Why do organizations keep investing in cybersecurity without feeling more secure? In this episode of CYBR.Minded, Dr. Dustin Sachs and cybersecurity executive, educator, and CISO Tradecraft co-host Ross Young explore why bigger budgets, more tools, and expanding control frameworks do not always reduce risk. They discuss threat-based planning, stronger metrics, tool sprawl, ineffective risk registers, outdated compliance requirements, and how leaders can focus limited resources on the threats and safeguards that matter most.
Things mentioned:
- Dr. Eric Cole - https://www.cybrsecmedia.com/in-appreciation-of-dr-eric-cole/
- Security Theater - https://www.schneier.com/essays/archives/2009/11/beyond_security_thea.html
- CISO Series - https://cisoseries.com
- Cybersecurity's Dirty Secret: Why Most Budgets Go to Waste By Ross Young - https://a.co/d/0ijQYNHw
- Cyber Defense Matrix - https://cyberdefensematrix.com
- CISO Tradecraft - https://www.cisotradecraft.com
- CISO Retreat - https://www.cisotradecraft.com/cisoretreat
- Recognition Is a Cybersecurity Control: What Challenge Coins Teach Us About Behavior Change - https://www.linkedin.com/pulse/recognition-cybersecurity-control-what-challenge-us-dr-dustin-kav1c/
Do you have a question for the host? Reach out to us at media@cscgroupllc.com
In this episode:
- Host: Dr. Dustin Sachs
- Guest: Ross Young
- Director: Bill Brenner
- Producer: Lauren Andrus
- Editor: Ivan Basconcillo
Produced in partnership with Psybercog Labs
Keep up with our Conferences and Events:
Keep up with CYBR.SEC.Media:
Learn About CYBR.SEC.Careers Non-Profit Efforts
Subscribe to the podcast:
Listen to our other shows: