#1756062: Why Do We Keep Complaining About the Same Issues in Cybersecurity?
| Description: |
The clichés that say nothing Some phrases show up in security commentary so often they've stopped carrying any meaning at all. Nancy Free of Armor Defense pointed to two of the worst offenders: "we take your security seriously," which she noted is "found in every post-breach letter to impacted parties. Great... glad you're serious NOW," and "it's not if you get breached, but when," which she called "the security equivalent of 'we all die eventually.' Technically true. Operationally useless." The market's own commentary, others argued, is just as guilty of recycling empty lines. John T., global CISO at BMS Group, put it down to "the immaturity of some commentators and the market as a whole," rattling off repeat offenders like "cyber is no longer just an IT issue," as though it ever wasn't, and "GRC is not just about policies," when the name already says so, along with "boards don't understand information/cyber security" and "cyber now threatens life," which he noted isn't new either given how much history already demonstrates it. A discipline without shared answers The repetition may point to something more structural than tired phrasing. Shawn P Riley argued that security still operates on experience and opinion rather than shared models or measurable outcomes, which is why the same questions keep resurfacing, "not because they're new, but because they're never actually resolved." In a more mature field, he said, these debates would converge into frameworks and evidence-based answers. "Instead, we keep re-litigating them from scratch, influenced by role, organization, or vendor narrative." Until that changes, the pattern won't either. Adrian G., CISO at Solenis, traced the same recycling back to the role itself, arguing it isn't a LinkedIn problem but "a role-design problem." Reporting lines, board communication, and business alignment keep resurfacing because the CISO role "was never structurally positioned to resolve them." Old topics, new lenses Not everyone agreed that repetition is a flaw. Todd Fitzgerald of McCormick School of Engineering pushed back on the idea that recurring topics are stagnant, arguing that where they "seem the same," different time periods and lenses are producing different solutions. He compared it to accounting. For example, an accountant today still has to talk about balance sheets, income statements, cash flow, and ROI. "This doesn't make these concepts obsolete or solved," he said. "We need to give our 30+ year CISO evolution a break." That repetition, others said, is doing real work for a changing audience. Dale Werner PhD, PsyD-c of mindloft argued "advocacy and education requires repetition," since what feels "tired and repetitive" to a veteran can be "interesting and insightful" to someone newer to the field, and consistent, knowledge-backed repetition "might nudge some to move in a consistent direction." A people problem, not a security problem Timing may explain more of the repetition than anyone wants to admit. Mike Rerick of DSG Supply suggested that everyone sits at a different point in the same cycle, noting a topic like CISO reporting lines "may not be relevant to you until you are the CISO and feel some of the issues or constraints others have felt before," and what feels tired to someone who's already lived through the struggle can be "fresh and new" to someone still catching up. That gap, others said, has less to do with security than with people. Jonathan Waldrop, CISO at Acoustic, framed it as human nature rather than industry immaturity, since topics stay topics "because it's complicated, and 'your mileage may vary... We still have to tell people to eat healthy, exercise, get the vaccine, and wash your hands," he said. "I don't think it's a security problem. I think it's a people problem." |
|---|---|
| More info: | https://www.linkedin.com/pulse/why-do-we-keep-complaining-same-issues-cybersecurity-cisoseries-iazcc/ |
| Date added | Oct. 1, 2026, 11:41 p.m. |
|---|---|
| Source | |
| Subjects |
