Leadership1 distinct publisher3 min readUpdated
Spending is forecast to climb from $213B to $240B while average breach costs hit a record, up 12%. The gap is measurement, and the man arguing it sells the fix.
The Board Room · Leadership desk
Compiled by The Board RoomSomething wrong?How this is made
Kirk Hanratty, CTO and co-founder of the security firm SynerComm, used a Forbes Tech Council column to make an argument most CISOs already suspect: organizations hold more security controls than at any point in history and still get breached, and the reason is that almost nobody measures whether the controls work [1][4]. The numbers he cites make the case awkward for anyone drafting next year's budget.
Global cybersecurity spending has risen every year since 2020, hitting a record $213 billion in 2025 and forecast by Gartner to reach $240 billion in 2026 [2]. Over the same period, according to Hanratty, the average cost of a data breach hit a record high in 2026, up 12% year over year [3]. The forecast spending increase is about $27 billion, or roughly 12.7% [5]. Which means the line going up on the cost side and the line going up on the defence side are moving at almost the same rate [6]. Buying more has not bought less loss.
His diagnosis is that programs are instrumented for existence, not efficacy. Most can tell you which controls are deployed and whether they are configured to a standard; almost none can tell you whether those controls are tuned to stop an attacker today [4]. The measurement history goes in stages: does the control exist, then is it configured correctly, and neither answers whether it does its job now, which depends on how it integrates with everything else [7].
The examples are the useful part. A VPN, or the secure web gateway that replaced it, can be configured exactly as designed and have nothing to do with why an attacker got in, because the decision that mattered - whether a password was guessable - was handed off through an authentication protocol to the directory underneath [8]. Multi-factor authentication is assumed to close that gap, until you find the legacy protocol that never supported it or the privileged account someone excluded to keep an old tool running [9]. AI workflows are the current version: an attacker crafts input that talks a model into ignoring its own guardrails, and no configuration review catches it [10].
The proposed answer is efficacy testing on a cadence - purple team exercises against documented attack behaviour, a baseline, and a feedback loop that tunes the stack against what the test found and tests again [11][12]. Where testing risks breaking production, such as account lockouts on identity systems, SynerComm says it uses manual playbooks rather than automated tools [13].
Read the conflict clearly. SynerComm sources, deploys and configures security technology and also sells continuous penetration testing, which is the product this argument recommends [14][15]. Hanratty pre-empts the objection by noting his firm does not operate the technology and that the client directs and approves every configuration [14], and by invoking the PCI DSS rule that a penetration tester be organizationally independent from whoever manages the tested system [16]. That rule exists because the conflict was familiar enough to need writing down [16].
Two things to watch. First, the breach-cost figure: the column attributes the spending numbers to Gartner but names no source for the 12% increase [17], so ask for the provenance before it lands in a board deck. Second, whether your own attestations are load-bearing. Attestation checks a point in time [18]; a stack that was correct 18 months ago is an assertion about 18 months ago.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Global cybersecurity spending has climbed every year since 2020 and hit a record $213 billion in 2025, forecast to reach $240 billion in 2026, per Gartner.
Security measurement moved in stages: first 'Does the control exist?', then 'Is it configured correctly?'. Neither tells you whether the control does its job today, which depends on how well it was integrated with the rest of the stack.
SynerComm sources, deploys and configures security technology for clients but does not operate it; the client directs and approves every configuration to meet their standards.
SynerComm also provides continuous penetration testing as an independent measure of whether the resulting stack prevents, detects and responds to real attack behavior.
PCI DSS requires that a penetration tester be organizationally independent from whoever manages or maintains the system being tested, a rule written because this conflict was already familiar enough to need one.
Attestation checks a point in time.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Thin: one contributed column, no independent data
The cluster contains a single source, a Forbes Tech Council column written by the CTO and co-founder of a firm selling the recommended service. Two statistics carry the premise: the spending figures are relayed secondhand with only a parenthetical Gartner attribution and no report named, and the 12% breach-cost rise has no attribution at all. The technical failure modes described — identity handoff, MFA exclusions, AI guardrail bypass — are plausible practitioner observations presented without a single documented engagement, test result or measured outcome.
No adoption signal in the supplied source
The column contains no release, deployment, benchmark, pricing or usage disclosure that could be counted. Its only adoption-adjacent statements are unquantified vendor descriptions — 'some clients run this as a broad simulated attack', 'others schedule quarterly purple team exercises', 'most enterprise environments have outsourced 24x7 detection and response' — with no counts, dates, named customers or measured uptake. Inferring adoption from these would be guessing.
Overstated: absolute prescription, no outcome evidence
The diagnosis is defensible and familiar, but the prescription is stated absolutely — purple team testing against documented attack behavior is framed as 'the only way to know' a control works — while nothing in the source measures whether that loop reduces breach frequency, cost or detection time. The headline spend-versus-loss parallel is used to imply that current programs fail and validation testing is the remedy, a causal step the numbers do not carry, and one of the two numbers is unattributed. Alternatives such as automated simulation tooling or exposure-management programs are not weighed against the recommended approach.
Strong and disclosed commercial interest
The author is CTO and co-founder of SynerComm, which the column states sources, deploys and configures security technology and separately sells continuous penetration testing — precisely the validation service the piece argues is the only reliable measure. The venue is a Forbes Tech Council contributed slot, a membership channel rather than edited reporting. The dual role is disclosed, and the column even invokes the PCI DSS independence rule and questions vendors who self-fund validation out of retainer credit, but the same independence logic is not turned back on a firm that both configures a client's stack and sells the testing of it.
Low: single interested source, no corroboration
Confidence is limited by structure rather than by internal inconsistency. The column is coherent and its failure modes are recognisable, and the vendor relationship is disclosed openly. But with one publisher, one interested author, no adoption signal, and the pivotal breach-cost figure unsourced, nothing here can be independently confirmed from the supplied material. The descriptive claims about the firm's own practice are reliable as self-report; the general and prescriptive claims are not verifiable.
leadership
Gartner says agents aren't ready; 60% of companies plan to deploy them anyway1 distinct publisher
leadership
The AI bill nobody reconciles: cost per finished task, not per million tokens1 distinct publisher
invest
Prevalent AI takes $22m after nine years of self-funding, and points it at financial crime1 distinct publisher
product
APIs built for human judgment now answer to agents that have none1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 19, 2026