Adequate Security
Adequate security means protecting information at a level that matches the risk and the potential harm that could result if the information were lost, misused, or accessed or changed without authorization. It is not about achieving perfect or maximum possible security, but about applying protections that are proportionate to the stakes involved. What counts as adequate can vary depending on the sector and the sensitivity of the information being protected.
Adequate security is generally defined as security commensurate with the risk and the magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of information. In practice it represents a risk-based, evidence-informed judgment rather than an absolute standard, distinct from both perfect security and the maximum security technically achievable. The specific measures deemed adequate are context-dependent and may differ across government, military, and other sectors; practitioners should verify the applicable interpretation against the current authoritative source governing their system and information type, as this entry does not address implementation, contractual, or agency-specific tailoring requirements.
Why it matters
Adequate security is the organizing principle behind risk-based cybersecurity: it directs organizations to calibrate protections to the risk and the magnitude of harm that would result from the loss, misuse, or unauthorized access to or modification of information. This matters because resources are finite, and treating every system as if it required the maximum security technically achievable is neither practical nor, in most cases, appropriate. The concept reframes the central question from "how much security can we build?" to "how much security does this information and its associated risk warrant?", a judgment that must be made deliberately and defended with evidence.
Because adequacy is a proportional standard rather than an absolute one, it can be misunderstood in two opposite directions. Some readers treat it as a ceiling that justifies minimal effort, while others treat it as an aspiration toward perfect security. Neither is correct: adequate security is generally understood as an evidence-based judgment that sits between perfect security and the maximum security technically possible. A related expert caution is that meeting an adequacy determination is not the same as being secure in an absolute sense, compliance with a standard and actual security posture are distinct, and an adequacy judgment reflects the risk understood at a point in time, which can change.
What counts as adequate is also context-dependent, and this is where practitioners most often go wrong. The level of protection considered adequate can vary across sectors, government, military, and others, and depends on the sensitivity of the information at stake. An adequacy determination appropriate for one sector or information type should not be assumed to transfer to another without verifying the applicable interpretation against the current authoritative source governing the specific system and information involved.
Who it's relevant to
Inside Adequate Security
Common questions
Answers to the questions practitioners most commonly ask about Adequate Security.