The Cyber Security Conundrum: A Gap in Execution
In the ever-evolving landscape of cyber threats, a critical issue has emerged: the gap between visibility and execution in cyber security. This revelation comes from ITR Technology, a company that recently attended the ITWeb CISO Retreat, an event that gathered CISOs to tackle the daily challenges of safeguarding organizational assets.
The Execution Challenge
Personally, I find it intriguing that ITR Technology highlights execution as the primary hurdle in cyber resilience. Alan de Waal-Smit, the head of sales, emphasizes that while we invest heavily in security tools, we remain vulnerable due to poor execution. This is a stark reminder that in the digital realm, the weakest link is often not the technology itself, but how it's utilized.
What many people don't realize is that the cyber security landscape is akin to an arms race. As organizations bolster their defenses, attackers evolve their tactics. The real challenge lies in ensuring that our response strategies keep pace with these dynamic threats.
Interconnected Pressures
De Waal-Smit identifies several interconnected pressures that CISOs face, including evolving threats, human risk, hybrid complexity, compliance, and skills shortages. This multifaceted challenge underscores the complexity of modern cyber security. It's not just about having the latest tools; it's about managing a diverse set of risks and ensuring a coordinated response.
One thing that immediately stands out is the tension between IT operations and security teams. De Waal-Smit describes it as a 'silo problem', where two teams with conflicting priorities operate within the same environment. This internal conflict is a microcosm of the broader challenge: aligning different functions towards a common goal.
The Cost of Data Breaches
The IBM Cost of Data Breach Report 2025 provides a sobering statistic: the average breach cost in South Africa was R44.1 million. This figure underscores the financial impact of cyber incidents and the potential consequences of inadequate execution. What makes this particularly fascinating is the 17% year-on-year decrease in costs, which could suggest that organizations are gradually improving their response strategies.
Credential Abuse: A Persistent Threat
The Verizon Data Breach Investigations Report offers another critical insight: credential abuse remains the top initial access vector for breaches. This is a recurring theme, indicating that despite advancements in security, basic human error or negligence continues to provide attackers with an open door.
A detail that I find especially interesting is the rise in third-party involvement in breaches, increasing from 15% to 30% in a year. This highlights the expanding attack surface and the need for organizations to scrutinize their entire ecosystem, not just their internal operations.
Bridging the Gap
De Waal-Smit's solution lies in shifting from multiple systems of record to a unified system of action. This approach integrates technology, people, and processes, ensuring that detection and response are not isolated functions. I believe this is a crucial step towards cyber resilience, as it fosters a holistic approach to security.
When IT and security teams share a workflow, the benefits are threefold: faster response times, reduced noise, and effective prioritization. This integration is key to overcoming the 'silo problem' and ensuring that organizations are prepared for the inevitable breach.
The Bigger Picture
In my opinion, the issue of execution in cyber security is a symptom of a larger problem: the struggle to align strategy with reality. Organizations often have the tools and knowledge to defend themselves, but they fail to implement them effectively. This gap between theory and practice is where attackers thrive.
What this really suggests is that cyber security is as much about organizational culture and process as it is about technology. It requires a unified, coordinated effort across all functions, with a shared understanding of risks and priorities.
As we move forward, the challenge for CISOs and security leaders is to bridge this gap, ensuring that their organizations are not just equipped with the latest tools but are also adept at executing a robust cyber security strategy.