Security misconceptions are hindering the effectiveness of security teams led by chief information security officers (CISOs), Gartner Senior Director Analyst Henrique Teixeira and Distinguished VP Analyst Leigh McMullen noted during the opening keynote of this week’s Gartner Security & Risk Management Summit.
“Many CISOs are burnt out and feel they have little control over their stressors or work-life balance,” said Teixeira. “Cybersecurity leaders and their teams are putting in the maximum effort, but it’s not having the maximum impact.”
Teixeira and McMullen identified four myths in the industry involving data, technology, manpower and controls:
Security myth 1: More data equals better protectionMany security teams believe that the best way to drive executives to take action on security initiatives is through sophisticated data analysis, including estimating the probability of a security incident.
However, Gartner analysts argued this is not practical to quantify risk, nor foster shared accountability between security and enterprise decision-makers, which is necessary for materially reducing business risk. The firm’s recent research revealed that only a third of CISOs report successfully driving action through cyber risk quantification.
“Rather than continuing to pursue more data and more analysis, savvy CISOs engage in a minimum effective insight approach,” Teixeira said. “Determine the least amount of information needed to draw a straight line between the enterprise’s cybersecurity funding and the amount of vulnerability that funding addresses.”
To achieve this approach, Gartner recommends CISOs use outcome-driven metrics, which link security and risk operational metrics to the business outcomes they support by explaining the levels of protection currently in place and the alternative protection levels available based on spend.
Security myth 2: More technology equals better protectionGartner forecasts global information security and risk management spending to increase 12.7% to reach $189.8 billion in 2023. However, as security budgets on tools and technologies increase, security leaders still feel their organizations are not properly protected.
“Cybersecurity often gets stuck in a gear acquisition mindset, believing that around the corner there must be something better,” McMullen said. “Instead, CISOs must embrace a minimum effective toolset — the fewest technologies required to observe, defend and respond to exposures.
“This will enable cybersecurity to own their architecture, reducing the complexity and lack of interoperability that makes it so difficult to generate value from technology investments,” he added.
A minimum effective toolset means CISOs should ensure the operational expenses of security professionals managing these tools are less than the risk mitigation benefits the tools provide, while evaluating from an architectural standpoint whether each tool enhances or diminishes the enterprise's protective abilities.
Security myth 3: More security professionals equals better protectionThe security talent supply cannot keep up with the demand, McMullen noted, adding the solution lies in "democratizing cybersecurity expertise," as opposed to trying to fill the talent gap.
“Security is a massive bottleneck to digital transformation, and a lot of that is because of a myth that only cybersecurity professionals can do serious cyber work,” he said.
CISOs can reduce the security team's burden by encouraging other employees and teams who acquire, modify or create technology to develop "minimum effective expertise" or cyber judgment, analysts noted.
This expertise or judgment is related to the idea of democratizing security expertise that equips all employees with enough security knowledge to make safer decisions, not just security professionals.
A recent Gartner report showed that business technologists with high cyber judgment are 2.5 times more likely to consider security risks when developing analytics or technology capabilities.
Security myth 4: More controls equals better protectionSecurity groups are well-aware of the pervasive non-secure behaviors among employees, but their usual solution of adding more controls “is backfiring,” said Teixeira.
“Employees report a huge amount of friction involved with secure behavior, which is driving unsecure behavior. Controls that are circumvented are worse than no controls at all,” he added.
Gartner’s recent surveys supported this idea as 69% of surveyed employees reported they have bypassed their organization’s security guidance in the past year, while 74% of employees would be willing to bypass these guidelines if it helped them achieve a business objective.
That’s why Teixeira recommended adopting the concept of "minimum effective friction," a human-centric approach that rebalances the performance assessment of security controls and prioritizes user experience over technical functionality.
The analysts forecast that half of CISOs will adopt the human-centric design for their security programs by 2027 to minimize operational friction and maximize control adoption. This approach prioritizes the individual over technology, threat, or location as a recent Gartner research showed that over 90% of employees admitted they knowingly engage in unsecured actions, despite being aware of the risks.
Comments