The Most Expensive Mistake in Cybersecurity Isn't a Data Breach

By Akash Dhobale, Sr. Manager – Cyber Security, Canara Bank

Every year, organizations invest billions of dollars in cybersecurity. Boards approve budgets, new platforms are procured, projects are launched, and dashboards begin to fill with encouraging metrics—endpoints protected, vulnerabilities reduced, alerts monitored, and compliance achieved.

The investment creates confidence. Unfortunately, confidence is not the same as resilience.

Yet the headlines tell a different story. Organizations with mature security programmes continue to experience ransomware attacks, insider threats, supply-chain compromises, and operational disruption despite significant investments.

This is not simply anecdotal. The Verizon 2026 Data Breach Investigations Report (DBIR), based on more than 22,000 confirmed data breaches, found that exploitation of software vulnerabilities accounted for 31% of breaches, overtaking stolen credentials as the leading initial access vector. The findings reinforce that resilient outcomes depend not only on technology investments, but also on disciplined governance, timely execution, and organizational capability.

This raises a question that deserves more attention than the next technology trend: What if the greatest weakness in enterprise cybersecurity is not the technology we buy, but the assumptions we make after buying it?

The Illusion of Security

One pattern has become increasingly visible across large enterprise transformation programmes. Organizations that struggle are rarely those with inadequate technology. More often, they assume technology alone will transform security outcomes. While technology transforms infrastructure, sustainable cybersecurity depends on transforming the organization itself—a fundamentally different leadership challenge.

During one enterprise cybersecurity transformation programme, I expected the most difficult discussions to revolve around architecture, deployment, and technical integration. Instead, the technical workshops concluded relatively quickly. The conversations that demanded the greatest leadership attention centred on governance, operational continuity, ownership of risk, and stakeholder alignment. That experience fundamentally changed my understanding of enterprise security. Technology was not the limiting factor—organizational alignment was.

In that sense, the most expensive mistake is not the breach itself. It is the false confidence that security has already been achieved.

Where Cybersecurity Actually Becomes Difficult

My experience leading enterprise transformation initiatives has taught me that technical problems are usually solved by engineers, whereas organizational problems require leadership.

The difficult conversations begin after the technology is selected. Who owns the risk? Can stronger controls coexist with business continuity? How should regulatory expectations be balanced with operational realities? How do security, operations, business, procurement, compliance, and executive leadership make decisions that satisfy competing priorities without weakening security?

These questions rarely appear on implementation dashboards, yet they determine whether cybersecurity becomes embedded into the organization or remains another completed project because leadership sets priorities, governance establishes accountability, and culture shapes behaviour.

The Four Investments That Determine Cyber Resilience

Technology provides the foundation for resilience. Organizations should prioritize solutions that integrate well with business processes, reduce operational complexity, and strengthen visibility rather than simply increasing the number of security tools.

Governance establishes accountability. Clear executive sponsorship, defined ownership of cyber risk, structured decision-making, and regular governance reviews keep security aligned with business priorities.

People determine whether security controls succeed in practice. Continuous awareness, role-based training, leadership communication, and reinforcement of secure behaviours turn policies into everyday habits.

Organizational alignment connects technology, business, operations, procurement, compliance, and executive leadership around shared objectives so that cybersecurity becomes an enabler of transformation rather than an obstacle to it.

A Better Measure of Success

Protected endpoints, deployment percentages, and compliance scores are valuable operational metrics, but they are poor measures of resilience. A better question is this: If a sophisticated cyberattack occurred tomorrow, would the organization respond as one coordinated enterprise or as disconnected departments protecting individual priorities? That answer reveals far more about cyber maturity than any technology dashboard ever could.

Building Capability, Not Just Infrastructure

Cybersecurity is no longer an IT initiative. Every significant cyber incident becomes a business event affecting customers, operations, reputation, regulatory confidence, and strategic decision-making. Resilience must become part of organizational leadership.

Cybersecurity maturity is not determined by the sophistication of the technology an organization owns, but by the consistency with which its people make secure decisions.

The Question Every Board Should Ask

Organizations will continue investing in cybersecurity technologies, and they should. Innovation remains indispensable. However, the greatest return on cybersecurity investment will not come from acquiring more tools. It will come from strengthening the organizational capability to govern, adopt, and continuously improve those tools.

Perhaps the most important boardroom question is no longer, 'Which security platform should we invest in next?' Instead, it should be, 'What organizational capability are we building alongside this investment?'

Technology can often be deployed within a quarter, but organizational resilience is built gradually through consistent leadership, governance, people, and disciplined execution. As the latest industry evidence demonstrates, organizations do not become secure simply by purchasing better technology; they become more resilient when technology investments are reinforced by governance, people, and organizational alignment.