The Cybersecurity Paradox: Why Execution Trumps Visibility
Here’s a paradox that keeps me up at night: we’ve never invested more in cybersecurity, yet we’ve never felt more vulnerable. It’s like buying the most advanced lock for your front door, only to leave the back door wide open. This disconnect was the centerpiece of Alan de Waal-Smit’s recent remarks at the ITWeb CISO Retreat, and it’s a point that deserves far more attention than it gets.
What makes this particularly fascinating is the shift in focus from visibility to execution. For years, the cybersecurity industry has sold us on the idea that seeing every threat is the ultimate solution. But de Waal-Smit, head of sales at ITR Technology, argues that knowing isn’t enough—acting is. It’s a simple yet profound distinction. Personally, I think this is where most organizations are failing. They’re drowning in data, alerts, and telemetry but lack the workflows to turn that information into action.
The Silo Problem: A Tale of Two Teams
One thing that immediately stands out is the tension between IT operations and security teams. De Waal-Smit calls it a “silo problem,” and he’s spot on. IT wants stability; security wants speed. It’s like two pilots fighting over the controls of a plane mid-flight. What many people don’t realize is that this isn’t just a technical issue—it’s a cultural one. These teams often have conflicting KPIs, and as de Waal-Smit notes, attackers don’t care whose metrics get hurt.
If you take a step back and think about it, this silo problem is a symptom of a larger issue: the fragmentation of cybersecurity tools and processes. Detection and response are often treated as separate entities, managed by different teams with different tools. This raises a deeper question: why do we still operate in such a disjointed way when the threats we face are increasingly interconnected?
The Cost of Inaction: Beyond the Headlines
The IBM Cost of Data Breach Report 2025 puts the average breach cost in South Africa at R44.1 million. That’s a staggering number, but what’s more alarming is the trend behind it. Despite the drop from the previous year, breaches are becoming more frequent and more damaging. A detail that I find especially interesting is the rise of third-party involvement in breaches, which jumped from 15% to 30% in just one year. This suggests that our supply chains are becoming our weakest links.
Credential abuse, according to the Verizon Data Breach Investigations Report, remains the top initial access vector. What this really suggests is that we’re still losing the battle against basic, preventable threats. It’s not that we lack the tools; it’s that we lack the execution.
The Solution: A Unified System of Action
De Waal-Smit’s proposed solution is deceptively simple: shift from two systems of record to one system of action. In my opinion, this is where the real innovation lies. By integrating IT service management with security operations, organizations can create a single workflow that prioritizes threats based on business context, not just severity.
What makes this particularly fascinating is the potential for automation. Threats become tickets, alerts are filtered before they overwhelm analysts, and response times shrink dramatically. From my perspective, this isn’t just about efficiency—it’s about resilience. When IT and security are aligned, the organization becomes more agile, more proactive, and ultimately, more secure.
The Broader Implications: A Cultural Shift
If there’s one takeaway from all this, it’s that cybersecurity isn’t just a technical problem—it’s a cultural one. The tools are there, but the mindset isn’t. We’re still treating security as an add-on, a separate function, rather than embedding it into every aspect of our operations.
This raises a deeper question: how do we change that culture? It starts with leadership. CISOs need to stop being seen as the “department of no” and start being viewed as enablers of business continuity. It’s about breaking down silos, fostering collaboration, and redefining success.
Final Thoughts: The Execution Imperative
As I reflect on de Waal-Smit’s insights, one thing is clear: execution is the new frontier of cybersecurity. Visibility is important, but it’s only half the battle. What this really suggests is that we need to rethink our approach entirely. It’s not about buying more tools; it’s about aligning people, processes, and technology.
Personally, I think this is a call to action for the entire industry. We need to stop chasing the next shiny tool and start focusing on what really matters: execution. Because at the end of the day, it’s not the threats that beat us—it’s our inability to act on them.