Cybersecurity management is becoming increasingly complex and costly
New requirements
Whereas in the past, system protection often boiled down to simple preventive measures, today's diverse and sophisticated threats require more elaborate strategies.
A trend observed in the choice of targets for cyber attackers, as explained by Baptiste David, Head of Market Strategy at Tenacy: " Not only do cybercriminals demonstrate a strong capacity for innovation, but they also seem to have fewer and fewer ethical boundaries. This is particularly evident when we see institutions such as the Red Cross and hospitals being attacked in the midst of the COVID-19 crisis. "
This paradigm shift requires companies to adapt. Ten to 15 years ago, companies took a minimalist approach, for example by installing antivirus software without any follow-up action, but this is no longer sufficient today. Antivirus software, among many other tools, now requires documentation and monitoring, and must be part of a broader cybersecurity strategy. Baptiste David emphasizes this point: " Compliance means doing, but it also means communicating, tracking, and documenting ."
In a context of labor shortages and under the weight of these regulatory constraints, managing cybersecurity seems to be a perilous task. At best, we get a fragmented view of the information system, and at worst, an increase in risks for the company.
An unnecessary accumulation of solutions
The first effect of poor management is to lead to significant investments in security solutions that, instead of providing adequate protection, are simply piled on top of each other.
A common scenario is investing in multiple anti-malware protection solutions in order to benefit from a double barrier, when in reality these tools could conflict with each other and reduce detection effectiveness.
Risks of non-compliance
Compliance requires documenting and maintaining the cybersecurity solutions used in the company. Without effective cyber governance, it is difficult to assess where an organization stands in terms of regulatory compliance.
This is particularly the case for operators of vital importance (OIVs), who are required to comply with the Military Programming Law (LPM) or face penalties. To this end, ANSSI and other government agencies may carry out security checks to verify that the rules are being properly applied. In the event of non-compliance, the operator concerned will receive an injunction to comply. If the breaches persist, this may result in financial penalties ranging from €150,000 to €750,000.
The prospect of losing business
In more extreme cases, non-compliance can lead to loss of certification and, by extension, loss of business partners. The ISO 27001 standard, for example, is required in the context of calls for tenders. Loss of such approvals can make it more difficult to acquire new customers while compromising existing business relationships.
Damage to reputation
Public fines or penalties also damage the company's reputation. Negative press coverage of cybersecurity issues can lead to a loss of trust among customers, partners, and investors. This is particularly true after a major data breach.
Excessive dependence on a single person
Companies tend to rely heavily on their CISO to manage the cybersecurity of their information systems. However, this dependence can be problematic if no monitoring mechanism is in place, leaving the company vulnerable when the CISO is absent or unavailable.
The importance of good management therefore lies in the implementation of a centralized monitoring tool such as Tenacy: since it does not depend on a single individual, it allows information to be shared within teams. This can translate into action plans, indicators, and a roadmap providing clear direction. If a CISO leaves the company or new members join the team, structured management facilitates the transfer of skills and the integration of these new resources.
How can we anticipate and limit management costs?
Define your goals and priorities
Each company, depending on its structure, mission, and priorities, has specific cybersecurity needs. For some, the priority may be focused on protecting workstations, while for others, it may be more about identity and access management.
Accurate identification of the organization's needs makes it possible to determine priority areas and allocate resources. Therefore, it is necessary for a CISO to ask themselves several questions.
- What are the risks associated with current information systems?
- How can the effectiveness of security measures be measured?
- What tools and indicators are available to monitor, detect, and respond to security incidents?
- Are employees sufficiently trained and aware of potential threats?
- How do security objectives align with the company's overall objectives?
Once the objectives have been established, they must be validated by management and the roles and responsibilities of each individual must be specified in an ISSP (Information Security Statement Policy).
Basing cyber management on facts
An information system is a constantly evolving environment that requires the CISO to adapt continuously.
As Baptiste David points out, " A CISO should not rely solely on instinct or conviction. While lessons learned from past experiences are important, it is essential to remember that what worked in the past in a given context may not always be transferable to another company."
It is therefore important to prioritize an approach based on facts and data.
If we take the example of an antivirus solution, simply purchasing it is not enough. You need to:
- ensure its deployment;
- monitor its effectiveness in real time;
- Establish clear indicators to assess functional coverage and the level of protection within the company, such as the number of attacks recorded or the number of malware programs blocked.
CSOs therefore need more than ever to use tools to manage cybersecurity actions within their companies. To this end, the Tenacy solution offers a set of features that enable security objectives and actions to be monitored in real time via dedicated dashboards.
Tenacy: Three Strategies for Controlling the Cost of Your Cybersecurity Management
The cost of poor governance is never reflected in a single budget line item. It is spread across manual consolidation hours, overlapping licenses, and unbudgeted audit catch-up work. A GRC platform addresses all three of these areas simultaneously because it processes security data just once for all of your entities and repositories.
Recoup the time you spend on manual consolidation
In organizations that manage their cybersecurity using Excel, simply aggregating metrics typically takes a full week each month—in other words, time spent collecting data without being able to focus on analyzing it. Tenacy automatically retrieves metrics from your technical sources via its native connectors, applies the same monitoring plans to each entity, and archives the results. At Tessi, the European leader in Business Process Services with a presence in fifteen countries, this streamlined process has freed up nearly 12 weeks per year previously spent on consolidation and reporting.
The most tangible impact is then measured in terms of headcount. Today, the group needs only two administrators to manage 53 entities, 22 monthly and quarterly metrics, and more than 500 corrective actions. Without this automation, the same workload would have required four additional people: in a market facing a cybersecurity skills shortage, this avoids recruitment costs and reduces the risk of turnover, as teams remain assigned to value-added tasks.
“If I had to do the same thing with personnel data and Excel files, I’d easily need four more people. And more importantly, I’d have much higher turnover because the teams would be doing nothing else.” Jérôme Farrouil, Group Director of Compliance, Risk, and Cybersecurity at Tessi
Focus on facts rather than piling up solutions
The “stacking of technical bricks” mentioned above rarely stems from an excess budget; rather, it results from a lack of visibility into what is already covered. By mapping your entities, your critical applications, and the actual level of security achieved for each, Tenacy provides you with a consolidated view that allows you to make investment decisions based on measurable data rather than intuition. Every control, every piece of evidence, and every action has an immediate impact on compliance scores and risk metrics, making your investment decisions justifiable to senior management.
The second source of savings lies in the overlap between standards. The frameworks supported by the platform (ISO 27001, NIS 2, DORA, SOC 2, PCI DSS, and 45 others) share a significant portion of their requirements, and a gap analysis between any two of them can be completed in just a few minutes. Jérôme Farrouil found more than 80% overlap between his internal security policy and a standard it was required to cover: these controls are performed once and leveraged multiple times, rather than being funded twice.
Secure Your Certifications and Avoid the Cost of Retakes
Losing a certification is costly, but so is getting back on track: a follow-up audit means a new round of preparation, mobilizing teams, and delaying business deadlines. Onet, a multiservice group with more than 80,000 employees, guided two of its business units to ISO 27001 certification in eleven months by centralizing its entire information security management system (ISMS) in Tenacy. During the feedback session, the auditor reclassified three major nonconformities as minor ones after reviewing the evidence, improvement plans, and recurring tasks available on the platform.
“Without Tenacy, we would have had to address the three major nonconformities and undergo another audit in three months. The tool was instrumental in proving to the auditor that our approach was structured and sustainable, even on such a tight timeline.” Hervé Comes, Group CISO at Onet
This traceability also addresses the reliance on a single person mentioned above. Logs, validations, and the history of metrics are stored within the platform, time-stamped and attributed, which allows an auditor to verify a process of continuous improvement and enables a new hire to take over management without starting from scratch. Cybersecurity knowledge is no longer stored in an individual’s files but becomes an organizational asset.
In conclusion
Keeping the cost of your cybersecurity management under control ultimately comes down to making decisions based on facts rather than impressions: that’s exactly what we invite you to see for yourself within your own organization by scheduling a demo.

.png)
.png)
