Cyber Security
Your Cybersecurity Roadmap Shouldn't Start With a Shopping List
Buying more security products is not the same as having a security strategy. The better question is: what are the biggest risks to this business, and what should we fix first?
11 min read — Altitude IT Security Team
Cybersecurity products are easy to buy.
Businesses can add endpoint detection, email security, backup, vulnerability scanning, security awareness training, Conditional Access, monitoring, SOC services, password tools and DNS filtering.
Many of those can be valuable.
But buying more security technology is not the same as having a security strategy.
The better starting question is:
What are the biggest risks to this business, and what should we fix first?
A useful cybersecurity roadmap should give the business clarity. Not simply a longer shopping list.
Start with the technology estate
Before recommending new security tools, the first step is to understand what already exists.
A modern business estate may include users, laptops and desktops, servers, Microsoft 365, cloud applications, firewalls, VPNs, remote-access tools, mobile devices, CRM systems, accounting platforms, HR systems, backups, supplier portals and application integrations.
If the estate is not understood, security recommendations can easily solve the wrong problem.
A business that has grown organically over ten years may have cloud services that were useful once and are now forgotten, supplier portals that still hold customer data, integrations running with credentials that belong to staff who have since left, and backup jobs that report success but have never been tested. A technology estate review turns that organically grown picture into something owned and understood.
You cannot prioritise risk properly if you do not know what you are protecting.
Establish the foundations first
Before adding advanced controls, check whether the basic security foundations are in place.
Those foundations include: supported operating systems; security patching; multi-factor authentication; appropriate administrator access; endpoint protection; secure firewalls; reliable backups; proper leaver processes; and secure remote access.
These connect naturally to Cyber Essentials principles. They represent the controls that remove the most common attack routes and that are expected by cyber insurers, regulated clients and government supply chains.
The important point is that sophisticated security layers cannot compensate reliably for weak foundations.
There is little value spending heavily on advanced monitoring if administrator accounts have no MFA and backups have never been tested. The advanced monitoring may catch an attacker who has already moved freely through the estate because the basic controls were missing.
Do the boring things well before buying the clever things.
Not every scanner finding is a business priority
Businesses increasingly receive output from vulnerability scanners, Microsoft Secure Score, security assessments, cyber insurance questionnaires, penetration tests and compliance reviews.
These are useful inputs.
But they are not automatically a prioritised roadmap.
A finding labelled "Critical" does not necessarily mean it is the most important business issue. Context matters.
Before deciding how urgently to act on any finding, it is worth asking: is the system internet-facing? Is exploitation realistic given the business's environment? Is another control already mitigating the risk? What data is involved? Could exploitation stop the business from operating? What does remediation actually require?
A critical vulnerability in an internal test system with no sensitive data and no internet exposure is a very different problem to a critical vulnerability in an internet-facing service handling customer payment information.
Severity is useful. Business consequence is more useful.
Translate technical issues into business consequences
Good security advice should explain why something matters in terms the business understands, not just technical descriptions.
Consider three common examples:
Missing MFA. The technical description is that a Microsoft 365 account is protected only by a password. The business consequence is that if those credentials are stolen through phishing, a data breach, or credential stuffing, an attacker may access email, impersonate staff, reset other services, or target customers and suppliers from a trusted-looking address.
Unsupported firewall. The technical description is that the internet-facing firewall no longer receives vendor security updates. The business consequence is that a newly discovered vulnerability could leave the main boundary of the business exposed without an available security fix. The organisation would be relying on the attacker not knowing about the vulnerability, or not targeting it, rather than on a supported and maintained control.
Untested backups. The technical description is that backup jobs report success but restoration has never been tested. The business consequence is that the organisation may discover during ransomware recovery or system failure that data cannot be restored within an acceptable timeframe — or at all. A reliable backup and recovery process is one that has been tested, not simply one that runs without error messages.
The roadmap should prioritise outcomes, not technical terminology.
Prioritise by risk reduction
For each improvement, a useful roadmap considers business impact, likelihood, current exposure, existing controls, cost, disruption, dependencies and effort.
The question to ask is:
Which change gives us the greatest meaningful reduction in risk for the resources available?
Some improvements may be low cost, low disruption and high impact. These should usually move quickly. Enforcing MFA across all accounts, removing unnecessary administrator access, or removing an old internet-facing service that is no longer needed are often in this category.
Others may require major licensing changes, hardware replacement, user retraining, business downtime, or wider infrastructure work. These need proper planning and a realistic timeline.
The goal is not to do everything at once. It is to make the right changes in the right order.
Build the roadmap in three horizons
A practical security roadmap can be structured around three clear horizons.
Immediate remediation
Things that expose the business to credible and potentially serious harm now. Examples may include missing MFA, unsupported internet-facing systems, critical unpatched vulnerabilities, broken or untested backups, compromised accounts and excessive administrator access. These should be addressed as a priority, not added to a list for the next quarterly review.
Planned improvements
Controls that materially improve resilience but that can be implemented properly through a managed plan. Examples include Conditional Access policies, improved endpoint detection, enhanced logging, a formal incident response process, supplier reviews, device management and a stronger backup strategy. Rushing these without adequate planning can introduce new problems or leave gaps that were not present before.
Longer-term maturity
Useful improvements that should remain visible but do not need to consume today's budget. Examples include further system hardening, additional automation, more advanced monitoring, process optimisation and broader governance work.
Longer-term does not mean unimportant.
It means: do it at the right time, in the right order.
Dependencies matter
Some security work should happen before other security work. A roadmap that ignores dependencies can create more problems than it solves.
Conditional Access, for example, may depend on having appropriate Microsoft licensing in place, clean and accurate user accounts, visibility of which devices are connecting, and correctly scoped administrator roles. Deploying Conditional Access without those foundations in order can break legitimate access, create exceptions that undermine the policy, or produce alert fatigue that leads staff to ignore security prompts.
Endpoint management may depend on understanding device ownership, replacing legacy systems that cannot be enrolled, and cleaning up user accounts first.
Incident response planning may expose backup gaps that need to be fixed before a useful plan can be written — because the plan assumes a recovery capability that does not yet exist.
A good roadmap should show these dependencies rather than treating every improvement as an isolated task on an independent timeline.
Cyber Essentials is a good foundation, not the finish line
Cyber Essentials provides a strong baseline around firewalls, secure configuration, security updates, access control and malware protection. These fundamentals help remove many of the most common attack routes and give businesses a defensible starting position. For many organisations, achieving Cyber Essentials certification is an appropriate and proportionate first step in building a security posture.
But a business security roadmap may also need to consider areas that fall outside the Cyber Essentials scope: Microsoft 365 configuration, supplier risk, backup and recovery, identity monitoring, incident response, business continuity, and the broader SaaS platform estate.
The right approach is to use Cyber Essentials as a foundation for risk reduction, not to treat certification as the entire security strategy. The risks that come from cloud suppliers and SaaS integrations, for example, are not covered by Cyber Essentials alone.
The problem with product-led security
A product-led conversation about security sounds like this:
"You need EDR." "You need another email security product." "You need a SOC." "You need this licence."
A risk-led conversation sounds like this:
"Here is what could realistically hurt the business." "Here are the controls already reducing that risk." "Here is the biggest remaining gap." "Here is the most proportionate way to improve it."
Security tools matter. A well-chosen endpoint detection product, a properly configured email security layer, or a tested backup solution can each be genuinely valuable. But they are means to an outcome, not the outcome itself.
A product should earn its place in the stack by solving a real problem.
A business that has patched and supported systems, enforced MFA, tested its backups and cleaned up its access controls will be in a stronger security position than one that has purchased six advanced security tools but never addressed those foundations.
Ask your IT provider one simple question
If your IT or security provider gives you a large list of recommendations, ask:
If we only have budget to do three things this quarter, which three would you choose and why?
A useful answer should explain the risk, the business consequence, the urgency, the dependency, the cost and the residual risk after the change is made.
If every recommendation is urgent and every finding is critical, nothing has actually been prioritised. That is not a roadmap. It is a list.
A provider who cannot explain their reasoning in business terms — who cannot connect a technical recommendation to a realistic consequence — may not be the right partner for building a security strategy.
Assurance over insurance
Businesses sometimes accumulate security tools in an attempt to feel safer. Each product is added in response to a breach reported in the news, a recommendation from a sales conversation, or a line on a compliance questionnaire. Over time, the security stack grows without a clear picture of what each layer actually protects against.
That can become insurance through products — a collection of tools purchased in the hope that one of them will catch the right thing at the right moment.
A better approach is: Assurance through understanding and control.
Assurance means knowing: what systems exist; what protects them; what the important risks are; which controls are working; where the gaps are; and what happens next if something goes wrong.
This is a stronger position than simply owning more security products. It is the difference between understanding your security posture and hoping it is adequate.
The Altitude IT view
A good cybersecurity roadmap should not leave a business thinking:
"What else do we need to buy?"
It should leave the business knowing: what matters most; what needs fixing now; what comes next; what can wait; and why the priorities are in that order.
Good IT support should reduce uncertainty as well as risk. The objective is not the biggest security stack. It is the right controls, in the right order, for the risks the business actually faces.
Outcome, not tech.
Understand the risk first. Then choose the control.