Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Organizational stubbornness—refusing to revisit security assumptions, priorities, or practices—can leave known risks untreated and make a security program look stronger on paper than it performs in practice. The harm is not that stubbornness has been measured as a direct cause of breaches; it is that resistance to evidence can block decisions, controls, testing, and learning that reduce business risk.

How can stubbornness hurt an organization’s cybersecurity?

Security choices affect whether the organization can keep operating, protect sensitive information, and recover from disruption. CISA advises senior leaders to involve CISOs in decisions about company risk and to communicate that security investment is a priority. When leadership treats security as an IT concern alone, or repeatedly defers controls without accepting the associated risk, operational convenience or near-term cost can silently become the deciding policy.

The consequences are visible in decisions and outcomes: basic protections remain incomplete, monitoring goes unexamined, incident reporting is unclear, or response plans are never exercised. These are governance and implementation problems, not proof that a personality trait caused an incident. CISA’s cross-sector report highlights uneven foundational protections, challenges prioritizing investment at small and medium organizations, varying maturity, and insufficient attention to operational technology (OT) cybersecurity. Organizations should adapt U.S. government guidance to their own legal and operating environments.

What happens when leadership ignores security advice?

Advice that is repeatedly deferred can leave a known exposure in place without a deliberate business decision about its consequences. CISA asks organizational IT leadership: “Can the organization accept the business risk of NOT implementing critical security controls such as MFA?” The question makes the trade-off explicit: if a critical control is declined, who accepts the risk, for how long, and what compensating measures or review date apply?

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A CISA red-team assessment illustrates why confidence is not enough. In one assessment requested in 2022 at a large critical-infrastructure organization, the team obtained persistent network access and moved laterally without detection during the assessment; MFA stopped access to one sensitive business system. CISA published the advisory on February 28, 2023. This is a specific assessment, not a measure of how often organizations are vulnerable. It does show that a program described as mature can still have consequential detection gaps, alongside controls that work.

How can we tell whether a security program is actually working?

Compare written commitments with observed performance. The following are practical diagnostic contrasts drawn from CISA and NIST guidance, not a published scoring framework.

Look beyond Ask for evidence of
Stated policy Controls operating as intended in the actual environment, with gaps tracked to an accountable owner and decision date.
IT-only ownership Executive and business participation when decisions weigh risk, cost, and operational impact.
Training completion Evidence that awareness efforts support the intended workforce attitudes and behaviors.
Plans on paper Exercised incident response and tested continuity for critical functions.
Uniform investment assumptions Risk-based priorities that account for organization size, constraints, and OT systems as well as IT.

Test controls and review logs

CISA recommends monitoring logs and assessing controls rather than relying on stated confidence. Ask whether monitoring would identify unauthorized access and lateral movement, who reviews the relevant logs, and how findings lead to remediation. Testing should reflect the real environment and the systems whose compromise would affect business operations.

Check whether employees can escalate concerns

Employees need documented incident-reporting thresholds and channels they can use. CISA advises leaders to set those thresholds and, in heightened-threat guidance, lower them. If staff are unsure what merits escalation or fear that reporting will be dismissed, warning signs may not reach responders in time.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Exercise response and continuity

CISA recommends involving business leaders and board members in tabletop exercises and testing continuity. An exercise should reveal whether decision-makers know their roles, whether response plans work under realistic constraints, and whether critical functions can continue. A plan that has not been exercised provides limited evidence of readiness.

Measure awareness by its intended effect

Training completion records show participation, not necessarily changed behavior. Haney and Lutters’ November 26, 2024 NIST-hosted case study describes a year-long study of a U.S. government agency shifting its awareness program away from a compliance focus toward workforce attitudes and behaviors. The publication reports no numerical outcome to generalize; it is a case study, not a universal causal test. Its useful lesson is to define the behavior or impact an awareness effort is meant to support, then assess that rather than completion alone.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should executives do when security competes with cost or convenience?

  1. Bring security into the decision. Give the CISO a role when leadership weighs risk, cost, and operational impact, consistent with CISA’s corporate-leadership guidance.
  2. Make deferred controls explicit. For a postponed or declined protection such as MFA, record the business risk, the accountable decision-maker, any compensating measure, and when the decision will be reviewed.
  3. Prioritize by risk and context. Address foundational protections and consider OT exposure, operational dependencies, and the resource constraints that can affect small and medium organizations. CISA’s cross-sector report describes uneven maturity and prioritization challenges; one-size-fits-all expectations can obscure the most consequential gaps.
  4. Fund evidence, not just assurances. Support log monitoring, control assessment, and follow-up on identified weaknesses. Ask for findings and remediation status rather than treating policy documents or a maturity label as proof of effectiveness.
  5. Include leadership in readiness work. Set reporting thresholds, involve business leaders and board members in exercises, and test continuity for critical functions so the organization can identify practical obstacles before an incident.
  6. Connect incidents to ongoing risk management. NIST SP 800-61 Rev. 3, published in April 2025 and superseding Rev. 2, aligns incident-response recommendations with the Cybersecurity Framework 2.0’s cybersecurity risk-management approach. Treat response planning, lessons learned, and risk decisions as connected work rather than separate compliance tasks.

These steps do not guarantee prevention. They make it harder for convenience, habit, or unexamined assumptions to substitute for an explicit, testable decision about risk.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.