Patching. Segmentation. Monitoring. That’s What $575 Million Came Down To

Why cybersecurity work matters — breach losses and regulatory penalties

When the Federal Trade Commission wrote up what went wrong at Equifax, the summary was not exotic. Their own guidance for businesses put it in three words: patch your software, segment your network, monitor for intruders.

The complaint describes a company that was warned by US-CERT in March 2017 about a critical vulnerability in software it was running, didn’t get it patched, ran a flat enough network that the intruders could move, and didn’t detect the intrusion on legacy systems. Approximately 147 million people had their personal data exposed. Equifax agreed to pay at least $575 million, and potentially up to $700 million, in a global settlement with the FTC, the CFPB, and 50 US states and territories. (FTC, July 2019.)

Read the failure list again. Patching. Segmentation. Monitoring.

That’s your Tuesday.

The work is already this important. It just isn’t counted that way

This is the honest core of the purpose question, and it’s not a motivational one.

You already do work that determines whether an organization has a very bad year. You patch, you manage access, you segment, you watch logs, you clean up the service account nobody documented. The difference between you and a security professional is not usually the technical act. It’s that nobody has made your work accountable to a business outcome — so it gets budgeted, scheduled, and interrupted like maintenance.

“Keeping the lights on” is a description of how your work is classified, not of how much it matters. And classification determines everything downstream: when you get consulted, what your work is compared against, whether the patch window survives contact with the sales team’s quarter-end.

Moving into security isn’t moving to more important work. It’s moving to where the same work is finally attached to what it’s actually worth.

“Losses” — what the number looks like

Two examples already broken down in detail on this site:

  • Equifax (2017) — 147 million people affected; at least $575 million in settlement, plus mandated third-party security assessments every two years for years afterward. Read the full anatomy.
  • MGM Resorts (2023) — an intrusion that started with social engineering against a help desk process and ended with an operational shutdown across properties. Read how ten minutes became a company-wide outage.

The MGM case is the one worth dwelling on if you’ve ever worked a service desk. The initial move wasn’t a zero-day. It was a process — identity verification at the help desk — and a person following it as written. Which means the control that would have mattered most was a decision someone should have made about that process, in advance, on a normal day, with no attacker in sight.

That decision is the job. Not the heroics afterward.

“Penalties” — why security got a seat at the table

The second half of the tile is the part most people skip, and it’s the reason this isn’t a soft benefit.

Since December 18, 2023, public companies in the US have been required under SEC Item 1.05 of Form 8-K to disclose material cybersecurity incidents within four business days of determining the incident is material. Separately, registrants must describe their processes for assessing, identifying, and managing cybersecurity risk — and how the board oversees it — in their annual 10-K. (SEC, final rules adopted July 2023.)

Sit with what that means structurally. Cybersecurity risk management is now something a public company must describe to its investors, annually, in a document its executives sign. It is no longer an IT line item. It’s a governance obligation with a filing deadline attached.

Add the sector-specific layer — HIPAA in healthcare, PCI DSS wherever cards are processed, state breach notification laws in all fifty states, DoD requirements in defense contracting — and the picture is consistent: someone in the organization has to own these decisions and be able to defend them.

That someone is a security professional. That’s the role. That’s why it’s resourced differently and why it sits closer to the decisions.

What “more respected” actually means

Respect, in an org, isn’t a feeling people have about you. It’s a position in the decision process.

The shift is concrete:

Keeping the lights onOwning risk
Called after something breaksConsulted before something is built
Asked can we do thisAsked should we, and at what risk
Judged on uptime and ticket volumeJudged on decisions and their reasoning
Work is a cost lineWork is a risk position the business holds
Your escalation path ends at your managerYour findings can reach the board

Nobody arrives at the right-hand column by being appreciated harder. You arrive by being the person who can articulate what could go wrong, how likely it is, what it would cost, and what to do about it first — in language the business can act on.

The invisible-success problem, and the honest answer to it

Here’s the objection worth raising before you decide this is what you want.

Prevention is invisible. The breach that didn’t happen has no ticket number, no incident review, no line in anyone’s quarterly summary. If you’re moving into security expecting recognition every time you’re right, you’ll be disappointed, and you’ll be disappointed in a familiar way — because that’s the same problem you have now.

The answer isn’t that security fixes this. It’s that security gives you something IT usually doesn’t: the work product is visible even when the incident isn’t.

An asset inventory is a document. A threat model is a document. A security plan with prioritized controls and stated reasoning is a document. These artifacts exist whether or not anything is ever attacked, they show your judgment on paper, and they’re reviewable by people who make decisions about your career. That’s a structurally different situation from a closed ticket that proves only that something broke and then didn’t.

You’re not trading invisible work for visible outcomes. You’re trading invisible work for visible reasoning.

What this page won’t claim

  • It won’t claim you’ll always be appreciated. ISC2’s 2025 Workforce Study surfaced concerns from practitioners that cybersecurity still isn’t viewed as a critical function in some organizations. Being structurally important and being treated that way are two different things, and the gap is real.
  • It won’t claim you’ll always win the argument. You will produce risk assessments that get overruled for business reasons. Being right and being overruled is a routine part of the job, and it’s one of the genuine frustrations of the field.
  • It won’t claim good security prevents all breaches. Well-run programs with competent people get breached. If your sense of purpose depends on a perfect record, this work will hurt.
  • It won’t sell you heroism. Defensive security isn’t a series of dramatic saves. Most of the value is created on quiet days, in decisions about processes and configurations that nobody will ever notice were made correctly.

What it will claim is narrower and more durable: the work has a defined, documented, legally-recognized consequence, and the organization has to care whether it’s done well.

Turning what you already do into decisions you can defend

The gap between the two columns in that table is a way of reasoning — one you can apply to any environment and explain to anyone who asks.

At Blue Team Academy that’s the Threat & Control Method, and each step produces one of the artifacts described above:

  1. Inventory — establish what exists, what’s critical, and what already protects it. Output: an asset inventory.
  2. Threats — determine what can go wrong, how, caused by whom or what, and which risks matter most. Output: a threat model.
  3. Controls — find the gaps, select the right controls, turn security decisions into a plan. Output: a security plan.
  4. Scale — apply the same reasoning across other technologies, environments, and scenarios. Output: a repeatable decision process.

Look at what Equifax was found to have gotten wrong — an unpatched known vulnerability, a network that permitted movement, undetected intrusion on legacy systems — and notice that each failure maps to a step. Something not inventoried. A threat not modeled. A control not chosen or not scaled to the legacy estate.

That’s not hindsight cleverness. It’s the point. The method exists so those decisions get made on ordinary days by ordinary practitioners, before anyone is watching.

Read the full breakdown: the Threat & Control Method explained.

You’ve spent years being the person who fixes it. The transition on offer is to becoming the person who decided it wouldn’t need fixing — and who can explain why, to anyone who asks, in terms the business understands.

That’s not a bigger job. It’s the same competence, pointed somewhere it counts. The rest is direction.

Cybersecurity is not rocket science.

See how the path works. The program is built around turning the IT experience you already have into defensive security judgment — using the Threat & Control Method, applied to environments that look like the ones you already run.

Explore the program →

Want breach breakdowns like these regularly? Keep IT Safe is the Blue Team Academy newsletter for IT professionals moving into defensive security — real incidents, real analysis, no hype. Subscribe to Keep IT Safe.