In the News: Media Coverage and SBS Updates | SBS

Jon Waldman on Cyber as a Business Risk on Boss Today | SBS

Written by SBS CyberSecurity | Sep 29, 2026, 3:00:02 PM

What is the biggest difference between organizations that get shut down by a cyber incident and organizations that recover quickly? The answer has less to do with deploying advanced technology than with how leadership views and treats cyber risk. That was the through line in a new feature for Boss Today, where SBS CyberSecurity President and Co-Founder Jon Waldman joined a group of security leaders to explain why resilience is decided in the boardroom long before it is tested in the network.

Waldman pointed to one assumption that still shows up constantly in client conversations: the belief that being small makes you uninteresting to attackers.

"Cyber attacks are almost fully automated today. Organizations believe they're small, they're not interesting, nobody knows who they are, but bad guys don't care where you are or what you have until they're in your network," he said.

That pattern has a long history. Waldman pointed to Target as the example people still recognize: "Hackers didn't hack Target. What they hacked was a small mom-and-pop HVAC company in Pennsylvania that had access to one of Target's data centers, and that's how they got in." The same attack paths, he said, are very much applicable today.

Once size stops being protection, he explained, cybersecurity moves out of the server room and into the same category as every other business decision leadership already makes.

"It's not the IT guy's problem. Most organizations are in the business of risk management anyways; that's how you run a business," Waldman said. "We compare it to loan risk: A bank makes money by lending money, and you risk assess your loans based on a formula. There's no 100% risk mitigation in anything, but you want to make good bets."

The goal of those bets, he said, is minimizing the chance that a cyber attack shuts the organization down entirely.

He also noted how long unidentified risk can sit inside an environment before anyone notices.

"The mean time to detect and contain an incident is about 250 days on average; generally about 180 days to detect and around 60 days to contain," Waldman said. "The big question we always talk about is: If somebody was in your network, would you be able to tell? If the answer is 'I'm not sure' or 'probably not,' then you have a significant problem on your hands."

The feature also included perspectives from leaders at other security and advisory firms on intelligence-driven anticipation, framework adoption, and tabletop testing as paths to resilience.

For organizations that need executive-level security leadership without hiring a full-time CISO, SBS offers Virtual CISO services, pairing strategic direction, governance, and regulatory alignment with an objective view of where your real risk sits.

Read the full Boss Today feature to hear more from Waldman on why resilience starts with leadership.