Security1 distinct publisher3 min readPublished
SecurityWeek argues the security job is recruited on technical depth and reviewed at budget time on cost and growth, and that mismatch, not any breach, is what costs the seat.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The mechanism the article describes ends in a sentence on a customer call, not in an incident report. A program built around an annual audit can say what a control did on the day someone checked it and nothing about the rest of the year, so when a buyer asks whether it is working now, most vendors can only say they think so [9]. The deal then waits for confirmation, and the same pause repeats across the pipeline [10]. Buyers are not being difficult; they ask because they have watched one weak vendor turn into their own breach [17].
Put the buyer side in absolute terms. More than half of over 3,000 enterprise technology buyers named data privacy and compliance their single most important concern, which is at least fifteen hundred purchasing organisations that rank it first [6]. Against that, compliance keeps getting heavier and teams do what the calendar allows: gather evidence once a year, then re-answer the same questions in each buyer's preferred format [18]. The article's line on this is worth keeping: the problem is design, not effort, and a program built to survive an annual audit will read as overhead however well it runs [16].
The framing has deeper roots than any single budget cycle. Success in the role has long been defined as proving a negative, showing that nothing went wrong, which positions the whole function as insurance rather than a business driver [3]. It does not help that at most companies the security review starts only after everyone else has agreed to proceed [7]. The SecurityWeek author, writing from a CEO seat, says he asks his CISO three things: how are you making us stronger, how are you helping us grow, and how will we recover [11]. His claim is that strength and recovery always get an answer and growth usually does not [12]. That is one boss's read, not a data set, and should be weighed as such.
What Dave Brown, CISO of Andesite and author of "The Lean CISO", described on Virtru's Hash It Out podcast is mostly not tooling. Sitting in on sales calls, keeping speed-dial access to the CRO, and maintaining an evidence library that turns multi-week security reviews into same-day answers [13] are scheduling and record-keeping decisions. Nothing in a recruitment process built around technical depth and security experience asks for any of them [2], which is a reasonable explanation for why they remain unusual.
The other half of the fix is scoreable targets. The article's worked example is a board asking for 50 percent growth and a security leader committing to specific items, such as earning the compliance certifications needed to sell into Europe within four months [15]. A dated certification can be marked pass or fail at review time in the same way a revenue number can. An absence of incidents cannot, which is precisely why the budget conversation keeps going badly for the people who only have that to offer.
Ranked by verification strength, evidence, and original report placement.
In McKinsey's early-2026 survey of more than 3,000 enterprise technology buyers, data privacy and compliance ranked as the single most important customer concern, named by over half of respondents, and providers falling short on security and compliance were increasingly excluded from consideration regardless of price or features.
The same McKinsey survey found that among buyers who switched providers in the past year, cybersecurity was the number one reason they left, ahead of price, coverage and reliability.
In PwC's 2025 global compliance survey, 72% of executives said the rising complexity of compliance over the past three years had hurt their company's profitability.
Speaking on Virtru's Hash It Out podcast, Dave Brown, CISO of Andesite and author of "The Lean CISO", described running security to move deals rather than gate them: he sits in on sales calls, keeps what he calls speed dial access to the CRO, and built an evidence library that turns security reviews that once took weeks into same-day answers.
Brown recounted a prospect whose CEO would not sign until he had spoken with the security leader directly; one conversation later the contract was signed on the call.
Compliance keeps getting heavier, so teams do what the calendar allows: collect evidence once a year and answer the same questions in slightly different formats for every buyer.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single contributed column resting on unlinked secondhand statistics
The cluster is one opinion piece by a CEO in a single publication. Its two quantitative pillars (McKinsey buyer survey, PwC compliance survey) appear only as secondhand citations with no links or methodology, the shorter-tenure premise cites 'industry surveys' generically, and the central argumentative claims about deal stalls and security being run last are unquantified authorial characterisation.
One named practitioner example
Observable adoption of the prescribed deal-facing security model amounts to a single secondhand disclosure from Andesite's CISO on a vendor podcast. Buyer-side pressure is asserted through survey citations, but no count of security organisations operating this way, no tooling deployment and no before/after metrics are supplied.
Prescription outruns its evidence
The column concludes that security can be 'one of the clearest sources of growth the leadership team has' and that the tools and data to work this way already exist, while its demonstration is one practitioner anecdote and an illustrative worked example. Directional claims about buyer scrutiny are plausible and externally sourced, which keeps the gap moderate rather than severe.
Executive thought-leadership with promotional attachments
The piece is written from the CEO seat advising security leaders and closes with a promotional pointer to the publisher's CISO Forum. Its supporting practitioner example is drawn from a vendor-run podcast and features a CISO promoting his own book, so both the platform and the cited voices have commercial reasons to frame security spend as a growth lever.
Directionally plausible, thinly verified
Confidence is limited by single-publisher sourcing, unverifiable secondhand statistics and a one-anecdote demonstration. What is firm is what the column itself says and the practice it reports; what remains unresolved is whether the shorter-tenure premise, the pipeline-stall mechanism or the growth payoff hold at scale.
invest
The card networks just picked the referee for agent checkout, and it looks like EMVCo2 distinct publishers
security
A North Korean IT worker got hired by a federal agency. Vetting is a security control now.1 distinct publisher
security
CISA orders Ray patched as RondoDox folds cluster software into a 174-exploit arsenal1 distinct publisher
security
Intel's 72 CVEs land in firmware, drivers and the AI tooling stack; AMD adds a dozen1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 24, 2026