile, setting controls, and measuring compliance to controls. That\u2019s become foundational to cyber security programs, but it\u2019s obviously not sufficient. Outcome-based cyber occurs when an organization is actively and continuously assessing their network and systems and reacting proactively and responsively to what is discovered. The U.S. government is now recognizing this in the Department of Defense\u2019s mandate to suppliers to transition to the new <a href=\"https:\/\/www.acq.osd.mil\/cmmc\/\">Cybersecurity Maturity Model Certification<\/a> (CMMC).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This evolution doesn\u2019t remove the need for classical cyber security controls. If an organization is not following some of the <a href=\"https:\/\/digitalguardian.com\/blog\/what-nist-sp-800-53-definition-and-tips-nist-sp-800-53-compliance\">NIST SP 800-53 compliant standards<\/a>, including configuration and privilege management, then that organization will not be secure, and won\u2019t meet CMMC guidance. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Outcome-based cyber measures the value and validity of an organization\u2019s cyber defenses and enterprise based on active analysis against the organization\u2019s total risk profile. Because each organization is different, outcome-based cyber is an organization\u2019s independent and strategic decision to implement. Most organizations with security operations centers already determine what they need to measure and what they need to react to, but those measures must evolve continuously.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Risks are discovered through analysis and red teams, a group from outside a network who come in as \u201cfriendly\u201d adversarial insiders. They use hacking tools, <a href=\"https:\/\/www.govtech.com\/security\/Social-Engineering-Scam-Hits-Washington-County-Government.html\">social engineering<\/a>, and physical access evaluations to assess targets\u2019 security profiles. Red teams deploy cyber scenarios and hopefully find vulnerabilities before they become issues.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">True outcome-based cybersecurity requires organizations to stay dynamic and reactive. The controls put in place on Day X may not apply on Day X+180, and must be re-examined to ensure they\u2019re addressing major new threat vectors. For instance, when data centers started deploying virtualization, threats started attacking hypervisors, and new policies and technologies appeared to defend against these attacks. The same is true with the latest Intel and AMD processor vulnerabilities, wired into the very hardware of the CPUs in our systems. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As researchers discover new vulnerabilities, leadership has to determine the risk these pose to the organization. If a CPU vulnerability can be accessed through a Web page drive-by attack, it\u2019s high priority and has to be patched; if a hypervisor vulnerability can only be executed by people with access to certain enterprise resources, adding monitoring to those resources may be the appropriate response.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The key to outcome-based cyber is the process of risk analysis. For example, what are the odds that a malicious actor can get to one server that houses critical business information? It might be low. Add 500 people with electronic access to that same server and the risk goes up significantly. Organizations must assess the cost of mitigating the risk against the cost and impact of the outcome if not responding to a vulnerability. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Outcome-based cyber is about continuously evaluating an organizations\u2019 status and the risk environment. Last January, the U.S. <a href=\"https:\/\/www.us-cert.gov\/ncas\/current-activity\/2020\/01\/08\/mozilla-patches-critical-vulnerability\">Cybersecurity and Infrastructure Security Agency<\/a> sent a notification about Mozilla\u2019s <a href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2020\/01\/18\/us-government-confirms-critical-zero-day-security-warning-for-windows-users\/#2f63694a3212\">Firefox zero-day vulnerability<\/a> that included the severity, commonality, and the fact it was already used in the wild by malicious actors. Through threat intelligence and information sharing, companies were able to identify the flaw, understand it as they assessed risk, and install <a href=\"https:\/\/www.welivesecurity.com\/2020\/01\/09\/mozilla-rushes-patch-firefox-zero-day\/\">patch<\/a>es.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Vulnerabilities, like that Firefox bug, must be patched, while other issues might be accepted, temporarily, as part of a risk analysis, and still others are addressed through installing compensating controls around them. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Security operations centers are responsible for analyzing new and emerging threats and building more powerful rules. Companies should be taking that information and sharing it both for internal and external partner organization use, including the Department of Defense Cyber Crime Center (<a href=\"https:\/\/www.dc3.mil\/\">DC3<\/a>) and <a href=\"https:\/\/www.it-isac.org\/\">IT-ISAC<\/a>. This will lead to increased global cyber resiliency, a topic that the Cyberspace Solarium Commission\u2019s <a href=\"https:\/\/www.solarium.gov\/report\">report<\/a> addresses. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Department of Defense\u2019s CMMC will be the new standard for doing work with the Pentagon, and it mandates an outcome-based cyber approach. Beyond the <a href=\"https:\/\/www.acq.osd.mil\/cmmc\/docs\/CMMC_Model_Main_20200203.pdf\">basic levels<\/a>, and entity must be capable of identifying and intercepting advanced per-system threat level cyberattacks, and assessing risks to emergent and anticipated threats. This is one of the purposes of outcome-based cyber. It\u2019s a philosophy, not a toolset \u2013 a philosophy that balances risk to the enterprise, the company, and the community. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><i>John Cosby is director of solution architects within BAE Systems\u2019 Intelligence &amp; Security sector.<\/i><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Compliance-based cyber is a comforting checklist of determining a risk profile, setting controls, and measuring compliance to controls. That\u2019s become foundational to cyber security programs, but it\u2019s obviously not sufficient.<\/p>\n","protected":false},"author":7,"featured_media":30842,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_canonical":"","_acf":"","_yoast_wpseo_primary_category":24,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","_smg_distribution_targets":[]},"categories":[106,29,32,24],"tags":[],"coauthors":[7541],"class_list":["post-16646","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-daily-brief","category-home","category-newsletters","category-opinion"],"acf":{"subheadline":"","legacy_arc_id":"YDNUL7DIYZEKFBJQM7ICH7V4J4","arc_canonical_url":"\/opinion\/2020\/03\/31\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\/","remove_feature_photo":false,"is_sponsored":false,"subtype":"","redirect_url":"","disable_inline_ads":false,"native_logo_pretext":"Presented By:"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.0 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>The most resilient organizations follow outcome-based cybersecurity - C4ISRNet<\/title>\n<meta name=\"description\" content=\"Compliance-based cyber is a comforting checklist of determining a risk profile, setting controls, and measuring compliance to controls. That\u2019s become foundational to cyber security programs, but it\u2019s obviously not sufficient.\" \/>\n<meta name=\"robots\" content=\"noindex, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The most resilient organizations follow outcome-based cybersecurity\" \/>\n<meta property=\"og:description\" content=\"Compliance-based cyber is a comforting checklist of determining a risk profile, setting controls, and measuring compliance to controls. That\u2019s become foundational to cyber security programs, but it\u2019s obviously not sufficient.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/one.sightlinemg.com\/c4isrnet\/opinion\/2020\/03\/31\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\/\" \/>\n<meta property=\"og:site_name\" content=\"C4ISRNet\" \/>\n<meta property=\"article:published_time\" content=\"2020-03-31T02:15:25+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-08T18:04:11+00:00\" \/>\n<meta name=\"author\" content=\"John Cosby\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"John Cosby\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\n\t    \"@context\": \"https:\\\/\\\/schema.org\",\n\t    \"@graph\": [\n\t        {\n\t            \"@type\": \"Article\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/opinion\\\/2020\\\/03\\\/31\\\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\\\/#article\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/opinion\\\/2020\\\/03\\\/31\\\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\\\/\"\n\t            },\n\t            \"author\": {\n\t                \"name\": \"migration\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\"\n\t            },\n\t            \"headline\": \"The most resilient organizations follow outcome-based cybersecurity\",\n\t            \"datePublished\": \"2020-03-31T02:15:25+00:00\",\n\t            \"dateModified\": \"2026-08-08T18:04:11+00:00\",\n\t            \"mainEntityOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/opinion\\\/2020\\\/03\\\/31\\\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\\\/\"\n\t            },\n\t            \"wordCount\": 809,\n\t            \"commentCount\": 0,\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#organization\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/opinion\\\/2020\\\/03\\\/31\\\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/GettyImages-890155054.jpg.jpg\",\n\t            \"articleSection\": [\n\t                \"Daily Brief\",\n\t                \"Home\",\n\t                \"Newsletters\",\n\t                \"Opinion\"\n\t            ],\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"CommentAction\",\n\t                    \"name\": \"Comment\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/opinion\\\/2020\\\/03\\\/31\\\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\\\/#respond\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebPage\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/opinion\\\/2020\\\/03\\\/31\\\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\\\/\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/opinion\\\/2020\\\/03\\\/31\\\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\\\/\",\n\t            \"name\": \"The most resilient organizations follow outcome-based cybersecurity - C4ISRNet\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#website\"\n\t            },\n\t            \"primaryImageOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/opinion\\\/2020\\\/03\\\/31\\\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\\\/#primaryimage\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/opinion\\\/2020\\\/03\\\/31\\\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/GettyImages-890155054.jpg.jpg\",\n\t            \"datePublished\": \"2020-03-31T02:15:25+00:00\",\n\t            \"dateModified\": \"2026-08-08T18:04:11+00:00\",\n\t            \"description\": \"Compliance-based cyber is a comforting checklist of determining a risk profile, setting controls, and measuring compliance to controls. That\u2019s become foundational to cyber security programs, but it\u2019s obviously not sufficient.\",\n\t            \"breadcrumb\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/opinion\\\/2020\\\/03\\\/31\\\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\\\/#breadcrumb\"\n\t            },\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"ReadAction\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/opinion\\\/2020\\\/03\\\/31\\\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\\\/\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"ImageObject\",\n\t            \"inLanguage\": \"en-US\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/opinion\\\/2020\\\/03\\\/31\\\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\\\/#primaryimage\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/GettyImages-890155054.jpg.jpg\",\n\t            \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/GettyImages-890155054.jpg.jpg\"\n\t        },\n\t        {\n\t            \"@type\": \"BreadcrumbList\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/opinion\\\/2020\\\/03\\\/31\\\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\\\/#breadcrumb\",\n\t            \"itemListElement\": [\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 1,\n\t                    \"name\": \"Home\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/\",\n\t                    \"ad_zone\": \"home\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 2,\n\t                    \"name\": \"Opinion\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/opinion\\\/\",\n\t                    \"ad_zone\": \"opinion\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 3,\n\t                    \"name\": \"The most resilient organizations follow outcome-based cybersecurity\"\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebSite\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#website\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/\",\n\t            \"name\": \"C4ISRNet\",\n\t            \"description\": \"Media for the Intelligence-Age Military | C4ISRNET\",\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#organization\"\n\t            },\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"SearchAction\",\n\t                    \"target\": {\n\t                        \"@type\": \"EntryPoint\",\n\t                        \"urlTemplate\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/?s={search_term_string}\"\n\t                    },\n\t                    \"query-input\": {\n\t                        \"@type\": \"PropertyValueSpecification\",\n\t                        \"valueRequired\": true,\n\t                        \"valueName\": \"search_term_string\"\n\t                    }\n\t                }\n\t            ],\n\t            \"inLanguage\": \"en-US\"\n\t        },\n\t        {\n\t            \"@type\": \"Organization\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#organization\",\n\t            \"name\": \"C4ISRNet\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/\",\n\t            \"logo\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/logo\\\/image\\\/\",\n\t                \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/c4isrnet-logo-white.png\",\n\t                \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/c4isrnet-logo-white.png\",\n\t                \"caption\": \"C4ISRNet\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/logo\\\/image\\\/\"\n\t            }\n\t        },\n\t        {\n\t            \"@type\": \"Person\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\",\n\t            \"name\": \"migration\",\n\t            \"image\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec\",\n\t                \"url\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"contentUrl\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"caption\": \"migration\"\n\t            },\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/author\\\/migration\\\/\"\n\t        }\n\t    ]\n\t}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"The most resilient organizations follow outcome-based cybersecurity - C4ISRNet","description":"Compliance-based cyber is a comforting checklist of determining a risk profile, setting controls, and measuring compliance to controls. That\u2019s become foundational to cyber security programs, but it\u2019s obviously not sufficient.","robots":{"index":"noindex","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"The most resilient organizations follow outcome-based cybersecurity","og_description":"Compliance-based cyber is a comforting checklist of determining a risk profile, setting controls, and measuring compliance to controls. That\u2019s become foundational to cyber security programs, but it\u2019s obviously not sufficient.","og_url":"https:\/\/one.sightlinemg.com\/c4isrnet\/opinion\/2020\/03\/31\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\/","og_site_name":"C4ISRNet","article_published_time":"2020-03-31T02:15:25+00:00","article_modified_time":"2026-08-08T18:04:11+00:00","author":"John Cosby","twitter_card":"summary_large_image","twitter_misc":{"Written by":"John Cosby","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/opinion\/2020\/03\/31\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\/#article","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/opinion\/2020\/03\/31\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\/"},"author":{"name":"migration","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1"},"headline":"The most resilient organizations follow outcome-based cybersecurity","datePublished":"2020-03-31T02:15:25+00:00","dateModified":"2026-08-08T18:04:11+00:00","mainEntityOfPage":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/opinion\/2020\/03\/31\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\/"},"wordCount":809,"commentCount":0,"publisher":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#organization"},"image":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/opinion\/2020\/03\/31\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyImages-890155054.jpg.jpg","articleSection":["Daily Brief","Home","Newsletters","Opinion"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/one.sightlinemg.com\/c4isrnet\/opinion\/2020\/03\/31\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/opinion\/2020\/03\/31\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\/","url":"https:\/\/one.sightlinemg.com\/c4isrnet\/opinion\/2020\/03\/31\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\/","name":"The most resilient organizations follow outcome-based cybersecurity - C4ISRNet","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#website"},"primaryImageOfPage":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/opinion\/2020\/03\/31\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\/#primaryimage"},"image":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/opinion\/2020\/03\/31\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyImages-890155054.jpg.jpg","datePublished":"2020-03-31T02:15:25+00:00","dateModified":"2026-08-08T18:04:11+00:00","description":"Compliance-based cyber is a comforting checklist of determining a risk profile, setting controls, and measuring compliance to controls. That\u2019s become foundational to cyber security programs, but it\u2019s obviously not sufficient.","breadcrumb":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/opinion\/2020\/03\/31\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/one.sightlinemg.com\/c4isrnet\/opinion\/2020\/03\/31\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/opinion\/2020\/03\/31\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\/#primaryimage","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyImages-890155054.jpg.jpg","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyImages-890155054.jpg.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/opinion\/2020\/03\/31\/the-most-resilient-organizations-follow-outcome-based-cybersecurity\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/one.sightlinemg.com\/c4isrnet\/","ad_zone":"home"},{"@type":"ListItem","position":2,"name":"Opinion","item":"https:\/\/one.sightlinemg.com\/c4isrnet\/opinion\/","ad_zone":"opinion"},{"@type":"ListItem","position":3,"name":"The most resilient organizations follow outcome-based cybersecurity"}]},{"@type":"WebSite","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#website","url":"https:\/\/one.sightlinemg.com\/c4isrnet\/","name":"C4ISRNet","description":"Media for the Intelligence-Age Military | C4ISRNET","publisher":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/one.sightlinemg.com\/c4isrnet\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#organization","name":"C4ISRNet","url":"https:\/\/one.sightlinemg.com\/c4isrnet\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#\/schema\/logo\/image\/","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/c4isrnet-logo-white.png","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/c4isrnet-logo-white.png","caption":"C4ISRNet"},"image":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1","name":"migration","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec","url":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","caption":"migration"},"url":"https:\/\/one.sightlinemg.com\/c4isrnet\/author\/migration\/"}]}},"jetpack_sharing_enabled":true,"distributor_meta":false,"distributor_terms":false,"distributor_media":false,"distributor_original_site_name":"C4ISRNet","distributor_original_site_url":"https:\/\/one.sightlinemg.com\/c4isrnet","push-errors":false,"jetpack_featured_media_url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyImages-890155054.jpg.jpg","_links":{"self":[{"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts\/16646","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/comments?post=16646"}],"version-history":[{"count":1,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts\/16646\/revisions"}],"predecessor-version":[{"id":16654,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts\/16646\/revisions\/16654"}],"wp:attachment":[{"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/media?parent=16646"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/categories?post=16646"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/tags?post=16646"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/coauthors?post=16646"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}