Using the Cyber Defence Matrix (CDM) to Understand Security
Download resourcesAbout this session
Guillaume Ross, Deputy CISO at JupiterOne, delivers a pre-recorded introduction to Sunil Yu's Cyber Defence Matrix, a five-by-five grid crossing asset classes (devices, applications, networks, data, users) with NIST CSF functions (identify, protect, detect, respond, recover). He explains the left-of-boom versus right-of-boom split: identify and protect happen regardless of an attack, while detect, respond and recover only apply once something bad has occurred, and shows how dependency on technology versus people shifts accordingly, informing hiring and automation decisions. He walks through mapping security vendors, internal processes like MFA device registration, exposed API key reports and Google Drive sharing, and specific tools (HackerOne, Code42, Okta) onto the grid, warning that vendors claiming to cover everything usually only fill a narrow vertical or horizontal slice. He closes with a method for grading metric quality, from mere presence through coverage, utilization, effectiveness and efficiency, and a bonus example showing how mapping security headcount and spend onto the matrix can reveal budget misallocation, such as a software company overspending on endpoint protection relative to application security.
Key takeaways
- Classify every security tool, control or process on the identify/protect/detect/respond/recover axis using the left-of-boom test: does something bad have to happen first for this to apply?
- Budget technology-heavy investment toward the left of the matrix (identify, protect) where automation works well, and staff headcount toward the right (detect, respond, recover) where people remain essential.
- When evaluating a vendor, ask directly where their product fits on the matrix; a claim to 'cover everything' usually signals a shallow horizontal or vertical slice rather than genuine breadth.
- Grade your security metrics by quality, not just existence: move from mere presence ('we have MFA') to coverage, utilization, effectiveness and cost-efficiency before trusting the number.
- Periodically map your security spend and headcount onto the matrix to catch structural bias, such as heavy endpoint investment in an organization whose real risk sits in applications or data.
Speakers

Guillaume has been working in IT and security for way too long by now. Having built security programs for companies of all sizes, worked in vendor organizations on the security and product management side and through years of consulting, he likes to… Read moreRead less
Guillaume has been working in IT and security for way too long by now. Having built security programs for companies of all sizes, worked in vendor organizations on the security and product management side and through years of consulting, he likes to keep it fresh by alternating between working internally, securing companies, and working for companies in the security industry. As the Head of Security for a brand new Fintech startup, he is currently learning a lot about managing security in an agile environment where security is an extremely high priority. Guillaume is a frequent conference speaker, alternating between technical/blue-team topics as well as security management topics. Guillaume is also a Pluralsight trainer, producing cyber security training around topics such as network security monitoring, SOC operations, osquery, cloud security and more.

