You Can't Fix Every Cybersecurity Risk at Once. So What Comes First?

Keep up with IT Club
Add IT Club as a preferred source in Google Search.
SMEs rarely lack cybersecurity recommendations; they lack unlimited budget, time and attention. IT Club explains how to rank security improvements by business impact, likelihood, dependencies, cost and the difference between what belongs in the Now, Next and Later columns.
Most businesses do not have a shortage of cybersecurity recommendations. They have the opposite problem. There are usually more sensible improvements than there is budget, time, management attention or technical capacity.
An SME may be told to improve MFA, replace old hardware, patch vulnerabilities, deploy endpoint detection, improve backups, tighten administrator access, review suppliers, strengthen email security, run awareness training, complete Cyber Essentials, write an incident-response plan and improve monitoring.
All of those may be worthwhile. That does not mean they can all happen this month, or that they all reduce meaningful business risk by the same amount.
The useful question is not “what could we improve?”
Ask instead: what needs doing now, what should come next and what can wait? Cybersecurity should support business decisions, not compete with them blindly.
Security is competing for the same resources as everything else
Cybersecurity does not sit outside the business. Its recommendations compete for the same money, people and attention as new systems, recruitment, equipment, sales, marketing, compliance, customer projects and staff development.
That wider context does not make security optional. It makes prioritisation necessary. A security recommendation without business context is not yet a business recommendation.
For example, replacing an unsupported internet-facing firewall may need to happen before a new reporting project, even if the reporting project has a clearer business case. Equally, an expensive monitoring platform may not be the best next investment if the business has not enabled MFA or tested its backups.
Start with what happens if you do nothing
For every proposed improvement, ask what would actually happen if the business left the issue unresolved for another month, quarter or year.
- Could trading stop?
- Could customer, employee or commercially sensitive data be exposed?
- Could money be stolen or payments redirected?
- Could an attacker gain administrator access?
- Could the problem spread across the business or into suppliers?
- Could recovery take days rather than hours?
- Could there be a contractual, regulatory or insurance consequence?
This is not an argument for ignoring technical findings. It is a reminder that the finding needs to be translated into a consequence the business can understand and compare with other decisions.
How likely is the problem?
Risk is not only impact. Likelihood matters too. A serious weakness on a system exposed directly to the internet may deserve a different response from a similar technical issue on an isolated internal device with strong access controls.
Ask questions such as:
- Is the system or account exposed to the internet?
- Is the vulnerability actively exploited or being probed?
- Is the account frequently targeted by phishing or fraud?
- Does exploitation require physical access or several unlikely conditions?
- Is another control already reducing the risk?
- Would a compromise give an attacker a route to more important systems?
Avoid security theatre. A scanner label, a supplier warning or a product salesperson's urgency can all be useful signals, but none of them is a complete risk assessment on its own.
Translate technical risk into business impact
A recommendation becomes easier to rank when somebody can explain the business consequence in plain language.
| Technical issue | Possible business consequence |
|---|---|
| No MFA on Microsoft 365 | A stolen password may give an attacker access to email, allow impersonation, expose files or help them target customers and suppliers. |
| Unsupported internet-facing firewall | The business may be relying on a perimeter device that no longer receives fixes for newly discovered weaknesses. |
| Backups have never been restored in a test | The business may discover during an incident that recovery is slower, less complete or impossible. |
| Uncontrolled administrator accounts | A compromised privileged account may let an attacker change security settings, create persistence or reach many systems at once. |
| No review of a critical supplier | An outage or breach at a platform holding important data may interrupt work without a clear recovery or communication route. |
If nobody can explain the business consequence, it is difficult to prioritise the technical recommendation properly. The answer may still be to investigate, but not necessarily to buy the proposed solution immediately.
What does the fix really cost?
Do not measure only the invoice. The real cost may include staff time, downtime, training, operational disruption, complexity, ongoing licences, support overhead and user inconvenience.
A control can be technically excellent but commercially disproportionate. Equally, some high-value improvements are cheap or mainly require disciplined administration.
- Enabling MFA for the right accounts
- Removing unused administrator accounts
- Updating unsupported software
- Testing a backup restore
- Disabling unused remote access
- Reviewing who can approve payments or change bank details
The aim is not to find the cheapest security work. It is to find the highest practical reduction in meaningful risk for the resources available.
Dependencies can change the order
Security work is not a menu where every item can be selected independently. Some improvements depend on foundations being in place first.
There may be little value in investing in sophisticated monitoring if MFA is missing, devices are unsupported, administrator accounts are uncontrolled, backups are unreliable or basic patching is poor. Monitoring may tell you that something went wrong, but it cannot restore a system or remove an attacker from an account by itself.
Advanced identity controls may also depend on correct licensing, clean user accounts, appropriate device management and known administrator roles. Building those foundations first can make later controls more effective and less disruptive.
Do the foundational work before adding layers of sophistication
A security roadmap should show dependencies. Otherwise the business can spend heavily on a visible tool while leaving a simpler control gap underneath it.
Use Now / Next / Later
The IT Club prioritisation model is deliberately simple. It is a management framework, not a formal quantitative risk-scoring methodology.
NOW
Now is for work where the risk is credible, the potential impact is serious, the exposure is current, a basic control is missing or delay materially increases the risk.
- Missing MFA on important accounts
- Unsupported internet-facing systems
- Critical known vulnerabilities with credible exposure
- Broken or inaccessible backups
- Compromised accounts
- Uncontrolled administrator access
These are examples, not automatic answers. A business should investigate the actual environment, exposure and existing controls before declaring any item urgent.
NEXT
Next is for improvements that materially reduce risk but can be planned, funded and assigned without displacing a more urgent weakness.
- Better endpoint detection and response
- Improved logging and alert review
- Conditional Access and stronger identity policies
- Supplier and data-flow reviews
- Security awareness improvements
- Formal incident-response planning
LATER
Later is for good-practice improvements and optimisation where existing controls already reduce the risk, the impact is limited, the work depends on another project, the cost currently outweighs the benefit or the issue can be monitored safely.
Later does not mean never. Put the work on the roadmap, record why it is waiting, set a review date and move it forward if the environment changes.
A practical priority test
- 1What happens if we do nothing?
- 2How likely is that outcome?
- 3What would it cost the business?
- 4Is another control already reducing the risk?
- 5What does the fix cost?
- 6What disruption does the fix create?
- 7Does other work need to happen first?
- 8Does this belong in Now, Next or Later?
High impact + high likelihood + weak existing controls usually means an item should move up the list. This is a prompt for better management discussion, not a pretend precision score.
Some things should jump the queue
A security plan should not be fixed forever. Certain events can immediately change priority:
- A vulnerability becomes actively exploited
- An account is compromised
- A supplier suffers a breach
- Cyber-insurance requirements change
- A customer contract introduces a new requirement
- A system reaches end of support
- The business changes how it works
- New sensitive data is introduced
Review the Now, Next and Later columns when the business acquires a system, changes suppliers, opens a new location, introduces sensitive data or experiences a security event. Priorities are part of an operating process, not a document written once and forgotten.
Do not let compliance become the entire roadmap
Frameworks such as Cyber Essentials can provide useful structure and help a business establish a baseline. They can also support customer conversations and make common controls easier to explain.
But compliance should not replace judgement. A business can meet a framework requirement and still have risks that matter, such as a critical supplier dependency, an untested recovery process or an account that can approve payments. Equally, a lower-risk issue outside a framework should not automatically jump ahead of something that could stop the business trading.
Use standards to create structure. Use business risk to create priority.
Certification can be valuable, but it is not a guarantee that every meaningful risk has been removed or that every future improvement has the same urgency.
Ask your IT or security provider to rank the work
If a provider gives you a list of 25 improvements, ask a direct question:
If we can only do three this quarter, which three would you choose?
Then ask why.
A useful provider should be able to explain:
- What risk each improvement reduces
- Why it matters now
- What happens if it waits
- What dependencies must be resolved first
- What it costs, including disruption and ongoing licences
- How much risk remains afterwards
If every recommendation is described as urgent, the prioritisation has failed. A useful adviser helps you choose, not just identify more things to buy.
Related Reading
Too many security recommendations?
If you are looking at a vulnerability report, Cyber Essentials remediation list or pile of security recommendations and cannot tell what genuinely needs attention first, ask the IT Club Advisor. One straightforward IT question. Independent guidance without the sales pitch.
The IT Club view
Cybersecurity matters. But the objective is not to build the most secure organisation theoretically possible regardless of cost. The objective is to help the business operate with risks it understands, controls, monitors and can afford.
There will always be another security improvement available. Good management is deciding which one creates the greatest reduction in meaningful risk today, while being honest about what is deliberately waiting.
You do not need to fix everything at once.
You do need to know what you are deliberately leaving until later — and why.
Plain-English Takeaway
You do not need to fix every cybersecurity risk at once. Rank each improvement by what happens if it is left unresolved, how likely that outcome is, the controls already in place, the cost and disruption of the fix, and any dependencies. Then put the work in Now, Next or Later — and keep Later visible rather than treating it as never.
Frequently asked questions
How should a small business prioritise cybersecurity improvements?
Start with the business consequence of doing nothing, then consider likelihood, existing controls, cost, disruption and dependencies. Missing MFA, unsupported internet-facing systems, compromised accounts and unreliable backups may deserve early attention, but context matters and no list is automatically urgent in every environment.
Should every critical vulnerability be fixed immediately?
A critical label should trigger investigation, not remove judgement. Check whether the affected system is exposed, whether the vulnerability is actively exploited, whether another control reduces the risk and what the business impact would be. An exposed, actively exploited weakness may need immediate action; an isolated system with compensating controls may have a different order.
What belongs in a cybersecurity Now, Next and Later plan?
Now is for credible current risks where delay could materially increase harm. Next is for important improvements that can be planned and funded. Later is for good-practice or optimisation work whose impact is limited, depends on another project or currently costs more than the risk reduction it provides. Later should stay on the roadmap and be reviewed.
What should I ask an IT provider about a long security recommendations list?
Ask which three actions they would choose if the business could only do three this quarter, what risk each reduces, why it matters now, what happens if it waits, what it depends on, what it costs and how much risk remains afterwards. If every recommendation is called urgent, the prioritisation has not been explained properly.
Is Cyber Essentials enough to set my security priorities?
Cyber Essentials can provide useful structure around common technical controls, but it should not replace business judgement. A business can meet a framework requirement and still have a serious supplier, recovery or account risk. Use standards to create a baseline, then use business impact and exposure to decide the order of work.
Related Articles
Could Your Business Refuse a Ransom Demand?
Stadler Rail refused a multimillion-dollar ransom demand after a contained cyberattack. The real lesson is whether your business has enough resilience to do the same.
Read articleAI Agents Are Starting to Hack Without Waiting for Humans
Attackers are beginning to use AI agents to investigate systems, change tactics and work in parallel. Here is what that means for ordinary businesses.
Read articleOne SaaS Breach Can Become Hundreds of Data Incidents
A breach at one cloud supplier can create data incidents across hundreds of customers. Here is what the Beacon CRM incident teaches businesses about supplier risk.
Read article