Technical Risk and Value Trade-offs: CISOs Face Difficult Choices in a Complex and Overloaded Security Market
The security industry has seen a surge in products, leaving CISOs facing difficult decisions without strategic guidance. 44% of executives say their organizations lack an overall information security strategy. Security spending is often driven by fear, with global security spending expected to reach $96.3 billion this year. Experts recommend reducing complexity and focusing on what truly matters by assessing critical assets, vendor risk, and involving CISOs in technology decisions.

At any trade show, enterprises face a dazzling array of solutions. Especially in the security field, new vendors entering the market often promise to solve all potential problems—if given the chance. This phenomenon intensifies the complexity of IT decision-making and vendor evaluation. Faced with thousands of product choices and a lack of clear guidance from business stakeholders, security leaders are left to navigate a vast and chaotic industry on their own.
What's more challenging is that many organizations adopt a naive attitude toward security, with boards and other business departments showing low engagement. This attitude directly leads to inadequate cybersecurity preparedness: according to PwC's global information security survey of 9,500 executives, 44% of executives said their organizations have no overall information security strategy.
The industry encourages a top-down approach to security governance, but this does not effectively address the product overload caused by unclear strategy. Increases in security spending are often reactive. Juan Pablo Perez-Etchegoyen, CTO of Onapsis, said in an interview with CIO Dive: "The cybersecurity industry is becoming so large, with so much content. From a CISO's perspective, it's almost impossible to truly determine what's critical and what's not."
The purchasing habits of security decision-makers are not always driven by strategic considerations. According to Gartner, fear of security breaches is the primary driver behind the growth in overall security spending. This year, global security spending is expected to reach $96.3 billion, an 8% increase year-over-year.
"From a CISO's perspective, it's almost impossible to truly determine what's critical and what's not."
—Juan Pablo Perez-Etchegoyen, CTO of Onapsis
Larger security budgets lead to the purchase of more products, making the management of security product portfolios and accurate risk assessment a daunting task. Tom Corn, Senior Vice President of Security Products at VMware, shared in an interview with CIO Dive that when discussing pain points with customers, "most conversations revolve around questions like: 'I have 50 products. In IT, I've never owned or managed 50 products; usually it's three to five. But in security, I have 50.'" When customers consider adjusting their security strategies, they ask: "To bring in something new, what three things do I need to remove?"
The Role of the CISO
Cybersecurity itself is not simple, but the introduction of new technologies brings complexity, which in turn increases risk. Building a network of isolated systems that do not communicate with each other does not effectively protect an organization. Tammy Moskites, Managing Director of Accenture Security, said in an interview: "When you look at the entire cybersecurity organization, they're trying to protect everything." However, when organizations identify their 'crown jewels' (critical assets), managing the security portfolio becomes more effective.
Reassessing critical assets is closely linked to the evolution of the CISO role. Enterprise security leaders are gradually recognizing the importance of understanding business impact and linking it to risk tolerance. As the cyber threat landscape evolves, third-party risk assessment is receiving increasing attention. For example, a malware attack against a vendor last fall led to customer data breaches at Delta Air Lines and Sears.
John Elliott, Data Protection Officer at easyJet, noted at the 2018 RSA Conference in San Francisco that vendor risk depends on their capabilities. But by assessing vendors' capabilities and operations, and defining acceptable risk, buyers can better understand potential impact. Elliott described a "personality profiling tool" for vendors; through in-depth questioning, security buyers can determine whether a vendor truly understands their business, has the capability to execute, and has the willingness to do so. This approach is similar to the Myers-Briggs Type Indicator, and while it may slow down the procurement process, Elliott said it "is often better than taking risks."
"When making product decisions, the CISO, as a collaborator or peer to the CIO, actually evaluates the technology they're bringing in and asks: 'What's the risk?'"
—Tammy Moskites, Managing Director of Accenture Security
Regardless of the approach, the key to security portfolio decisions lies in placing security assessment authority with the CISO or other security business decision-makers. Moskites stated that the CISO can work with vendors to evaluate controls and collaborate with the CIO to point out gaps in products, while the decision to accept those risks rests with the CIO. Moskites added: "The CIO can still make product decisions, but the CISO's decision is that when the CIO is about to make a product or technology decision, the CISO, as a collaborator or peer, evaluates the technology they're bringing in and asks: 'What's the risk?'"
