Skip to content

Taming tool sprawl: Streamlining cyber security programme performance

Aug 2026 · International Conference on Cyber Security And Protection Of Digital Services · Vol 10, pp. 97 · 0 citations

TL;DR

The paper concludes that a disciplined focus on validation enables financial institutions to reduce exposure, improve returns on existing investments, and provide more meaningful, evidence-based reporting to senior stakeholders.

Abstract

Financial services institutions face increasing pressure from regulators, boards, and customers to demonstrate the effectiveness of their cyber security controls. Many organisations, however, operate extensive portfolios of security tools without clear evidence that these investments deliver measurable risk reduction. This paper examines the operational and governance challenges associated with tool sprawl and introduces the concept of ‘security debt’ as the accumulation of unvalidated exposures and misconfigurations. Drawing on practitioner experience and industry research, it argues that the core issue is not the absence of technology but the lack of systematic validation of control effectiveness. The paper proposes a structured four-phase model to streamline cyber security programme performance: baseline, integrate, remediate what matters, and automate and scale. The model emphasises alignment with recognised frameworks, including MITRE ATT&CK, the National Institute of Standards and Technology Cybersecurity Framework, the Center for Internet Security Critical Security Controls, and the Digital Operational Resilience Act, alongside continuous measurement of control performance. By shifting from activity-based to effectiveness-based metrics, organisations can improve visibility, prioritise remediation, and strengthen governance. The paper concludes that a disciplined focus on validation enables financial institutions to reduce exposure, improve returns on existing investments, and provide more meaningful, evidence-based reporting to senior stakeholders. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.

View source

Similar papers

Review Open access Sep 2026

Cybersecurity In Fintech Ecosystems: A Systematic Review of Threats and Security Strategies

The study demonstrates the importance of an integrated and versatile cybersecurity architecture that includes multi-vector threat monitoring, behavioural analytics, intelligent fraud detection and risk management that can improve detection capabilities, minimize false positives, boost data protection and increase the c...

Vedankita Mohod, R. Jugele · 0 citations
Review Sep 2026

Measuring Cybersecurity Investment Effectiveness: Linking Risk Reduction Metrics to Digital Transformation Value Outcomes

In emerging markets, the strategic conundrum is similar, with financial institutions investing big in cybersecurity and lacking a clear path to measurement of impact on outcomes of digital transformation at the firm level. With the theory and insights provided by Resource Based View and the economics-of-information-sec...

Afeniforo Ayodele Augustine · 0 citations
Open access 2026

Cybersecurity In The Tunisian Banking Sector Comprehensive assessment of cyber risk management, governance, resilience and digital transformation

The digital transformation of the Tunisian banking sector has profoundly altered the ways in which financial services are accessed, transactions are processed and data is managed. This development simultaneously increases the attack surface of banking institutions and the importance of cybersecurity for financial stabi...

Houda Jendoubi · 0 citations
Sep 2026

Beyond the Checklist: Modernizing Cybersecurity Regulation for the U.S. Power Grid

The NERC CIP standards have been mandatory for more than fifteen years and are widely regarded as a baseline for securing the bulk power system, yet little is known about how the people who implement, audit, and write them experience the regulatory lifecycle in practice. Drawing on interviews with twenty two auditors,...

Sena Şahin, Burak Sahin, Robin Berthier et al. · 0 citations
Open access 2026

Examining the Impact of Cybersecurity Investment on Organizational Performance in Bosaso, Somalia

In the 20th century, the increasing reliance on technology by organizations has led to a significant rise in cyber threats, including malware, ransom ware, and phishing attacks. These threats pose serious challenges to business success, jeopardizing the availability, integrity, and confidentiality of organizational ass...

Mohamed Abdirisak Burale, Aedah Binti Abd Rahman, Prof, Dr. Syed Sajjad Hussain Rizvi · 0 citations
Open access Sep 2026

The Adaptive Deficit: An Evolutionary Governance Perspective on Information Security

Despite growing regulation and mature security tooling, cyberattacks continue to rise. This study examines how information security professionals perceive the challenges of securing modern systems. More specifically, we consider increasing technological complexity, the human factor, organizational change, and resilienc...

Emmanouil Mavrofidis, Aikaterini Tsatsaroni, A. Kameas · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.