I beg to differ
Cybersecurity has become a victim of its own effectiveness
So, apart from the months of disruption and lost sales at Co-op, M&S, JLR, it's been a superb year for ITSec?
Cybersecurity professionals were the most overlooked workers in IT when it came to pay rises in 2025, according to new figures from recruiter Harvey Nash. The trend was especially stark in the UK, where 77 percent of all security staff saw no salary increase, although the pattern was observed globally too with 71 percent of …
Consider that part of the problem might be local effectiveness. If one company has not experienced any incidents, they may not be too worried about someone else that has unless someone comes along to scare them. Corporate leadership don't tend to spend much time reading about security incidents that happened to someone else, especially when compared to IT people who read IT news, so they no little about those incidents, and if they do, they probably assume there's a reason why those companies were attacked and their one wasn't, a reason other than scale and luck. Security teams usually don't think they need to bring scare stories to management because they have the same context as you do and assume management is aware of that. In my experience, it's also seen as unethical to exaggerate threats or speculate about what an attack on this company might look like, the approaches most likely to increase support for adding resources to security.
It is if you're a lawyer .. have I've been in the wrong profession all these years :o
Rigbyfinancial.co.uk: “As we head into 2026, cyber threats look set to continue dominating the risk landscape, with the need for robust cover switching from ‘nice-to-have’ to ‘must-have’. In response, insurers are tightening terms, raising premiums, and demanding proof of strong cybersecurity practices before offering cover. Policies are also evolving to tackle new threats like deepfakes, AI-enhanced phishing and supply chain vulnerabilities.”
If there's one thing that anyone who's worked in the IT field for a while will know to be true is that the team that's constantly firefighting - most often due to their lack of ability - are the ones that are praised. Because they're always running around, doing this, doing that, sending emails about downtime and patching, and the other busywork, they're the ones the business sees as 'working hard'.
Whereas the team that's got everything running properly, has scheduled maintenance windows and staff who actually know and understand what they're doing at the micro and macro levels, they're getting ignored because they're essentially invisible.
Honestly, it's a disgrace. It's a failure of management to see and recognise where the work and effort is going and what it is achieving - but then again, when have management ever had vision or brought about success?
IT nowadays is akin to a utility - water, gas, electricity - everyone just expects it to work. Would you praise your electricity supplier if they had to turn the power off every second Tuesday or your water supplier if the water pressure varied from day to day between a trickle and gush?
water, gas, electricity - everyone just expects it to work.
In a few place those historic expectations are not always being met. Not infrequently from the same root causes of the dismal reliabilty and resilience historically exhibited by IT.
I have certainly seen successful teams retrenched with the roles/work out·sourced on the unspoken assumption that those teams couldn't have been doing much if they weren't being noticed. The out·sourced replacement are invariably very soon "noticed" and very frequently thereafter.
There is no doubt that communicating metrics to management in this field helps lift the profile of these teams, but only if done properly and only if the higher levels are actually receptive and supportive of the work. If you have a good manager that communicates well and is trusted by the C-suite, that also understand risk, threats, etc, then it's all good (mostly). If you have a poor management chain (like a CISO that claims every nmap scan or ping-sweep as an attack, then you're on a hiding to nothing.
I spent a long time as a meat-shield for a large software/hardware supplier in the US. I was good enough at it that no researcher broke the responsibile disclosure timescales. One of the products was, and still is, a dumpster fire of security nastiness. In part due to me and tthe team, the leadership just deprioritised fixing security. It burned me out. It's still a dumpster fire. I still won't have it in my new company.
Yes, we're doing well to protect, but incidents are still on the rise, and recent NCSC, Microsoft, Government security alerts, as well as our own experiences are showing a rise...
Maybe we're at 'peak' Cyber protection - and the attackers are winning whatever we do from now on... ?
are they rising? yes.
It isn't due to lack of cybersec people. It is due to lack of /good/ cybersec people, and deliberate management decisions. But mostly, management.
Security problems come from the C level. Cybersecurity people try to change that, but they will fail, as long as high-level managers are making stupid decisions with security being literally the last priority (look at actions, not words -- last. absolute...last).
You know the saying, "security isn't a product"? Well, security also isn't a team. You can't buy a product and become secure, you can't hire a team and become secure.
We are not at "peak cyber protection" -- we are in a valley, and we keep digging.
I'm not at all surprised that management neglects roles that essentially are about prevention.
As the late Trevor Kletz often said regarding the chemical industry: "if you think safety is expensive, try having an accident", which IMO should be chiseled into the forehead of everyone in a management position.
the problem in IT is that security problems AREN'T expensive enough.
Managers keep their jobs -- even the ones that directly CAUSED the problem in the first place.
Customers complain, but keep buying from the same vendors.
The media portrays the attackers as the bad guys, and the company as the victim.
Business insurance pays damages.
Zero accountability.
There are some companies that violate every security standard and just shouldn't be allowed to continue to exist. But instead, those companies are generally the lowest bidder. Doing the job right is too expensive.
Unfortunately, I think there needs to be a "corporate death penalty" -- where companies are just instantly shutdown. Stockholders lose 100% of their value. C-level managers are required to repay the previous year's bonuses and have a lifetime ban from taking a similar role at any future employer. Customers and vendors are screwed without compensation, as they should have been doing the "due diligence" thing, they weren't, share the pain. It is something that should be used rarely, but its possibility should be on every manager's mind during at every decision they make.