Problem
All aspects of managing a cybersecurity program are important, but I view these as key. If you lose sight of which threats are most relevant or which controls offer substantial near-term value, everything else gets a lot harder. Can you see how something like the Verizon DBIR helps accomplish this? What has helped make this process more real/understandable? Any relevant personal experience you'd like to share?