This is part 3 of 3 in a series of posts: The Missing Layer in Cybersecurity. You can catch up on part 1 here, and part 2 here if you haven’t read them yet.
A recent survey of 200 U.S. cybersecurity leaders found that 100% of organizations had granted security or compliance exceptions in the past year to move high-risk digital work forward (Replica Cyber Exception Economy Report). What was once a carve-out for genuine emergencies has become standard operating procedure, and most leadership teams do not have clear visibility into how often it is happening or what it is costing.
High-Risk Work Is No Longer Confined
Three years ago, most of the work that required direct engagement with untrusted content sat in specialized functions such as dedicated security teams, specific fraud units, niche threat intelligence groups. Those teams had their own challenges, but the practitioners doing this kind of work had been bounded…not anymore.
Widespread AI adoption has put model evaluation and agent testing on the project list of technology teams that had no such function in 2022. A team assessing a third-party AI tool before deployment is now doing the same category of work that malware analysts do: running untrusted code in an environment they also use for other things, and hoping the separation holds.
Fraud and financial crime teams are doing more of their investigative work further into hostile territory. Cryptocurrency tracing, scam operation research, account investigation in criminal networks. This work has extended well beyond what a standard compliance environment was designed to support. AML investigators are touching external systems and data that exist outside the normal corporate perimeter, often with no dedicated infrastructure to do it from.
Threat intelligence has distributed from specialized teams into broader security organizations. Analysts investigating adversary infrastructure and accessing hostile sites are now common across security teams of varying sizes and maturity levels.
The aggregate result is that high-risk work has become a regular part of the week for a much larger share of the workforce than it was five years ago. The infrastructure to support it has not kept pace.
Governance Reaches Its Ceiling
When teams need to conduct high-risk work without dedicated environments, the options narrow fast. The organizations in our survey settled into a recognizable set of responses: proceed on corporate systems despite reservations, delay or cancel the work, or hand it to a third party.
Each of those carries a real cost. Proceeding on corporate systems is the path most organizations take, and it is the one that turns every high-risk investigation or evaluation into a potential exposure. Delays and cancellations mean the work does not get done at the pace the business requires. Third-party handoffs solve the infrastructure problem by creating a dependency and a new risk surface.
The approval process that precedes most of these decisions (the exception, the sign-off, the formal waiver) does not change the underlying exposure. It documents that someone made a decision. What a change management approval cannot do is prevent malware analyzed on a corporate endpoint from propagating if something goes wrong or prevent a dark web investigation from creating a path back to production data.
Governance documents the risk, but unfortunately, it still isn’t contained.
Separation
A purpose-built environment for high-risk work changes what a failure can reach, not the work itself. The analyst still conducts the investigation. The engineer still evaluates the model. The fraud team still traces the transaction. What changes is that a failure in that environment stays within the boundary of the isolated environment rather than propagating into the systems the organization depends on.
The risky activity still needs governance, monitoring, and policy. Those things do not become irrelevant. They become more effective, because the environment they are governing is separated from the environment that cannot afford to fail.
The organizations that have built this infrastructure describe the same operational shift: their teams move faster on high-risk work, not slower, because the question of whether to proceed stops being tangled up with questions about what a failure might reach.
Both Spending and Risk are Up
U.S. cybercrime losses are up 33% year over year (IC3 Annual Report). The average data breach now costs $4.4 million globally (IBM Cost of a Data Breach Report). AI-assisted fraud is outpacing the investigative infrastructure built to counter it. The volume of high-risk digital work will increase, not decrease, as AI adoption continues and threat actors grow more sophisticated.
The governance layer that the industry has built over thirty years has immense value, but now, the scale of high-risk work now being performed as routine business has grown past what governance alone was designed to handle. The containment layer is the part of the risk model that most organizations have not built yet. The data on exceptions, losses, and exposure suggests the cost of that absence is no longer theoretical.
To learn more about secure environments for high-risk work, check out our demo video.