Free tools Windows power users keep installed
One-click scans. No signup required.
Organizations can reduce cyber risk more durably by getting the basics right before adding more advanced security tools. In an opinion article published September 18, 2026, Edwin Ng argues that accurate asset inventories, strong identity safeguards, risk-based priorities, rehearsed recovery, and clear business communication provide the foundation on which newer technologies can work.
Why security fundamentals still matter
New tools can help detect, prevent, and respond to threats, but they cannot reliably protect assets an organization does not know it has, compensate for weak identity practices, or recover systems without a workable plan. Ng’s point is not that organizations should avoid advanced technology; it is that its value depends on sound everyday controls beneath it.
Ng is LogicGate’s CISO and previously served as CISO at Hyatt Hotels Corporation. His article is an opinion piece, not a comparative product test. The recommendations below are a practical way to apply its argument without treating any one product or framework as a complete solution.
1. Build an accurate, maintained asset inventory
Security teams need a dependable view of what they are responsible for protecting. Ng recommends discovery across on-premises systems, cloud and multicloud environments, endpoints, and third-party applications, followed by consolidation of scattered records into a maintained source of truth.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
An inventory is useful only if it is both broad enough and dependable enough to guide decisions. When building or improving one, check:
- Coverage: Include the environments and asset types that actually support the organization, not just the systems already managed by the security team.
- Ownership: Record who is accountable for each asset so vulnerabilities, access questions, and recovery work have a clear destination.
- Data quality: Reconcile duplicates, stale entries, and missing information before treating the inventory as a basis for risk decisions.
- Update cadence: Establish how discovery and ownership records stay current as systems and services change.
- Integration: Make inventory information usable by the teams and processes that need it, rather than leaving it isolated in another record system.
These are implementation considerations, not vendor-selection results: Ng’s article does not name or test asset management products.
2. Strengthen identity safeguards with workable recovery
Ng recommends ensuring multifactor authentication (MFA) is in place and considering passkeys as a further safeguard. Neither should be treated as a complete answer to identity risk. Organizations still need to decide which accounts and workflows are covered, how authentication will work across their services and devices, and how people can securely regain access when a credential or device is lost.
Rank #2
Passkeys are gaining adoption, but the available figures have a defined scope. In its October 14, 2025 Passkey Index, the FIDO Alliance reported that, among contributing member companies, 93% of accounts were eligible for passkeys, 36% had a passkey enrolled, and 26% of sign-ins used passkeys. These figures describe those organizations, not the entire population. The same index reported an average sign-in time of 8.5 seconds for passkeys versus 31.2 seconds for the traditional approaches compared, and a 93% sign-in success rate versus 63% for other methods. Those are reported index findings, not guaranteed outcomes for an individual deployment. FIDO Alliance’s Passkey Index announcement
Ng’s article also repeats a claim that MFA-protected accounts are 99% less likely to be hacked and attributes it to CISA. The cited CISA page was inaccessible during the research used for this article, so that figure is not independently verified here and should not be treated as a confirmed statistic.
3. Prioritize security work by business risk
Security spending should reflect the organization’s risk appetite and protect its critical products, services, and data first. A practical priority-setting process starts by identifying what would cause the greatest harm if unavailable, exposed, or altered, then directs limited time and resources toward reducing those risks.
A common framework can help teams describe and compare the work. Ng names the CIS Controls; the Center for Internet Security describes them as a prioritized, prescriptive set of practices and lists CIS Controls v8.1 as its latest version on the official page. Center for Internet Security: CIS Critical Security Controls
Use a framework to organize and communicate safeguards, not as a substitute for deciding which services and data matter most to your own organization. A control may be important in general but still rank below a more urgent exposure affecting a critical business function.
4. Prepare to identify, contain, and recover from incidents
Prevention remains important, but it cannot be the only part of a security strategy. Ng recommends pairing prevention with faster incident identification, response, secure system and data backups, recovery plans, and practice. As he puts it, “The quicker you can identify a breach in progress, the quicker you can shut it down.”
Rank #4
Recovery planning should connect the technical steps to the services the business needs back. Useful questions include:
- Which systems and data must be restored first to resume critical services?
- Are backups protected well enough to remain usable if the systems they support are compromised?
- Who makes and communicates decisions during a response?
- Can teams demonstrate that they can restore systems and data, rather than merely confirm that backups exist?
Ng’s article does not set a recovery-time objective, a testing schedule, or a preferred product. Organizations need to define their own recovery targets and prove their plans through practice.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.5. Give security and business teams a shared language
Technical findings matter more to decision-makers when they are connected to business consequences. Ng recommends translating risks for stakeholders and quantifying them where a defensible estimate is possible. Potential considerations include projected lost business, regulatory penalties, and reputational damage.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Not every risk can be assigned a credible dollar value. Estimating losses from an incident that did not happen is especially uncertain, so a precise-looking figure should not be presented as certainty. Explain the assumptions behind an estimate, distinguish measured costs from projections, and use other clear descriptions of impact when the evidence does not support financial precision. Ng’s article summarizes the need to bridge the gap plainly: “Bridging that communications gap is critical.”
How to apply the fundamentals together
The five recommendations reinforce one another. Inventory makes it possible to see what needs protection; identity controls help restrict access; risk prioritization directs effort toward what matters most; response and recovery limit the damage when prevention fails; and shared language helps leaders decide what to fund and why.
Ng’s argument is that advanced security tools can add value when built on that foundation—not that a checklist, framework, or individual safeguard guarantees security. As he writes, “In reality, mastering foundational controls is what moves the needle.”
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

