The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →A cybersecurity strategy needs to address both sides of an incident: reduce the chance and potential impact of a breach before it happens, then be ready to respond and recover if prevention fails. Torsten George’s “left and right of boom” framing is a practical way to check whether an organization is investing in both.
What “left and right of boom” means
“Boom” is the incident. “Left of boom” refers to preparation and controls intended to prevent an incident or limit its harm; “right of boom” means response and recovery after one occurs. Torsten George traces the phrase to military efforts to detect and disrupt improvised explosive devices before applying it to cybersecurity. In business, the framework asks whether security work reduces risk before an incident and supports recovery afterward—not whether a particular tool can guarantee safety.
George’s 2022 article recommends treating risk reduction as continuous and fitting it to the organization’s risk appetite and tolerance. That balance matters because prevention cannot eliminate cyber risk. NIST’s systems-engineering approach describes cyber resiliency as the capability to anticipate, withstand, recover from, and adapt to adversity, rather than as a single defensive product. NIST published that guidance in SP 800-160 Vol. 2 Rev. 1 on December 8, 2021.
Build the left-of-boom foundation
George’s recommendations focus on knowing what the organization must protect, restricting opportunities for compromise to spread, and checking that controls work in practice. They are starting points to tailor to the organization’s systems and operating environment, not a universal implementation checklist.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errors#1 Best Overall
Know what is connected
Maintain an inventory of hardware and software. Without visibility into assets, security teams have a weaker basis for assessment, prioritization, and meaningful security metrics. Keep the inventory useful for the systems and endpoints the organization actually operates.
Limit access and movement
- Use multi-factor authentication (MFA). Add an additional verification step to help reduce opportunities for unauthorized access.
- Apply least privilege. Give users and systems only the access they need, limiting what an intruder may reach if an account is compromised.
- Segment networks. Separate parts of the environment so a compromise in one area is less able to move laterally across the organization.
- Apply Zero Trust principles. George summarizes the idea as “never trust, always verify.” Treat access as something to verify rather than assume solely because a user or device is already inside a network.
Protect endpoints and verify defenses
Design endpoint security for distributed and work-from-anywhere environments, where devices may not routinely connect from a central office. Run anti-malware software, but also confirm that it is functioning; installation alone does not establish that a control is operating effectively.
Assess cloud choices in context
George suggests considering cloud migration and the security measures offered by major cloud providers. That is a decision to assess against the organization’s requirements, not an automatic way to reduce risk: his article does not provide a comparative analysis showing that migration reduces attack surface in every case.
Plan for the right-of-boom work
When an incident occurs, the organization needs more than a document describing what it hopes to do. George uses “cyber go-bag” as shorthand for proactive resilience: prepare the capabilities and steps needed to secure endpoints remotely, remove malware, restore critical applications, and reconnect endpoints after compromise.
Rank #3
Make recovery planning specific enough to guide action. Identify which applications are critical, how affected endpoints can be handled remotely, and what must happen before systems are safely restored and reconnected. Planning should include distributed endpoints as well as central infrastructure. The framework does not claim that any one control—or a go-bag by itself—ensures recovery.
Use resilience as a systems capability
NIST broadens the idea beyond endpoint response. Its SP 800-160 Vol. 2 Rev. 1 says: “Cyber resiliency engineering intends to architect, design, develop, implement, maintain, and sustain the trustworthiness of systems with the capability to anticipate, withstand, recover from, and adapt to adverse conditions, stresses, attacks, or compromises that use or are enabled by cyber resources.” In other words, resilience concerns how systems are designed and sustained across their life cycle, not just what an incident team does after an alert.
Rank #4
Organizations can select and tailor NIST’s concepts to their technical, operational, and threat environments. A useful strategy connects that systems view to practical questions: what must keep operating, what can be isolated, how restoration will work, and how operations can adapt after disruption.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Turn the framework into a strategy
Use the two sides of boom as a planning lens, then decide what is appropriate for your environment and risk tolerance.
Best Value
- Establish visibility. Build and maintain a hardware and software inventory so teams can assess the environment they are defending.
- Choose preventive controls around real exposure. Consider MFA, least privilege, segmentation, endpoint protection, and Zero Trust principles in light of the organization’s systems and operations.
- Check that controls operate. For example, verify that anti-malware is functioning instead of treating deployment as proof of protection.
- Specify recovery needs. Identify critical applications and how endpoints can be secured, cleaned, restored, and reconnected after compromise.
- Fit the plan to operations. Use the organization’s risk appetite, technical environment, and operational requirements to shape what it prepares to withstand and recover from.
For organizations comparing approaches or vendors, useful criteria include prevention coverage, endpoint visibility and remote recovery, integration with existing systems, and whether recovery capabilities meet operational requirements. These criteria support evaluation; they are not a ranking of products.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




