A SEAT at THE TABLE: Helping business leaders grow their influence
Join the discussion as we unpack what’s working, what’s not and how to stand out and win in a competitive market.
A SEAT at THE TABLE: Helping business leaders grow their influence
The Cybersecurity Problem Nobody Is Fixing
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Companies are spending more on cybersecurity than ever. Yet cyberattacks, breaches and vulnerabilities continue to increase.
What if we're trying to solve the wrong problem?
In this episode of A Seat at The Table, Jane Singer talks with cybersecurity expert Greg van der Gaast at Sequoia Consulting, about why many cybersecurity failures aren't really technology failures at all.
They're symptoms of deeper problems in the way an organization operates.
Greg has spent more than 25 years in cybersecurity, including working undercover for the U.S. government and advising executives, boards and organizations on cybersecurity risk. But today, he argues that companies need to stop thinking about cybersecurity primarily as a technical problem.
Instead, executives should ask a different question:
What is happening inside our organization that allowed this vulnerability to exist in the first place?
Why More Cybersecurity May Not Make You More Secure
When a vulnerability is discovered, the conventional response is usually to add another security tool, process, test or layer of protection.
Greg argues that this treats the symptom rather than the cause.
An unpatched system, badly configured server, vulnerable application or outdated piece of technology didn't simply appear. Decisions, processes and behaviors inside the organization allowed that problem to develop.
The underlying issue could be poor software engineering, inadequate lifecycle planning, unclear ownership, bad incentives, weak governance, inefficient processes or an IT function that isn't operating effectively.
Fix those underlying problems and companies can potentially eliminate entire categories of cybersecurity risk rather than paying indefinitely to mitigate them.
Greg shares the example of a SaaS company with a large number of software vulnerabilities. Instead of building a bigger application-security function to continually find and fix vulnerabilities, the company addressed weaknesses in its engineering practices.
Within 12 months, vulnerabilities fell by 87% — without adding more security work.
But the benefits went far beyond cybersecurity. The application became more reliable, customer renewals improved, engineering turnover dropped and the company's AWS bill fell by €2.3 million.
The security vulnerabilities were signals of a much bigger business problem.
Cybersecurity as a Quality Problem
One of Greg's most useful ideas is surprisingly simple:
Treat cybersecurity vulnerabilities as quality defects.
If a manufacturer repeatedly discovers the same defect, management doesn't simply build a bigger department to repair defective products forever. It asks what is happening earlier in the process that's creating the defect.
Greg argues that companies should apply the same thinking to cybersecurity.
- Why wasn't the software patched?
- Why was the system misconfigured?
- Why is unsupported legacy technology still operating?
- Why was insecure software developed?
- Why wasn't the technology lifecycle planned?
- Why did employees have access to systems they didn't need?
Keep asking "why" and eventually the conversation moves away from cybersecurity technology and toward management, processes, organizational structure, incentives, accountability and leadership.
That's where Greg believes many cybersecurity problems really begin.
Why Blaming Employees Misses the Point
Companies frequently describe employees as their biggest cybersecurity weakness.
Greg challenges that assumption.
If a marketing intern clicks a phishing link and that action can bring down a company's critical financial systems, the real question isn't simply why the employee clicked.
Why was one employee's mistake capable of causing so much damage?
There should have been multiple layers of organizational and technical protection between that phishing email and a critical production environment.
Blaming the employee can prevent companies from investigating the systemic failures that made the incident possible.
Why Cybersecurity Is a Leadership Issue
Many CEOs, CFOs and other senior executives assume cybersecurity belongs to IT because they don't consider themselves technically qualified to make cybersecurity decisions.
Greg believes that can be a costly mistake.
Executives don't necessarily need deep technical cybersecurity expertise. They already understand many of the skills needed to address the underlying problems: accountability, incentives, governance, organizational structure, quality, investment decisions and operational efficiency.
In fact, Greg argues that once executives understand cybersecurity from first principles, they may be better positioned to make the strategic decisions that improve security than people looking at the problem exclusively through a technical lens.
Cybersecurity becomes a business management problem — not simply an IT problem.
What You'll Learn in This Episode
Jane and Greg discuss:
• Why cybersecurity spending keeps increasing without eliminating cyber risk
• Why cybersecurity vulnerabilities should be treated as quality defects
• How poor engineering practices create security vulnerabilities
• Why fixing root causes can be cheaper than continually mitigating cyber risk
• How organizational health affects cybersecurity
• Why IT processes, governance and incentives deserve more attention
• Why executives don't need to be cybersecurity experts to improve security
• How cybersecurity problems can expose waste elsewhere in the organization
• Why blaming employees for phishing attacks can hide larger systemic failures
• How IT and business alignment affects cyber risk
• Why adding more cybersecurity technology isn't always the answer
• How continuous improvement and root-cause analysis can be applied to cybersecurity
• Why CEOs and CFOs should take a more active role in cybersecurity strategy
• How better technology management can improve security, productivity and profitability at the same time
00:00 Why cybersecurity may not be a technology problem
02:22 What cybersecurity gets wrong
09:13 Fixing the cause instead of the vulnerability
12:13 When cybersecurity is really an organizational problem
16:19 Why CEOs should rethink cybersecurity
23:15 Why blaming employees misses the real problem
24:28 Does more cybersecurity spending make you safer?
Questions This Episode Answers
Why do companies keep getting hacked despite spending more on cybersecurity?
Greg argues that companies frequently spend money mitigating vulnerabilities without addressing the organizational behaviors and processes creating those vulnerabilities.
Is cybersecurity really an IT problem?
Technology is certainly involved, but many vulnerabilities originate in management decisions, software development practices, lifecycle planning, incentives, governance and organizational structure.
Can better business processes improve cybersecurity?
Yes. Greg's approach focuses on improving the underlying processes that produce technology, reducing the number of vulnerabilities that need to be managed later.
Should CEOs understand cybersecurity?
Executives don't necessarily need to understand the technical details of hacking. They do need to understand how organizational decisions create or reduce risk.
Are employees really the weakest link in cybersecurity?
Greg argues that blaming an employee for clicking a phishing link can miss the bigger issue: the organizational and technical failures that allowed one mistake to cause significant damage.
Does spending more money on cybersecurity make a company safer?
Not necessarily. Greg discusses why the maturity of IT and business processes — and alignment between IT and the business — can be more important than simply buying more cybersecurity tools.
How can companies reduce cybersecurity costs?
Instead of continually paying to mitigate recurring vulnerabilities, Greg recommends tracing security problems upstream and addressing the processes, behaviors and organizational structures that create them.
The Bigger Takeaway
Cybersecurity vulnerabilities aren't just threats that need to be managed.
They're clues.
They can reveal poor engineering, inefficient IT operations, weak governance, bad incentives, outdated systems and other organizational problems that may already be costing the company money.
Get more B2B insights:
Subscribe to A Seat at The Table's newsletter for weekly B2B strategy:
https://seat.fm/join-our-newsletter/
Learn how to build a consistent B2B marketing system:
https://seat.fm/marketing-mentor/
Connect with Greg van der Gaast: https://www.linkedin.com/in/gregvandergaast/
Sequoia Consulting: https://sequoia-consulting.co.uk
Visit A Seat at The Table's website at https://seat.fm