Less than half of organizations say their security program is successfully achieving their desired outcomes, according to a new Cisco study.

Cisco’s 2021 Security Outcomes Study, which in previous years was called the CISO Benchmark Report, surveyed 4,800 security, IT, and privacy professionals across 25 countries and asked them about their specific security practices and objectives. It found that the overall rate of success at the program level is 42%. In terms of specific outcomes, about 48% of organizations said their security program succeeds at meeting compliance requirements, 46% said it gained executive confidence, and 43% said it allowed them to avoid major incidents. At the bottom of the list 36% said their programs are minimizing unplanned work.

The “maintaining compliance” and “minimizing unplanned work” outcomes sit at opposite ends of the chart, and Cisco said this hints at the inherent trade-offs that exist when pursuing security objectives.

The survey went on to ask respondents about practices they employ to build a successful security program and ranked these based on their strength of correlation with respondents claiming to have a highly successful security program. According to the results, a proactive technology refresh (12.7%) and a well-integrated tech stack (10.5%) are the most important factors for security success, followed by a sound security strategy (6.1%) in the No. 3 spot.

These top three “sound obvious when you say them, but they’re not necessarily obvious to every organization,” Cisco CISO Mike Hanley said. “So sound security strategy, for example: it’s very easy to go out and buy the shiny new object for a really bespoke threat or an elaborate capability that actually generates net new work.”

Successful Security Strategies

While a strong strategy trumps — or should trump — the latest zero-day attack prevention product, Hanley said he’s spoken with several CISOs that struggle with developing a strong organizational understanding of what their security strategy even is. “What are you trying to protect? What’s the impact of loss? How do you think about your security controls, your mitigation or risk transfer, and how do you staff and maintain or retain talent as part of your security team? That strategic piece is fundamental to thinking about the higher-order functions like prevention and detection of incidents in a in a proactive sense,” he explained.

A successful security strategy should dictate how an organization prioritizes and invests in its security practices and tools, Hanley added. “And the proactive tech refresh and well-integrated tech are sort of peanut butter and jelly in this conversation,” he said. “The tech refresh generally moves us more toward a place where security teams are able to move at the speed of the business.”

This became especially apparent in 2020, when an increasingly complex security landscape — riddled with myriad tools from a diverse set of vendors — collided with COVID-19 and its related newly remote workforce, shift to cloud services, and economic downturn that put a strain on company budgets.

What to Expect in 2021?

“Nine months ago people knew zero trust as a paradigm was coming, and I think they were excited about a perimeter-less future, and then it basically arrived overnight in a violent and unceremonious fashion when we all had to shift to work from home,” Hanley said. This forced businesses to rapidly adjust their strategies to allow employees to work securely from home, and this transition to cloud-delivered services including security is here to stay, he added.

“CISOs really need to look hard at their role as a steward of strategy, controls, and risk management decisions that will drive the transformations of their business that will continue in 2021,” Hanley said. “We will never go back fully to the way things were in February 2020. I expect many of the new ways of working, of remote first, of cloud first, of employee devices being part of our conversation, of data moving around into other cloud service providers — those things are not going away.”

This, he added, requires CISOs to “challenge assumptions about our strategy and refresh it … to accelerate and protect the outcomes that the business is trying to achieve.”