Global Food Manufacturer · Risk

Turning vulnerability counts into $46M of risk removed

Prioritizing remediation by severity score is defensible, auditable, and quietly wrong. Re-sequencing the same work around business impact took roughly $46M of quantified annual exposure off the books — with the same team and the same budget.

Organization
Global food production and manufacturing company — $14B revenue, 50,000+ employees, worldwide manufacturing and distribution
Role
Director of Cybersecurity (Deputy CISO)
Scope
Enterprise cyber risk, governance, architecture direction, $24M annual security budget
Outcome
~$46M reduction in annual quantified cyber risk exposure
Annual security budget $24M Quantified annual risk removed ~$46M ≈ 1.9× the budget

Quantified annual exposure removed, set against the annual security budget for the same period.

The situation

The remediation queue was being worked in severity order. Criticals first, then highs, then the rest — the default behavior of essentially every vulnerability management program, and the thing every scanner report is designed to encourage.

The problem is that severity score measures the technical characteristics of a flaw. It does not know which systems run the plants, which ones hold customer and employee data, which ones would stop a shipment, or which ones an attacker could actually reach. In a global manufacturing environment those distinctions are the entire risk picture. A critical-rated flaw on an isolated internal system and a medium-rated flaw on an internet-facing system adjacent to production are not the same problem, and treating them as a queue sorted by the same number means the team spends its capacity in the wrong place while remaining perfectly compliant with its own process.

Meanwhile the executive reporting suffered from the same defect. “We closed 3,000 findings this quarter” is a number an executive committee cannot do anything with. It does not say whether the company is safer, and it gives no basis for deciding whether the next dollar should go to security or somewhere else.

What I did

Made the exposure legible before trying to reduce it

The first work was not remediation. It was building a quantified view of enterprise cyber risk — expressing exposure as annualized loss expectancy tied to specific business processes rather than as a count of findings. That meant mapping the technical estate to what it actually supports: production and plant operations, the supply chain, financial systems, customer and employee data, and the systems whose loss would show up in a quarterly result.

My finance background is the reason this was possible to defend. A risk model that a CFO cannot interrogate is a risk model that will not survive its first real challenge. The assumptions, the loss magnitudes, the frequency estimates, and the sensitivity of the output to each of them all had to be explicit enough to argue about.

Re-sequenced the work around impact, not score

With exposure expressed in dollars, the prioritization question changed shape. It was no longer “what is the most severe finding?” but “which unit of remediation effort removes the most quantified exposure?” Those two questions produce very different queues.

Some of the highest-value work turned out to be unglamorous: segmentation and access changes around a handful of business-critical environments, retiring a small number of systems nobody wanted to own, and closing exposure paths that never ranked highly on any individual scan because the risk was in the combination rather than in any single finding. Some highly-rated findings were consciously deferred, documented, and accepted — which is a defensible position only when you can show the math on what you did instead.

Rebuilt the reporting around the same model

The Executive Cybersecurity Committee and board reporting was rewritten to lead with exposure and its movement over time, with control performance and operational metrics supporting it rather than substituting for it. KPIs and SLAs were set against that model so that program performance, spend, and risk were being measured on one consistent basis.

This is the part that compounds. Once an executive team can see exposure move in response to funded work, security stops being a cost center that reports activity and becomes a function that reports return.

Outcome

  • Approximately $46M reduction in annual quantified cyber risk exposure, achieved by re-sequencing existing capacity rather than adding headcount.
  • A risk model that held up under external scrutiny — the same quantified view supported audit documentation, cyber-insurance underwriting, and regulator conversations during IPO readiness.
  • Executive reporting that produces decisions: funding conversations now start from exposure and expected reduction rather than from finding counts.
  • KPIs and SLAs measuring risk, spend, and program performance on a single consistent basis.

What transfers

The sequencing insight is portable to any organization with more remediation demand than capacity — which is all of them. The prerequisite is a quantified exposure model that the business side of the house can argue with. Without that, “prioritize by business impact” is just a slogan, and the team quietly reverts to sorting by severity because at least that number is objective.

Related