By Akash Dhobale, Sr. Manager – Cyber Security,
Canara Bank
Every year, organizations invest billions of dollars in
cybersecurity. Boards approve budgets, new platforms are procured, projects are
launched, and dashboards begin to fill with encouraging metrics—endpoints
protected, vulnerabilities reduced, alerts monitored, and compliance achieved.
The investment creates confidence. Unfortunately,
confidence is not the same as resilience.
Yet the headlines tell a different story. Organizations
with mature security programmes continue to experience ransomware attacks,
insider threats, supply-chain compromises, and operational disruption despite
significant investments.
This is not simply anecdotal. The Verizon 2026 Data Breach
Investigations Report (DBIR), based on more than 22,000 confirmed data
breaches, found that exploitation of software vulnerabilities accounted for 31%
of breaches, overtaking stolen credentials as the leading initial access
vector. The findings reinforce that resilient outcomes depend not only on
technology investments, but also on disciplined governance, timely execution,
and organizational capability.
This raises a question that deserves more attention than
the next technology trend: What if the greatest weakness in enterprise
cybersecurity is not the technology we buy, but the assumptions we make after
buying it?
The Illusion of Security
One pattern has become increasingly visible across large
enterprise transformation programmes. Organizations that struggle are rarely
those with inadequate technology. More often, they assume technology alone will
transform security outcomes. While technology transforms infrastructure,
sustainable cybersecurity depends on transforming the organization itself—a
fundamentally different leadership challenge.
During one enterprise cybersecurity transformation
programme, I expected the most difficult discussions to revolve around
architecture, deployment, and technical integration. Instead, the technical
workshops concluded relatively quickly. The conversations that demanded the
greatest leadership attention centred on governance, operational continuity,
ownership of risk, and stakeholder alignment. That experience fundamentally
changed my understanding of enterprise security. Technology was not the
limiting factor—organizational alignment was.
In that sense, the most expensive mistake is not the breach
itself. It is the false confidence that security has already been achieved.
Where Cybersecurity Actually
Becomes Difficult
My experience leading enterprise transformation initiatives
has taught me that technical problems are usually solved by engineers, whereas
organizational problems require leadership.
The difficult conversations begin after the technology is
selected. Who owns the risk? Can stronger controls coexist with business
continuity? How should regulatory expectations be balanced with operational
realities? How do security, operations, business, procurement, compliance, and
executive leadership make decisions that satisfy competing priorities without
weakening security?
These questions rarely appear on implementation dashboards,
yet they determine whether cybersecurity becomes embedded into the organization
or remains another completed project because leadership sets priorities,
governance establishes accountability, and culture shapes behaviour.
The Four Investments That
Determine Cyber Resilience
Technology provides the foundation for resilience.
Organizations should prioritize solutions that integrate well with business
processes, reduce operational complexity, and strengthen visibility rather than
simply increasing the number of security tools.
Governance establishes accountability. Clear executive
sponsorship, defined ownership of cyber risk, structured decision-making, and
regular governance reviews keep security aligned with business priorities.
People determine whether security controls succeed in
practice. Continuous awareness, role-based training, leadership communication,
and reinforcement of secure behaviours turn policies into everyday habits.
Organizational alignment connects technology, business,
operations, procurement, compliance, and executive leadership around shared
objectives so that cybersecurity becomes an enabler of transformation rather
than an obstacle to it.
A Better Measure of Success
Protected endpoints, deployment percentages, and compliance
scores are valuable operational metrics, but they are poor measures of
resilience. A better question is this: If a sophisticated cyberattack occurred
tomorrow, would the organization respond as one coordinated enterprise or as
disconnected departments protecting individual priorities? That answer reveals
far more about cyber maturity than any technology dashboard ever could.
Building Capability, Not Just
Infrastructure
Cybersecurity is no longer an IT initiative. Every
significant cyber incident becomes a business event affecting customers,
operations, reputation, regulatory confidence, and strategic decision-making.
Resilience must become part of organizational leadership.
Cybersecurity maturity is not determined by the
sophistication of the technology an organization owns, but by the consistency
with which its people make secure decisions.
The Question Every Board
Should Ask
Organizations will continue investing in cybersecurity
technologies, and they should. Innovation remains indispensable. However, the
greatest return on cybersecurity investment will not come from acquiring more
tools. It will come from strengthening the organizational capability to govern,
adopt, and continuously improve those tools.
Perhaps the most important boardroom question is no longer,
'Which security platform should we invest in next?' Instead, it should be,
'What organizational capability are we building alongside this investment?'
Technology can often be deployed within a quarter, but
organizational resilience is built gradually through consistent leadership,
governance, people, and disciplined execution. As the latest industry evidence
demonstrates, organizations do not become secure simply by purchasing better
technology; they become more resilient when technology investments are
reinforced by governance, people, and organizational alignment.