logo

Five Signs Your Organization Is Failing at Security

ID: 971a3b19-021e-5a34-b797-f244525c8bdf

STIX ID: report--971a3b19-021e-5a34-b797-f244525c8bdf

Feed Name: Black Hills Infosec Blog

Date Published: 2017-09-18

Date Updated: 2026-04-27

Author: BHIS

...
...

This piece outlines five signs of a failing InfoSec program—executive misunderstanding of security’s purpose (advise and oversee), improper reporting structures that bury security under IT, lack of executive ownership of policy, security leaders who politicize or dilute findings, and high staff turnover—while urging direct reporting to the executive leadership team, honest risk communication, establishing a staffing standard (e.g., 6–8% of IT headcount), and avoiding the “tool trap.” It concludes with a call to action for C-level leaders to own policies and elevate security, and for practitioners to push for improvements or move on if the organization remains unwilling to change.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.