
If you’ve been working in the cybersecurity space for long enough then you’ll likely notice a recurring theme. A major breach occurs at a company; executives want answers; and within days vendors are standing in line to explain how their product could have protected against the attack. All of sudden budgets that could not be allocated months prior are being spent rapidly and yet another security tool is being added to an already large list of security tools. Everyone feels like “progress” is occurring simply because something was bought.
But was it really?
Here’s an opinion that may irk a few folks. I do not feel most organizations suffer from a technology issue. I feel they suffer from a prioritization issue. We have somehow led ourselves to believe that cybersecurity is something we can “buy” rather than something we need to “build.” Every year we invest billions into endpoint detection, vulnerability management, cloud security, identity platforms, AI enabled SOC tools, threat intelligence feeds, etc… And yet ransomware is still in the news, data breaches are still occurring daily, and security teams are busier than ever. If buying more products was the answer we’d be seeing better results.
Let me be clear; I’m a huge fan of new technology. As you can tell from my previous writings, I enjoy experimenting with my home lab and testing new security products. Innovation is why I love working in this industry. However, there is a significant difference between purchasing technology due to a problem it addresses versus purchasing technology due to trend or all the other teams having it. Far too many organizations rush to adopt the latest platform without taking sufficient time to truly define and understand the problem they’re trying to resolve.
I’ve worked with organizations that had budgets dedicated to cybersecurity that most teams would kill for. These organizations had numerous products from nearly every major vendor available to them, had dashboards spanning entire walls, and produced more alerts than analysts could possibly stay busy 24/7. Paper-wise these organizations seemed incredibly mature. I would then ask a very simple question… “What are the top 5 critical assets your organization cannot afford to lose?” At times the answer was not immediately obvious; I would then ask “who makes decisions regarding your organization during a major cyber incident” or “how would your organization operate if critical systems went down”? Most rooms fell silent once again.
That’s not a technology problem…
That’s a fundamentals problem…
I’ve also worked with smaller organizations that did not have endless budgets nor massive security teams. Therefore, they could not purchase every single new product hitting the market. So, they took the time to ensure the basics were correct. They understood what they were protecting, identified their biggest risks, maintained accurate asset inventories, and defined clear incident response procedures. Everyone understood their role in the event something went wrong. Were they perfect? Absolutely not. No organization is. However, several of them were more effective than companies that spent ten times more on cybersecurity.
There is a huge mistake organizations make today- that is to confuse activity with progress. Using another security platform feels productive. Using an AI enabled solution feels innovative. Creating additional dashboards creates an appearance of visibility. None of those activities automatically reduces risk. In fact, each additional product introduces another system which must be configured/maintained/monitored/integrated and understood by the people responsible for defending the environment. If your team is currently overwhelmed by current tools then adding additional tools may actually make things worse instead of better.
AI is probably currently one of the best examples of this today. AI has huge potential and I believe it will change cybersecurity significantly over the next decade. It can automate repetitive tasks, improve threat detection, speed up investigations, and allow analysts to spend more time solving meaningful problems instead of chasing false positives. Those are real benefits. However, AI is not going to solve poor identity management issues, create accurate asset inventories, remove technical debt, or build stronger security cultures. It can make a mature security program more efficient but it will not create maturity where none exists.
Before any new security technology is purchased by an organization, I think they should ask themselves one simple question: what problem am I trying to solve today? Not trending products? Not products competitors have bought? Not impressive products demonstrated during vendors demos? What specific risk exists today that this investment will reduce? If that question cannot be clearly answered than the organization is likely not ready to make that purchase.
Interestingly some of the largest improvements in security come from items which are not particularly exciting. Cleaning privileged accounts. Eliminating unused access rights. Ensuring proper asset management. Improving incident response plans. Conducting realistic table top exercises. Educating employees to recognize social engineering attacks. None of these initiatives produce flashy conference presentations but consistently reduces risk. Also many of them cost much less than buying another enterprise security tool.
One of the best security leaders I ever worked with rarely asked “what should we buy next?” Instead he would say “what is preventing our team from being successful?” Occasionally the answer was related to technology; however more frequently related to unclear ownership of responsibilities, poor communication between departments/stakeholders, technical debt, obsolete processes, and conflicting priorities. These aren’t problems that can be solved with another software license. These are leadership problems, operational problems, and sometimes cultural problems.
Ultimately cybersecurity has never really been about technology. It’s about helping organizations operate safely while achieving their business objectives. Technology is important in resolving that objective but should never become the strategy.
The strongest security programs I have seen were not the ones with the biggest budgets nor collections of tools available to them. They were the ones who identified their risks, focused on the fundamentals of cybersecurity, invested in their people, and built processes that could be executed when needed most.
Next time someone proposes buying another security tool before signing the purchase order take a moment and consider how well your team is getting out of the tools you already own. Consider whether the true challenge is technological or operational. In my experience there are many times that a new product is the right decision. However, a new product should result from a clearly defined strategy-not a strategy itself.
In conclusion cybersecurity isn’t a competition to see who owns the most tools. It’s about reducing risk, protecting the business interests of an organization, and making sure the organization continues operating when-and not if-something goes wrong.
Stay Ahead of Cyber Threats
Subscribe to receive the latest cybersecurity insights, AI trends, research, executive commentary, and new articles from TS Cyber Intelligence.
No spam. No marketing emails. You’ll only receive an email when a new article is published, and you can unsubscribe at any time.
