
The Habit Cyber-Security Just Can't Quit
Why buying more security tools keeps the industry sick, and what actually works
Illumio is a Business Reporter client.
Dr. Chase Cunningham spent several years recovering from an injury he sustained in the Navy. For much of that time, he said, the treatment focused on managing the symptoms rather than addressing the underlying problem.
Eventually, Cunningham changed his approach, focusing instead on flexibility and fundamentals. The experience shaped how he thinks about cyber-security today.
He sees an industry with a similar tendency: when something goes wrong, organizations buy another product. When that doesn’t solve the problem, they buy another. Budgets climb, stacks thicken and attackers keep getting in, while the underlying issue can go unexamined.
That was the argument Cunningham made in a recent LinkedIn Live session with John Kindervag, chief evangelist at Illumio and the man who created Zero Trust. The session, titled Hard Truths: Stop Treating Symptoms and Why Cybersecurity Keeps Relapsing, answered with a blunt verdict: too many security programs are well funded and badly diagnosed.
Expense in depth
Cyber-security treats symptoms too. We just call it defense in depth. Industry sceptics have a better name for it: “expense in depth”. Buy a tool for every gap. Stack them up. Call it a strategy.
“If you keep dumping money into a problem, you don’t wind up with a solution,” Cunningham said. “You wind up with a lack of budget.”
The worst case he’s seen was a cruise line running close to 60 security products. The reason was simple. Five CISOs in seven years, each one arriving with a blank check and a new stack. Nobody removed anything. Tools overlapped three and four deep. Some sat on the shelf for years, fully licensed and never deployed.
There’s a shelf-life problem too. You buy a license for three years. As Cunningham noted, in this fast-changing market, three years may as well be 10.
Why smart people keep buying
The pair outlined several forces they say are pushing security leaders in the same direction.
Sunk cost is part of it. People defend what they have already bought, even when it isn’t working. Herd behavior is another part. Kindervag and Cunningham both described leaders who align to what everyone else is doing, mostly so nobody can single them out if something goes wrong.
Then there’s the appearance problem. Kindervag recalled interviewing a CISO about a SIEM deployment the man barely understood. He compared reading its output to reading tea leaves at the bottom of a cup. Would he buy it again? Absolutely, he said, because without it he wouldn’t look like a mature organization.
Another client bought thousands of licenses for an endpoint product he openly called awful. Why? Because refusing would have made him look like a bad customer.
And there’s the shortcut of buying whatever sits in the top right of an analyst chart. Both men are ex-analysts. Both say the research is meant to guide a decision, not replace one.
“That’s where people go wrong,” Cunningham said.
The result is a warehouse of boxes. As Kindervag walked into that scenario earlier in his career, a CISO asked him to install all of it. He couldn’t. Half of it didn’t talk to the other half.
The shift from products to policy
The fix is deceptively simple: policy.
Kindervag wants teams focused on policy instead of products. How are the rules written? What actually governs how a packet moves? Those are the questions that decides whether an environment contains a breach or lets it spread.
That work used to be brutal. Spreadsheets, tribal knowledge and maybe an intern with a lot of patience. It isn’t anymore. Cunningham pointed out that policy can now be built and enforced at speed and scale, and that modern tools let you test policy before it goes live. That last part matters more than it sounds.
“If I deploy a policy and it breaks the CEO’s email, that policy just died on the vine,” he said. Testing first is what makes the work survivable.
Travel light
Cunningham used a military image for the alternative. Full battle rattle is every piece of gear you own, strapped on at once. It’s heavy. It slows you down. And most of the time you don’t even need it.
Elite units don’t roll that way. They bring targeted equipment for the exact problem in front of them.
His advice for security leaders follows the same logic. Step back from the problem. Look at the research on what actually causes breaches. Work out the minimum set of capabilities that stops those things. Then implement them strategically.
And above all, own the decision.
“Don’t be willing to roll over because you want to be a good customer,” he said. Being slightly outside the norm is fine. Buying something you don’t need because saying no felt awkward is not.
The industry keeps relapsing because it keeps reaching for the next prescription. The way out is the same one Cunningham found. Stop asking what else you can add. Start asking what’s actually wrong.
Learn more on how Illumio can help your business contain breaches.
This article originally appeared in Business Reporter.
Image credit: Illumio