CPS-149 · Impact

When Security Spend Runs Ahead of Basic Controls — and the Cost of Protection That Misses the Basics

Security tools can be necessary. They cannot compensate indefinitely for weak identity control, overdue patching, unmanaged access, untested recovery and unclear operational ownership.

Mellorca Impact·Digital Infrastructure·5 September 2026

The tolerated pain

Organisations sometimes respond to each security concern with another product while basic controls remain inconsistent. The technology stack grows, but administrators still share accounts, critical systems remain unpatched or recovery is assumed rather than tested.

Operational consequence

More products create alerts, licences, integrations and configuration that also need owners. If foundational controls are weak, security teams can spend more time operating tools without proportionately reducing exposure.

How it becomes money

security control cost = product spend + implementation + administration + unresolved residual exposure

The last term cannot be converted into a credible currency value without business-specific scenarios. Instead, track whether the controls associated with material risks are actually implemented and tested.

CISA’s published cybersecurity essentials emphasise fundamentals including multifactor authentication and prompt software updating. Those controls are not the whole security programme, but they illustrate why basic hygiene must accompany product investment.

Commercial triggerIf the business can list security products more easily than it can prove MFA coverage, patch discipline, access ownership and recoverability, spend may be stronger than control maturity.

Resolution

  1. Map material business risks to required controls.
  2. Close foundational identity, patching and recovery gaps first.
  3. Measure control coverage and exceptions.
  4. Remove or consolidate tools that duplicate capability.
  5. Assign operational owners for every retained control platform.
  6. Test whether controls work, not merely whether licences exist.

Bottom line

Security maturity is not measured by product count. It is measured by the organisation’s ability to prevent, detect, contain and recover from relevant failures.

Source

CISA: Four Cybersecurity Essentials.