When Harmonic Security was founded, the organisation consisted of just three or four people. Two years later, the company has grown to 73 employees and this kind of growth brings plenty of opportunity, but it also changes the way an organisation needs to think about security and risk.
For Harmonic Security, whose clients rely on the company to help them govern AI across their workforce, being able to assess and understand risk quickly is essential. Traditional approaches to risk management can struggle to keep pace with a rapidly changing organisation.
“We need to be quite agile in the way that we assess risk,” explains James Chappel, CISO at Harmonic Security. “We're trying to think about it in a new, fresh way where pragmatism and ease of use is at the front end of how we do security, and not this thing that's stuck in a back office not really adding any value.” commented James.
That led Harmonic Security to adopt the Cydea Risk Platform as the foundation for how it understands, quantifies and communicates cyber risk.
Framing risk as a story, not a spreadsheet
One of the biggest hurdles in cyber security governance is the sheer amount of time required to identify and measure risk through conventional metrics. By adopting Cydea, Harmonic shifted to treating risk as a narrative built around scenarios, consequence, and frequency.
“Identifying risk is a really time-consuming process,” the team shared. “Cydea helps us speed that up because we look at scenarios almost as a narrative. We look at consequence and we look at frequency. That enables us to really find the data that may relate to risk and get that established in an organisation really quickly, rather than trying to have to find these metrics that measure risk.”
The result is a more consistent and repeatable way of understanding risk, supported by evidence and a clear narrative that can be shared directly to executive leadership. “We have a clear framework to follow, evidence that can back that up, and a story we can tell the business,” James noted. “We’re able to actually express to the board in dollar terms the impact of cyber risks on our organisation.”
Handling scale without losing momentum
When an organisation scales rapidly, business variables never stay static. Customer contract values change, employee headcounts grow, and customer bases move continuously and in a traditional model, updating risk assessments to match these moving targets can be painful.
Using Cydea’s built-in scenario library and dynamic variables, the team at Harmonic can update core numbers in one place, automatically flowing changes across every risk scenario. “Some of the features, like the scenario library and the variables, have really saved me quite a lot of time,” James explained. “Things like our total exposure to customer contract value, the numbers of employees, or numbers of customers do change quite frequently, and being able to update those in one place and having that flow into our scenarios is really important. I can very quickly and easily take an idea, a risk, and a scenario, look at the company variables that may relate to that, and report that back to the business.”
Building risk capability within the security team
The Cydea Risk Platform has also helped Harmonic Security build its own internal capability. Ed Merrett, Director of Security, came into the role having previously seen risk management handled differently elsewhere and taking ownership of risk meant learning how to approach it properly, while also developing a model that worked for Harmonic’s own business.
“The platform has kind of enabled me to self-learn that in a way and define how we want to do risk here,” Ed highlighted.
For a growing organisation, that flexibility is important. Rather than relying entirely on a separate risk function or external consultants to interpret and manage every assessment, the team can build its own understanding and maintain its risk model directly in the Cydea Platform. “I think the platform has been a game changer for me in my career,” Ed commented.
Building trust through the right partnership
Harmonic Security’s experience demonstrates what can happen when risk management becomes a practical part of security operations. With the Cydea Risk Platform, the team has built a repeatable way to assess cyber risk through scenarios, quantify potential impact, incorporate changing business data and communicate risk in financial terms.
For a rapidly growing organisation, that means being able to move quickly without losing rigour and it gives Harmonic Security a way to keep its understanding of risk alive as the business changes, new threats emerge and incidents occur.
And with the Cydea Risk Platform providing the framework, data and insight behind that approach, cyber risk becomes something the organisation can continually understand, communicate and act on.
“There’s a level of trust that we have with Cydea because they’re bringing stuff to us for attention,” James concluded. “They’re allowing us to navigate things in the right way, and the team themselves as people are great to work with who really understand this domain.”