Skip to content

Leadership1 publisher3 min readPublished

Your controls passed the configuration check. Nobody asked whether they stop attacks

Spending is forecast to climb from $213B to $240B while average breach costs hit a record, up 12%. The gap is measurement, and the man arguing it sells the fix.

The Board Room · Leadership desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • Kirk Hanratty is the CTO and co-founder of SynerComm, focused on proving controls stop real attacks, not just that they exist. He wrote that organizations have more security controls than at any point in history and still get hacked.
  • Global cybersecurity spending has climbed every year since 2020 and hit a record $213 billion in 2025, forecast to reach $240 billion in 2026, per Gartner.
  • The average cost of a data breach also hit a record high in 2026, up 12% year over year.
  • Most security programs can say which controls exist and whether they are configured to a standard; almost none can say whether those controls are tuned to actually stop an attacker right now.
  • The forecast increase in global cybersecurity spending from 2025 to 2026 is $27 billion, or approximately 12.7%.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

Kirk Hanratty, CTO and co-founder of the security firm SynerComm, used a Forbes Tech Council column to make an argument most CISOs already suspect: organizations hold more security controls than at any point in history and still get breached, and the reason is that almost nobody measures whether the controls work [1][4]. The numbers he cites make the case awkward for anyone drafting next year's budget.

Global cybersecurity spending has risen every year since 2020, hitting a record $213 billion in 2025 and forecast by Gartner to reach $240 billion in 2026 [2]. Over the same period, according to Hanratty, the average cost of a data breach hit a record high in 2026, up 12% year over year [3]. The forecast spending increase is about $27 billion, or roughly 12.7% [5]. Which means the line going up on the cost side and the line going up on the defence side are moving at almost the same rate [6]. Buying more has not bought less loss.

His diagnosis is that programs are instrumented for existence, not efficacy. Most can tell you which controls are deployed and whether they are configured to a standard; almost none can tell you whether those controls are tuned to stop an attacker today [4]. The measurement history goes in stages: does the control exist, then is it configured correctly, and neither answers whether it does its job now, which depends on how it integrates with everything else [7].

The examples are the useful part. A VPN, or the secure web gateway that replaced it, can be configured exactly as designed and have nothing to do with why an attacker got in, because the decision that mattered - whether a password was guessable - was handed off through an authentication protocol to the directory underneath [8]. Multi-factor authentication is assumed to close that gap, until you find the legacy protocol that never supported it or the privileged account someone excluded to keep an old tool running [9]. AI workflows are the current version: an attacker crafts input that talks a model into ignoring its own guardrails, and no configuration review catches it [10].

The proposed answer is efficacy testing on a cadence - purple team exercises against documented attack behaviour, a baseline, and a feedback loop that tunes the stack against what the test found and tests again [11][12]. Where testing risks breaking production, such as account lockouts on identity systems, SynerComm says it uses manual playbooks rather than automated tools [13].

Read the conflict clearly. SynerComm sources, deploys and configures security technology and also sells continuous penetration testing, which is the product this argument recommends [14][15]. Hanratty pre-empts the objection by noting his firm does not operate the technology and that the client directs and approves every configuration [14], and by invoking the PCI DSS rule that a penetration tester be organizationally independent from whoever manages the tested system [16]. That rule exists because the conflict was familiar enough to need writing down [16].

Two things to watch. First, the breach-cost figure: the column attributes the spending numbers to Gartner but names no source for the 12% increase [17], so ask for the provenance before it lands in a board deck. Second, whether your own attestations are load-bearing. Attestation checks a point in time [18]; a stack that was correct 18 months ago is an assertion about 18 months ago.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories