• About
  • Subscribe
  • Contact
Wednesday, May 7, 2025
    Login
  • Management Leadership
    • Growth Strategies
    • Finance
    • Operations
    • Sales and Marketing
    • Careers
  • Technology
    • Infrastructure and Platforms
    • Business Applications and Databases
    • Big Data, Analytics and Intelligence
    • Security
  • Industry Verticals
    • Finance and Insurance
    • Manufacturing
    • Logistics and Transportation
    • Retail and Wholesale
    • Hospitality and Tourism
    • Government and Public Services
    • Utilities
    • Media and Telecommunications
  • Resources
    • Whitepapers
    • PodChats
    • Videos
  • Events
No Result
View All Result
  • Management Leadership
    • Growth Strategies
    • Finance
    • Operations
    • Sales and Marketing
    • Careers
  • Technology
    • Infrastructure and Platforms
    • Business Applications and Databases
    • Big Data, Analytics and Intelligence
    • Security
  • Industry Verticals
    • Finance and Insurance
    • Manufacturing
    • Logistics and Transportation
    • Retail and Wholesale
    • Hospitality and Tourism
    • Government and Public Services
    • Utilities
    • Media and Telecommunications
  • Resources
    • Whitepapers
    • PodChats
    • Videos
  • Events
No Result
View All Result
No Result
View All Result
Home Technology Security

Gartner: Adopt a minimum effective mindset to maximise cybersecurity value

FutureCIO Editors by FutureCIO Editors
June 8, 2023
Photo by Andrea Piacquadio: https://www.pexels.com/photo/shallow-focus-photo-of-man-reading-newspaper-3799099/

Photo by Andrea Piacquadio: https://www.pexels.com/photo/shallow-focus-photo-of-man-reading-newspaper-3799099/

“Many CISOs are burnt out and feel they have little control over their stressors or work-life balance,” said Henrique Teixeira, senior director analyst at Gartner. “Cybersecurity leaders and their teams are putting in the maximum effort, but it’s not having maximum impact.”

CISOs must embrace a “Minimum Effective” mindset to maximise cybersecurity’s impact for the business.

“A Minimum Effective mindset is a deliberate, ROI-driven approach to leading cybersecurity into the future,” added Leigh McMullen, distinguished VP analyst at Gartner. “While the idea of ‘minimum’ may seem uncomfortable, it refers to the inputs, not the outcomes. This approach will enable cybersecurity functions to go beyond merely ‘defending the fort’ to unlocking their true potential to create tangible value.”

Below are four myths (or misconceptions) and how to security leaders can create new value across business engagement, technology and talent.

Debunking Myths that Obscure Cybersecurity's Full Value l Gartner Security & Risk Management Summit

Myth #1: More data equals better protection

It’s commonly believed that the best way to drive action from executive decision-makers on cybersecurity initiatives is through sophisticated data analysis, such as calculating the likelihood of a cyber event occurring. However, it is not practical to quantify risk in this way. Further, this approach does not deliver shared accountability between cybersecurity and enterprise decision-makers necessary for materially reducing business risk. Gartner research has found that just one-third of CISOs report success driving action through cyber risk quantification.

“Rather than continuing to pursue more data and more analysis, savvy CISOs engage in a Minimum Effective Insight approach. Determine the least amount of information needed to draw a straight line between the enterprise’s cybersecurity funding and the amount of vulnerability that funding addresses.”

Henrique Teixeira

CISOs should use an outcome-driven metrics (ODM) approach to action Minimum Effective Insight. ODMs link security and risk operational metrics to the business outcomes they support by explaining the levels of protection currently in place and the alternative protection levels available based on spend.

Myth #2: More technology equals better protection

Worldwide spending on information security and risk management products and services is forecast to grow 12.7% to reach $189.8 billion in 2023. Yet even as organisations spend more on cybersecurity tools and technologies, security leaders still feel they are not properly protected.

“Cybersecurity often gets stuck in a gear acquisition mindset, believing that around the corner there must be something better,” said McMullen. “Instead, CISOs must embrace a Minimum Effective Toolset – the fewest technologies required to observe, defend and respond to exposures. This will enable cybersecurity to own their architecture, reducing the complexity and lack of interoperability that makes it so difficult to generate value from technology investments.”  

Organisations can begin the journey to a Minimum Effective Toolset by taking a human-cost view, keeping the overhead on cyber professionals managing cybersecurity tools lower than the benefit of the tool in mitigating risks. In parallel, take an architectural view to measure whether any given tool is additive to or subtractive of, the ability to protect the enterprise. Cybersecurity mesh architecture (CSMA) principles can also support security in designing for simplicity, composability and interoperability.

Myth #3: More cybersecurity professionals equal better protection

Leigh McMullen

“Demand for cybersecurity talent has outstripped supply to the point that CISOs are unable to catch up. Security is a massive bottleneck to digital transformation, and a lot of that is because of a myth that only cybersecurity professionals can do serious cyber work. Democratising cybersecurity expertise, rather than trying to hire out of the talent gap, is the solution.”

Leigh McMullen

Gartner predicts that by 2027, 75% of employees will acquire, modify or create technology outside IT’s visibility, up from 41% in 2022. CISOs can reduce the burden on their teams by helping these business technologists build Minimum Effective Expertise or cyber judgment. A recent Gartner survey found that business technologists with high cyber judgment are 2.5 times more likely to consider cybersecurity risks when developing analytics or technology capabilities.

Myth #4: More controls equal better protection

A recent Gartner survey found that 69% of employees have bypassed their organisation’s cybersecurity guidance in the past 12 months, and 74% of employees would be willing to bypass cybersecurity guidance if it helped them or their team achieve a business objective.

“Cybersecurity organisations are well-aware of the pervasive non-secure behaviour of the workforce, but the typical response of adding more controls is backfiring,” said Teixeira. “Employees report a huge amount of friction involved with secure behaviour, which is driving unsecure behaviour. Controls that are circumvented are worse than no controls at all.”

Minimum Effective Friction rebalances cybersecurity’s assessment of the performance of security controls to prioritise user experience rather than technical functionality alone. Gartner predicts that by 2027, 50% of large enterprise CISOs will have adopted human-centric security design practices to minimise cybersecurity-induced friction and maximise control adoption.

Related:  Drive business growth with a true cloud ERP
Tags: cybsecurityGartnerminimum effective mindset
FutureCIO Editors

FutureCIO Editors

No Result
View All Result

Recent Posts

  • Agentic AI-powered AppSec platform launched for the AI era
  • IDC forecasts GenAI alone will grow at a 59.2% CAGR
  • Dataiku brings new AI capabilities to create and control AI agents
  • Microsoft reveals the rise of a new kind of organisation in the AI era
  • St Luke’s ElderCare enhances data security and user experience with Juniper

Live Poll

Categories

  • Big Data, Analytics & Intelligence
  • Business Applications & Databases
  • Business-IT Alignment
  • Careers
  • Case Studies
  • CISO
  • CISO strategies
  • Cloud, Virtualization, Operating Environments and Middleware
  • Computer, Storage, Networks, Connectivity
  • Corporate Social Responsibility
  • Customer Experience / Engagement
  • Cyber risk management
  • Cyberattacks and data breaches
  • Cybersecurity careers
  • Cybersecurity operations
  • Education
  • Education
  • Finance
  • Finance & Insurance
  • FutureCISO
  • General
  • Governance, Risk and Compliance
  • Government and Public Services
  • Growth Strategies
  • Hospitality & Tourism
  • HR, education and Training
  • Industry Verticals
  • Infrastructure & Platforms
  • Insider threats
  • Latest Stories
  • Logistics & Transportation
  • Management Leadership
  • Manufacturing
  • Media and Telecommunications
  • News Stories
  • Operations
  • Opinion
  • Opinions
  • People
  • Process
  • Remote work
  • Retail & Wholesale
  • Sales & Marketing
  • Security
  • Tactics and Strategies
  • Technology
  • Utilities
  • Videos
  • Vulnerabilities and threats
  • White Papers

Strategic Insights for Chief Information Officers

FutureCIO is about enabling the CIO, his team, the leadership and the enterprise through shared expertise, know-how and experience - through a community of shared interests and goals. It is also about discovering unknown best practices that will help realize new business models.

Quick Links

  • Videos
  • Resources
  • Subscribe
  • Contact

Cxociety Media Brands

  • FutureIoT
  • FutureCFO
  • FutureCIO

Categories

  • Privacy Policy
  • Terms of Use
  • Cookie Policy

Copyright © 2022 Cxociety Pte Ltd | Designed by Pixl

Login to your account below

or

Not a member yet? Register here

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Management Leadership
    • Growth Strategies
    • Finance
    • Operations
    • Sales and Marketing
    • Careers
  • Technology
    • Infrastructure and Platforms
    • Business Applications and Databases
    • Big Data, Analytics and Intelligence
    • Security
  • Industry Verticals
    • Finance and Insurance
    • Manufacturing
    • Logistics and Transportation
    • Retail and Wholesale
    • Hospitality and Tourism
    • Government and Public Services
    • Utilities
    • Media and Telecommunications
  • Resources
    • Whitepapers
    • PodChats
    • Videos
  • Events
Login

Copyright © 2022 Cxociety Pte Ltd | Designed by Pixl

Subscribe