The People, Process, And Technology Security Control Stack

Seven questions will change how you think about cybersecurity.

Who defines the direction of the company? Who owns the data? Who allocates and approves capital and operational expenses? Who is responsible for business risk? Who defines which data is most important and how strongly it should be protected? Who defines the most critical business processes? Who applies security controls and manages protection of the data?

Six of those seven answers point to business leadership. One points to IT.

So why does executive leadership delegate cybersecurity responsibility to IT?

This is the question the cybersecurity industry does not want you to ask. The answer exposes a structural problem running through organizations of every size across every industry. For decades, the industry has told you people, process, and technology are all important. What it has not told you is their order of importance, or why the order matters.

The Hierarchy Your Security Team Already Knows

The security profession teaches a defense strategy as a three-part hierarchy. People first. Procedures second. Technology third. The order is not arbitrary. It reflects an uncomfortable reality about how organizations actually fail.

The 2024 Verizon Data Breach Investigations Report reported that 68% of breaches involved a human element (Verizon Business, 2024). Errors, privilege misuse, and social engineering. A person made a decision. A person clicked a link. A person shared a password. The technology did not fail. The person using it did.

I have watched this pattern repeat across four decades of advisory work on five continents. The details change. The pattern never does.

Why People Matter More Than Procedures

People create risk. People also prevent it. Every security control, every procedure, every piece of technology depends on a human being choosing to follow the rules or choosing not to.

Employees repeat security mistakes even after awareness training. Phishing simulations expose the same susceptibility in the same people, year after year. Training alone does not change behavior. As authentication expert Andrew Shikiar has noted, for a procedure like multifactor authentication to be adopted and sustained, it needs to be easy to use. If a critical security procedure is inconvenient, employees will find ways around it. Every time.

Attackers understand this better than most defenders do. They exploit urgency, trust, and fear to bypass security protocols. The manipulation works regardless of what procedures are in place. You have seen this in your own organization. I am confident of it.

People make decisions, sometimes in error and sometimes with intent, to bypass any control standing between them and their immediate objective. Getting the job done takes priority over following the security policy. Even the most perfectly designed process is breakable when faced with human unpredictability.

Why Procedures Matter More Than Technology

If people matter more than procedures, the next question follows naturally. Why do procedures matter more than technology?

The reason is simple. Technology does not do what you want it to unless you tell it to.

A security camera is a technical control. A documented process for monitoring the camera and responding to an alarm is what provides the security. Without the process, the camera is a recording device with no one watching. A firewall is a technical control. A flawed configuration process leaves it open. The technology did not fail. The process governing the technology failed.

In the event of a breach, technology reports an incident. Procedures govern the human response. They dictate how the company will contain the breach, investigate the cause, and recover operations. Without a clear response process, a technical alert is a notification with no action behind it.

Technology automates what humans have defined. It does not replace the thinking behind the definition.

Why Many Organizations Get This Backward

Here is the problem. Many businesses, if not most, invert the hierarchy. They prioritize technology over procedures, and procedures over people. The reason is not complicated. Money and business leadership.

Over the years, business leaders have been convinced cybersecurity is too complex for them to consider. It needs an IT focus and IT decision making to get it right, or so the argument goes.

Pick this statement apart thread by thread. Nothing could be further from the truth. Go back to those seven questions. Business leadership is responsible for six of the seven answers. IT is responsible for one.

The problem runs deeper than executive delegation. Many cybersecurity professionals evolved up through IT. They built careers configuring firewalls, deploying endpoints, and managing networks. Technology is the lens through which they see every problem. Procedures and people are afterthoughts, acknowledged but rarely prioritized. Risk as a financial concept, the potential for measurable dollar loss, almost never enters the conversation.

Security vendors understand this perfectly. They court the technology-first buyer because the technology-first buyer speaks their language. The sales cycle is shorter when the buyer already believes the answer is a product. Nobody in the room asks whether the organization knows what it is protecting or why.

So the technology budget grows. The procedure library stagnates. The people problem goes unaddressed. The result is predictable. Organizations spend more on security technology every year while breaches continue at the same rate or worse. The hierarchy is inverted. The investment follows the inversion.

Admiral Mike Rogers, former Director of the National Security Agency, wrote in Harvard Business Review about this exact failure. Technical controls create a false sense of security. Strong cybersecurity depends on culture and procedures, not technology alone. This was true in 2015 when he wrote it. It remains true today.

What This Means For Your Business

The hierarchy is not academic. It has direct financial consequences.

If your security investment prioritizes technology over the people and processes governing it, you are spending money in the wrong order. The technology may be excellent. The procedures may exist on paper. But if the people executing those procedures are not trained, not accountable, and not engaged, the investment sits on sand.

The question is not how much to spend on cybersecurity. The question is whether you are spending on the right things in the right order.

Where To Start

Torsetti Labs research has examined these questions and many more. The answers are available in two forms, both at no cost to you.

Download Cybersecurity Needs YOU at TorsettiLabs.com. It is a free guide written specifically for business leaders who want to understand their role in cybersecurity before investing another dollar. Read it. Consider the questions. Look at what your answers would be for your own organization.

Then, when you are ready to act, You Are the Target, the first book in the Small Business Executive Cyber Risk Series, is available at TorsettiLabs.com/books. It will show you exactly what happens when business leadership does not own the cybersecurity conversation and what to do about it.

Your greatest vulnerability has a desk, a salary, and good intentions. The hierarchy of people, process, and technology exists for a reason. Start at the top.


Sources

Verizon Business 2024 (verizon.com/business/resources/reports/dbir) | 68% of breaches involved the human element.

Rogers, M. (2015). Cybersecurity’s Human Factor, Lessons from the Pentagon. Harvard Business Review. https://hbr.org/2015/09/cybersecuritys-human-factor-lessons-from-the-pentagon


Dr. Stuart Broderick is the founder of Torsetti Labs and a cybersecurity executive with four decades of experience across five continents. His work sits at the intersection of business operations and information security governance.

TorsettiLabs.com | San Antonio, Texas


Dr. Stuart Broderick is the founder of Torsetti Labs and the author of the Business-Driven Cybersecurity series. He has 40 years of practitioner experience across five continents.

Share:

More Posts

Send Us A Message