CR ๐๐ป๐๐ฒ๐น๐น๐ถ๐ด๐ฒ๐ป๐ฐ๐ฒ | ๐ฃ๐ผ๐๐ #๐ฏ๐ฒ๐ณ
Last week, I asked a group of security leaders a question that changed the direction of the conversation:
“๐ช๐ต๐ฎ๐ ๐ถ๐ ๐๐ต๐ฒ ๐ผ๐น๐ฑ๐ฒ๐๐ ๐๐ป๐ฟ๐ฒ๐๐ผ๐น๐๐ฒ๐ฑ ๐ฟ๐ถ๐๐ธ ๐ถ๐ป ๐๐ผ๐๐ฟ ๐ผ๐ฟ๐ด๐ฎ๐ป๐ถ๐๐ฎ๐๐ถ๐ผ๐ป?”
Not the newest.
Not the most critical.
The oldest.
The room went quiet.
Because every organization has them.
The vulnerability that has been accepted for years.
The legacy application scheduled for replacement “next year.”
The unsupported system nobody wants to touch.
The control gap everyone knows about but nobody owns.
Over time, something interesting happens.
The longer a risk exists, the more comfortable people become with it.
It becomes familiar.
It gets mentioned less often.
It disappears from leadership discussions.
Eventually, it stops feeling like a risk at all.
Until an incident reminds everyone it still exists.
I’ve seen risks survive:
- Multiple CIOs
- Several CISOs
- Countless audits
- Technology refreshes
- Organizational restructures
Not because they were impossible to solve.
Because they became normalized.
And normalization is dangerous.
A new risk receives attention.
An old risk receives acceptance.
One practice I’ve found incredibly valuable is maintaining a simple metric:
๐ฅ๐ถ๐๐ธ ๐๐ด๐ฒ.
Not risk score.
Not risk severity.
Risk age.
Because when a medium-risk finding remains unresolved for five years, it often tells a more important story than a newly discovered high-risk vulnerability.
It reveals:
- Governance challenges
- Funding constraints
- Ownership gaps
- Operational dependencies
- Decision-making patterns
In other words, it reveals organizational reality.
The next time you review a risk register, don’t start with the highest score.
Start with the oldest entry.
Ask:
- Why does it still exist?
- Who owns it?
- What changed since it was identified?
- Would we accept this risk today if it were discovered for the first time?
The answers are often more valuable than the risk itself.
Because cybersecurity isn’t only about finding new risks.
It’s about understanding why known risks remain.
And sometimes, the most dangerous risks are the ones that have been around so long that nobody notices them anymore.