The Cybersecurity Investment Trap: Why More Technology Won’t Fix How Your Organisation Behaves

Cybersecurity depends on culture, incentives and behaviour as much as technology.

By Tobias Ander | edited by Patricia Cullen | Sep 25, 2026
Shutterstock

Opinions expressed by Entrepreneur contributors are their own.

You're reading Entrepreneur United Kingdom, an international franchise of Entrepreneur Media.

When a business identifies a cybersecurity problem, the instinctive response is often to buy something. A new endpoint platform. Better identity management. Another monitoring tool. More sophisticated email protection. An AI-powered security solution. That response is understandable. Technology is tangible. It can be demonstrated, procured, implemented and measured. A board can approve a budget, a supplier can deliver a product, and a project team can report that the solution is live. Behaviour is much harder.

You cannot purchase a security culture, install it over a weekend or summarise it in a single dashboard. Yet organisations continue to invest heavily in technology while paying much less attention to the conditions in which people actually make security decisions. This is not an argument against cybersecurity technology. Strong technical controls are essential. The mistake is expecting technology to solve problems that are fundamentally organisational. Some of the most difficult security failures emerge in the gap between the formal process and what somebody decides to do when faced with a real deadline, a real customer and an inconvenient security control. An employee shares information through an unapproved service because the authorised platform makes a simple task difficult. A manager asks someone to bypass a process because a customer is waiting. A team starts using a public AI tool because the approved alternative is unavailable or too restrictive.

These decisions are often described simply as people “breaking the rules.” That explanation is convenient, but incomplete. Most employees are not trying to make their organisations less secure. They are trying to get their jobs done. When sensible people repeatedly find reasons to work around a control, that behaviour may be telling management something important about the organisation itself.

Growth exposes the gap between policy and reality
This becomes particularly visible in growing businesses. In a small company, security can depend heavily on informal trust and direct communication. Everyone knows who owns what. Exceptions can be discussed quickly. If somebody is unsure, they know whom to ask. Then the organisation grows. New employees arrive. More suppliers become involved. SaaS platforms multiply. Teams adopt their own tools. Data starts moving across more systems and more organisational boundaries. What worked when there were 30 employees may become unsafe when there are 300. The natural response is to formalise. More policies are written. More approval processes are introduced. More technical controls are added. Some of that is necessary. But if the organisation adds controls without understanding how work actually gets done, security begins to create friction. Once that friction becomes high enough, people find alternatives.

During my time as CISO in the Swedish Armed Forces and the Swedish Transport Agency, I saw how controls that looked perfectly reasonable on paper could collide with operational reality. That gap is where security culture becomes visible. The useful question for a business leader is therefore not simply whether people are following the security process. It is why sensible people sometimes decide not to. A workaround may indicate carelessness. But it may also reveal an approval process that takes too long, a tool that does not fit the work, conflicting incentives or a manager who has made delivery more important than compliance. If management treats every workaround as an employee problem, it risks addressing the symptom while leaving the cause untouched.

We measure what is easy, not always what matters
Technology also gives leaders something culture rarely does: clean metrics. Executives can see how many attacks were blocked, how many endpoints are protected and how quickly systems are patched. Similar thinking has gradually shaped the human side of cybersecurity. We measure how many employees completed training, how many passed a quiz and how many clicked a simulated phishing message. Those figures may be useful, but they are primarily activity metrics. They do not necessarily tell us whether behaviour has changed.

An organisation can have a 100% training completion rate while managers routinely bypass controls to meet deadlines. Employees can pass phishing tests and still hesitate to report a genuine mistake because they fear the consequences. The more important questions are harder to reduce to a dashboard. Do people know what to do when a situation does not fit the policy? Do they report problems quickly? Do managers demonstrate the same security behaviours they expect from their teams? When the same issue happens repeatedly, does the organisation prescribe more training, or does somebody ask whether the process itself is contributing to the behaviour? Awareness matters. Training matters. But awareness alone rarely creates lasting behavioural change. Knowing the correct answer in an annual training module is very different from making the right decision when a customer is waiting, a deadline is approaching and the secure process takes twice as long.

Security culture is therefore not simply an IT issue. It is shaped by what leaders reward, what managers tolerate, how processes are designed and what happens when somebody makes a mistake. If an organisation says security is important but rewards managers almost exclusively for speed and delivery, employees notice. If the policy says one thing while senior leaders routinely do another, employees notice that too. And if somebody admits a mistake and is immediately blamed, everyone watching learns something about the organisation’s real priorities. Next time, they may keep quiet.

Stop designing security for perfect people
Many security approaches still depend on an unrealistic assumption: that people will make the correct decision every time. They will recognise the malicious email. They will use the approved system. They will not share the wrong information. They will not take a shortcut under pressure.
Real organisations do not work like that. People make mistakes. The important question is what happens when they do. If a single imperfect decision can cause serious consequences, the problem may not simply be that somebody failed. The system may have depended too heavily on human perfection. A resilient organisation assumes that mistakes, misunderstandings and unexpected situations will happen. Technology should limit the consequences, but the organisation also needs an environment in which problems are reported early and recurring workarounds are treated as information about how the business functions. That requires a different leadership conversation.

Instead of asking only whether another security product is needed, business leaders should ask where people are working around controls and why. They should understand what happens when an employee reports a mistake and which behaviours the organisation is actually trying to influence, rather than settling for the vague ambition of making people “more aware.”
And perhaps most importantly, they should occasionally ask an uncomfortable question: Are we buying another technology because it genuinely addresses a well-understood risk — or because buying technology is easier than changing the way our organisation works?
Cybersecurity technology remains essential. But it cannot compensate indefinitely for poor incentives, unclear responsibilities, badly designed processes or a culture in which people hide mistakes. The strongest organisations therefore do not choose between technology and behaviour. They design them together.

They make secure behaviour easier rather than harder. They use workarounds as feedback. They examine mistakes without automatically assuming that the person is the problem. And they judge security not only by what has been installed or completed, but by how the organisation actually behaves when reality becomes inconvenient. Buying another security tool may take weeks. Changing the conditions in which people make decisions requires sustained leadership attention. That is precisely why the organisational side of cybersecurity is easier to postpone.
But if organisations continue investing in technology while neglecting behaviour, incentives and culture, they should not be surprised when technical strength and operational reality drift apart.
You can patch software. You cannot patch culture.

When a business identifies a cybersecurity problem, the instinctive response is often to buy something. A new endpoint platform. Better identity management. Another monitoring tool. More sophisticated email protection. An AI-powered security solution. That response is understandable. Technology is tangible. It can be demonstrated, procured, implemented and measured. A board can approve a budget, a supplier can deliver a product, and a project team can report that the solution is live. Behaviour is much harder.

You cannot purchase a security culture, install it over a weekend or summarise it in a single dashboard. Yet organisations continue to invest heavily in technology while paying much less attention to the conditions in which people actually make security decisions. This is not an argument against cybersecurity technology. Strong technical controls are essential. The mistake is expecting technology to solve problems that are fundamentally organisational. Some of the most difficult security failures emerge in the gap between the formal process and what somebody decides to do when faced with a real deadline, a real customer and an inconvenient security control. An employee shares information through an unapproved service because the authorised platform makes a simple task difficult. A manager asks someone to bypass a process because a customer is waiting. A team starts using a public AI tool because the approved alternative is unavailable or too restrictive.

These decisions are often described simply as people “breaking the rules.” That explanation is convenient, but incomplete. Most employees are not trying to make their organisations less secure. They are trying to get their jobs done. When sensible people repeatedly find reasons to work around a control, that behaviour may be telling management something important about the organisation itself.

Tobias Ander • Information security leader

Tobias Ander is an information security leader and senior advisor specialising in information security culture,... Read more

Related Content