top of page
Abstract Digital Mesh

The Cyber Security Independence Problem We Still Haven’t Fixed

Aug 14
3 min read

After more than a decade on the commercial side of cyber security, I’ve had conversations with literally hundreds of organisations across enterprises in every sector, financial services, government, healthcare, education, legal, technology and the broader mid-market.


I’ve worked alongside vendors, consultancies, internal security teams, CISOs, CIOs, risk leaders, auditors, assessors and boards.


And after 10 years, there is one thing I still find surprising:


Organisations continue to put an enormous amount of trust in the same provider to design their security, implement it, operate it, assess it and then tell them whether it is working.


In almost any other part of business, we would immediately recognise the conflict.


You wouldn’t normally ask the person who designed a financial control to independently audit whether that control was designed correctly.


Yet in cyber security, it happens constantly.


The same consultancy might:


design the security architecture;


implement the controls;


provide the managed IT service;


operate the SOC;


manage compliance;


conduct the annual assessment;


perform the penetration test; and


present the results back to management or the board.


Sometimes they are effectively the architect, builder, operator, auditor, blue team and red team at the same time.


That doesn’t automatically mean the work is poor.


There are some outstanding security providers capable of delivering across all of those disciplines.


The issue is independence.


Who is checking the checker?


If your security provider designed the environment, implemented the controls and continues to manage them, how comfortable are they going to be identifying fundamental problems with their own work?


If your SOC provider is responsible for detecting and responding to attacks, should that same organisation be the one conducting the red team exercise designed to determine whether the SOC can actually detect an attacker?


If your compliance consultant spent months preparing you for an assessment, should they also be the organisation providing the independent assurance that the environment meets the required standard?


Perhaps everything is working perfectly.


But independent assurance exists precisely because we shouldn’t have to rely on perhaps.


Cyber security needs constructive tension


Good security benefits from different perspectives.


The architect should expect their design to be challenged.


The blue team should expect someone independent to try to bypass their controls.


The SOC should expect an external team to test whether its monitoring actually detects realistic attacker behaviour.


The organisation implementing a security framework should expect someone else to assess whether the controls genuinely meet the intent of that framework.


That tension is healthy.


It creates better outcomes.


A strong red team isn’t there to prove the blue team is incompetent. It is there to find the assumptions, blind spots and gaps that inevitably emerge in complex environments.


Likewise, an independent assessor isn’t there to undermine the implementation partner. Their role is to provide confidence that the organisation is receiving the outcome it believes it has paid for.


Independence doesn’t mean replacing your existing providers


This is probably the biggest misconception.


Independent assurance is not an argument for constantly changing vendors.


Quite the opposite.


If you have a good MSP, MSSP, SOC provider, security consultancy or internal team, keep them.


But occasionally bring in someone whose only job is to challenge the environment independently.


Let one team build it.


Let another test it.


Let your security provider defend it.


Let an independent red team attack it.


Let your implementation partner help you achieve compliance.


Let someone else verify it.


The objective isn’t to create friction between providers.


It is to create confidence for the organisation.


After a decade, my view is pretty simple


Cyber security has become increasingly sophisticated, but our approach to assurance sometimes hasn’t.


We invest heavily in technology, managed services, frameworks, certifications and consulting.


Then we ask the organisations delivering those services to provide much of the assurance over their own work.


For something as important as cyber security, organisations should be asking a very simple question:


Who independently validates the people we already trust?


Trust your security partners.


Build long-term relationships with them.


But every so often, give someone independent permission to try to prove them wrong.


That is where real assurance starts.


Darcy Sudholz

 
 
bottom of page