
Who has access to what, and with what privileges? The question sounds simple, but it's in that answer that a huge part of an organization's risk hides today. And yet, in the words of today's interviewee, almost no company gets up in the morning with the goal of 'being secure'. It gets up with the goal of being profitable.
It's not a minor detail. In 2025, the median cybersecurity budget of European organizations was already around 1.5 million euros, and 70% of companies pointed to regulatory compliance such as NIS2, DORA, Cyber Resilience Act, as the main driver of that investment, according to the NIS Investments 2025 report by ENISA, the European Union agency for cybersecurity.
That tension, between what it costs to look secure and what really protects, runs through the entire conversation I had with Javier Rodríguez Prada. And it comes from someone who has seen the problem from every possible angle: he has worked as a Security Manager, in GRC roles and as a CISO, both coordinating teams and on his own, and he has worked both at cybersecurity companies providing services to clients and within the organizations that have to protect themselves.
Together, we explored identity risk from an unusual angle: not that of the analyst who hunts the attacker, but that of governance and business. We talked about why identities, human and non-human, have become the key aspect of risk, about why so many companies confuse having the certificate with being secure, and about an unpopular opinion that, deep down, is a warning. What follows are his answers, unfiltered.
_
8Layers: You've gone through consultancy, and you've also been the end client, across different sectors and company sizes. Looking back, what has that diversity taught you about security that someone who has always been in the same kind of environment can hardly see?
Javier: There's still too much variability in what are considered good practices. Part of the incentives companies have to invest in security get limited once they 'obtain the certificate', which helps improve the security posture, but you don't always manage to take that last step that would finish managing risk correctly. A company's effective security level perhaps still has a more subjective than objective component, and that's where focus could be placed to make assessments comparable.
8L: You've led the obtaining and maintaining of certifications such as ISO 27001 and ENS, and you know NIS2 and other frameworks closely. What's the biggest difference between an organization that "has the certificate" and one that is really secure? Where does compliance become theater, and when does it truly bring value to the business?
Javier: It depends on the incentives companies have. Nobody has the goal of "being secure", but of being as profitable as possible. The companies that best understand how risk affects their bottom line will be the most secure within their means, and only those that additionally have sufficient means will be able to be secure. Companies that see a 'certificate' as a mere enabler can possibly end up having all the certificates, and it doesn't mean much in real terms.
It's common that a common language isn't established between the technical and business sides. The technical side should have more business support to understand the language of business, and the business should show concern beyond obtaining the compliance check. If I had a magic lamp, my wish would be to identify incentives and motivations so that both sides want to understand each other without 'having to' understand each other.
8L: Audits are snapshots of a moment, but the environment, and above all identities (who comes in, who leaves, what permissions they have) changes every day. In practice, how do you sustain a state of compliance between one audit and another? And how would that process, done in a healthy way, look to you?
Javier: With continuous assessment tools. I don't see any other way that doesn't go through continuous assessments in real or near-real time. There are few 'technical' controls you can afford to monitor through monthly or even weekly 'snapshots'. There is no product, that I know of, capable of covering all the checks of different regulations at once (the number and complexity of regulations is constantly changing), so identifying and equipping yourself with a set of specialized tools in different areas that complement each other would be the 'silver bullet'. There will always be manual processes of collecting manual or documentary evidence, but let's try to narrow them down and minimize them.
8L: Our column is called Identity Attack, Unfiltered, so I want to sharpen the focus on identity. From governance and risk, how much does who has access to what and with what privileges weigh today in an organization's risk, for example?
Javier: I think identity is the key aspect, and more relevant every day. Human identities, non-human, even 'identities' of assets depending on how each organization manages them. I haven't seen any company that, after an initial review, doesn't find some privileged user or sensitive identity worse protected than expected, and this is a tangible risk of a potential incident.
ENS and NIS2 address it from a management point of view; indirectly they advocate for Zero Trust. I'd say that ENS at its High level is stricter regarding controls and evidence of hardening and identity lifecycle management. It's a good starting point for companies to know what they should manage and what to pay attention to.
8L: And even complying with ENS or NIS2, how far does a regulation really go? Is complying with it enough to be covered on identity?
Javier: I understand that a regulation points to good practices and prescribes more or less demanding minimums. An audit, even a certification one, won't be able to certify 100% compliance. Due to the heterogeneity of each company's technological architectures, it's hard for regulations to ask for much more, especially considering that companies of different sizes, sectors, etc. should be able to comply with them.
8L: And organizations end up accepting identity risks like a privileged account that nobody deactivates, an inherited access that stays alive "just in case". How should an organization manage what it needs to consciously accept, and what separates a "we accept this risk in a documented way" from a "we simply forgot about it"?
Javier: Starting by having a 'methodology' in place that explains the acceptability of that risk, and continuing by setting up alerts that warn in case an increase in that risk materializes.
I relate it to maintaining a regulation's state of compliance: either you've automated it, or you risk unpleasant surprises.
8L: We're wrapping up, thank you so much for everything. To close: do you have any unpopular opinion about GRC, compliance or risk management that you'd defend even knowing that many people in the sector wouldn't agree?
Javier: While I was studying for the ISACA certification exams, even though they're based on theoretical assumptions that only apply 'by the book' in large corporations, I have to admit I had several moments of "now I know what I would have done differently in such and such a previous situation", and that's the best learning from a certification.
Landing on an unpopular opinion: it has helped me understand the value of managing security from the start, without waiting to 'have something set up to cover the basics'. Like technical debt, the longer you take to make changes to a system in constant change or growth (fixing a vulnerability, or implementing a GRC system), the more costly it ends up being. As an analogy: GRC is to a security management program what a vulnerability or a bug is to a software program.
If anything stays from this conversation with Javier, it's that identity security isn't solved with a certificate hung on the wall. It's solved by understanding that no company pursues "being secure" as an end, but as a consequence of managing its risk well, and that this risk today lives, more and more, in identities: who has access to what, with what privileges, and what stays switched on "just in case". Compliance marks a minimum; it doesn't guarantee that minimum is still true the next day. And, like any debt, managing identity too late only gets more expensive over time.
Identity Attack, Unfiltered
Identity Attack, Unfiltered is 8Layers' biweekly series where we give security experts the floor to talk, unfiltered, about identity risk: how they see it from the field, what worries them, and what they'd do differently. Each conversation adds a different perspective, from governance to digital forensics, from the SOC to threat intelligence.
The series grows out of what we do at 8Layers, uniting in a single view of identity what normally lives apart: posture, detection, and compliance.
Do you work in identity security and feel you have something to contribute? We'd love to hear from you. Write to us at marketing@8layers.io and tell us your perspective; you could be the next voice in the series.