The Cybersecurity Paradox: Why Execution Trumps Visibility
Here’s a paradox that keeps me up at night: we’ve never invested more in cybersecurity, yet we’ve never felt more vulnerable. It’s like buying the most advanced lock for your front door, only to leave the back door wide open. This disconnect was the centerpiece of Alan de Waal-Smit’s recent remarks at the ITWeb CISO Retreat, and it’s a point that, in my opinion, cuts to the heart of our collective cybersecurity dilemma.
What makes this particularly fascinating is how it flips the narrative. For years, the industry has fixated on visibility—more tools, more data, more dashboards. But de Waal-Smit, head of sales at ITR Technology, argues that visibility is a red herring. The real gap isn’t in seeing threats; it’s in acting on them. Personally, I think this is a game-changer. It’s like realizing you’ve been staring at a map for so long that you forgot to actually start the journey.
The Silo Problem: A Tale of Two Teams
One thing that immediately stands out is the tension between IT operations and security teams. De Waal-Smit calls it a “silo problem,” and he’s spot on. IT wants stability; security wants speed. It’s a classic clash of priorities, and what many people don’t realize is how this internal friction becomes an attacker’s best friend. The attacker doesn’t care about your KPIs or departmental turf wars—they just exploit the gaps.
If you take a step back and think about it, this isn’t just a technical issue; it’s a cultural one. Organizations pour money into tools but neglect the alignment of their teams. From my perspective, this is where the real vulnerability lies. Tools are only as good as the people and processes behind them.
The Numbers Don’t Lie—But They Don’t Tell the Whole Story
The IBM Cost of Data Breach Report 2025 puts the average breach cost in South Africa at R44.1 million. That’s down 17% year-on-year, which might sound like progress. But here’s the kicker: breaches are still costing tens of millions, and the Verizon Data Breach Investigations Report highlights that credential abuse remains the top entry point for attackers.
A detail that I find especially interesting is the rise in third-party involvement in breaches—up from 15% to 30%. This raises a deeper question: are we outsourcing our risks without outsourcing accountability? What this really suggests is that our supply chains are becoming our weakest links, and visibility alone can’t fix that.
The Shift to a System of Action
De Waal-Smit’s solution? Move from two systems of record to one system of action. This isn’t just about integrating tools; it’s about integrating mindsets. Detection and response shouldn’t live in separate worlds. When IT and security share a workflow, the results are clear: faster response, less noise, and real prioritization.
But here’s where it gets tricky. Treating IT service management as your security control plane requires a fundamental shift in how organizations operate. It’s not just about technology; it’s about breaking down silos and redefining roles. Personally, I think this is where most organizations will stumble. Change is hard, especially when it challenges established power dynamics.
The Broader Implications: Beyond the Breach
What this conversation really highlights is the gap between strategy and execution. We’re great at planning, but terrible at implementing. This isn’t unique to cybersecurity—it’s a problem across industries. But in cybersecurity, the stakes are higher.
If you ask me, the real lesson here is about alignment. Organizations don’t fail because they lack tools; they fail because they lack cohesion. This isn’t just a technical problem; it’s a leadership problem. Leaders need to stop treating IT and security as separate entities and start seeing them as two sides of the same coin.
Final Thoughts: The Execution Imperative
As I reflect on de Waal-Smit’s insights, one thing is clear: execution is the new frontier of cybersecurity. Visibility is important, but it’s only the first step. The real battle is fought in the trenches, where threats are detected, prioritized, and neutralized in real time.
In my opinion, the organizations that will thrive in this evolving threat landscape are the ones that prioritize execution over visibility. They’ll break down silos, align their teams, and treat cybersecurity as a system of action, not just a system of record.
So, the next time you hear someone talk about the latest cybersecurity tool, ask them this: How will it improve execution? Because at the end of the day, that’s what really matters.