Back to Insights Vulnerabilities

Lean Cybersecurity: A fascinating article on the paradox of how increasing cybersecurity investments can actually increase cyber risks.

When the Solution Becomes the Problem
When Do More People and More Management Layers Weaken Defense?
For many years, a simple concept dominated organizations: to protect ourselves from cyber threats, we need to invest more. More money, more senior managers, and more complex management structures.
But a recent study published in the prestigious MIT Sloan Management Review challenges this assumption.
The study, which included interviews with 34 senior security executives (such as CISOs and CIOs), found that expanding the management hierarchy in the cyber field may actually create an illusion of security. Instead of improving the organization’s resilience, this managerial complexity creates procedural risk – a type of risk that won’t appear in scanning tools or technical reports.
The Self-Confidence Trap
Three Ways Multiple Management Layers Exacerbate Risk
The study identifies a central psychological bias – “Illusory Superiority” – which strengthens as the management structure grows.
Here are the three main risks caused by this:

False sense of readiness: As a threat is perceived as more severe (for example, a major ransomware attack), managers tend to become more confident in their ability to handle it – even more so than other organizations. Frequent discussion of threats creates a sense of control and readiness, even if the actual ability to handle the event has not been tested in practice.
Blurred responsibility: Multiple management layers cause everyone to assume that someone else is handling the issue. Field employees assume IT managers are responsible, IT assumes senior managers are responsible, and senior management assumes the top executive tier is responsible. The result? No one feels they are the sole owner of the risk, and gaps remain open.
Ignoring the field: Senior managers tend to undervalue the knowledge and experience of technical personnel on the ground. The assumption that a managerial rank reflects the highest level of expertise can lead to ignoring warnings or critical recommendations from employees who know the systems in depth.

Less Complexity, More Resilience
How to Build Effective Cyber Leadership?
The study doesn’t just diagnose the problem, it also offers a practical solution:
Lean Management: Instead of adding layers, it is recommended to adopt a lean and clear management model. For most organizations, a structure where one senior manager is absolutely and clearly responsible for the cyber domain (with full authority) is more efficient than a branching hierarchical system.
Anonymous External Benchmarking: The best way to break the illusion of self-confidence is through measurement against others. Sharing threat intelligence and readiness data with similar organizations – in an anonymous and controlled manner – provides a more reliable reality check and shows where the organization actually stands, not just how it sees itself.
Recommendations from IPV Security Professionals

Reduce management layers and sharpen clear responsibility for cyber risk (who exactly is responsible for what).
Encourage a culture where information from the field reaches management without barriers and delays.
Measure actual readiness through exercises and tests, and not just through presentations and declarations.
Compare capabilities against similar organizations, and do not rely solely on internal “gut feelings.”
Separate the need to “project confidence” to customers or investors from a sincere, uncompromising internal risk assessment.

In Conclusion,
The study’s central conclusion is clear: cyber resilience is not the result of a large and bloated structure, but of aware, humble, and illusion-free leadership. Organizations that identify human biases in decision-making processes and build their structure around clarity, responsibility, and listening will be much better prepared for the next cyber event.
In an era where cyber threats are only intensifying, perhaps the right question isn’t how much money we invested – but how we are managing that risk.
For more information: https://cisoteria.com/lean-cybersecurity-reduce-risk/

Continue the Conversation

Facing a cybersecurity challenge? Let's talk about how a managed program can strengthen your resilience.

Start a conversation