---
title: Six ways security teams sabotage their own plans
description: Six ways security teams sabotage their own plans
image: https://businessinsights.bitdefender.com/hubfs/it-team.png
---

[![](https://businessinsights.bitdefender.com/hubfs/2021/09/logo-white.svg)](https://businessinsights.bitdefender.com/?hsLang=en-us)

[![CONTACT AN EXPERT](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd)

- [For Home](https://www.bitdefender.com/solutions/)
- [For Business](https://www.bitdefender.com/business/)
- [Resources](https://www.bitdefender.com/business/resource-library.html)
- [Webinars](https://www.bitdefender.com/business/webinars.html)

# [BUSINESS INSIGHTS](https://businessinsights.bitdefender.com/?hsLang=en-us)

[#Enterprise Security](https://businessinsights.bitdefender.com/topic/enterprise-security)

 By [**George V. Hulme**](https://businessinsights.bitdefender.com/author/george-v-hulme) / Jan 08, 2018

# Six ways security teams sabotage their own plans

Share this [![Share on email](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/email-color.png)](mailto:?subject=Check%20out%20https://businessinsights.bitdefender.com/six-ways-security-teams-sabotage-plans&utm_medium=social&utm_source=email%20&body=Check%20out%20https://businessinsights.bitdefender.com/six-ways-security-teams-sabotage-plans&utm_medium=social&utm_source=email) [![Share on twitter](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/twitter-color.png)](https://twitter.com/intent/tweet?original_referer=https://businessinsights.bitdefender.com/six-ways-security-teams-sabotage-plans&utm_medium=social&utm_source=twitter&url=https://businessinsights.bitdefender.com/six-ways-security-teams-sabotage-plans&utm_medium=social&utm_source=twitter&source=tweetbutton&text=) [![Share on linkedin](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/linkedin-color.png)](http://www.linkedin.com/shareArticle?mini=true&url=https://businessinsights.bitdefender.com/six-ways-security-teams-sabotage-plans&utm_medium=social&utm_source=linkedin) [![Share on facebook](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/facebook-color.png)](http://www.facebook.com/share.php?u=https://businessinsights.bitdefender.com/six-ways-security-teams-sabotage-plans&utm_medium=social&utm_source=facebook)

It’s not always the bad guys that sabotage enterprise security efforts, sometimes organizations do that all on their own.

Here are six common ways:

**Enterprises fail to plan**

Too many organizations fail to create an information security plan that is purpose-built for their organization. When the right plan is in place, enterprises are able to get the security controls they specifically need to do everything that needs to be done to keep people, apps, and data secure.

A good security plan involves not only technical and development teams, but also the lines of business, legal, human resources, internal audit, executives and the CEO and the board. It also uses data (internal and external) and feedback to measure its effectiveness and costs and improves over time.

Without a plan, the enterprise is at significant risk of floating mindlessly from one threat to another and never getting ahead of the risk.

**There’s no data classification**

This is another big one. Enterprises that don’t know where their most valuable data resides – or even what their most valuable data and applications are, are flying blind. When data is classified, enterprises know where to invest their security resources, based on such factors as business importance of the data and systems to the running of the business, financial value, regulatory mandates that may control that data protection, and such.

By classifying data, not only is investments in security better known, but such efforts will also help to inform other areas of the security program such as incident response planning, and identity management and access privileges. Without classifying data, enterprises really don’t know where they should start, so they over-invest by trying to protect everything the same or the invest in the wrong areas.

**Not coming to understand the specific organization and industry**

Every industry is different. How a company whose primary asset is data will be secured differently than one whose primary service is transportation, which is different from the concerns on manufacturing and a research and development firm. Then each organization is different on its own in terms of culture and risk tolerance. Whenever a CISO is out of touch of their organization and their industry, the organization’s security program suffers because it’s not tailored to the demands of the specific industry or the risk tolerance of the organization.

**There’s no alignment with security and business objectives**

As organizations become more dependent on data and software services to operate their business, the alignment of cybersecurity teams and the goals of the broader business becomes even more crucial. Not only does the attack surface of the organization increase as the digital footprint increases, but the software and data becomes more central to the survival of the business.

Of course having strong security and business alignment requires good communication with senior leadership, but it also requires learning about each line of business, their objectives, and becoming more empathetic to their needs and helping them to better manage risk while obtaining those objectives.

**Regulatory compliance drives security**

This is always a bugaboo of mine. Enterprises get caught up on meeting regulatory demands and “checking those boxes” that they don’t actually focus on mitigating the actual risks of being breached. In other words, there’s a big difference between installing all the right security technologies, having someone called a CISO, and having all the right polices in place on the surface from managing all of these technologies properly, and supporting the program with the right processes enforced by security leadership who has actual authority. 

**Business execs not involved in tabletop drills**

Tabletop testing, an exercise which consists of team members having to respond, through discussion, how they’d respond to a realistic adverse scenario, such as an attack on their data or critical systems. Each participant must respond with how their organization would respond to the attack, and these exercises help to establish the right lines of communication are in place for the real event and that gaps in resources and capabilities are filled long before any adverse event occurs. It’s also essential business leadership sit on these exercises so they understand what each group is responsible for and how to help manage the organization properly through a live event should that ever be necessary.

### Explore More Topics

- [Enterprise Security (743)](https://businessinsights.bitdefender.com/topic/enterprise-security)
- [Threat Research (201)](https://businessinsights.bitdefender.com/topic/threat-research)
- [Cloud Security (174)](https://businessinsights.bitdefender.com/topic/cloud-security)
- [SMB Security (170)](https://businessinsights.bitdefender.com/topic/smb-security)
- [Ransomware (166)](https://businessinsights.bitdefender.com/topic/ransomware)
- [Privacy and Data Protection (137)](https://businessinsights.bitdefender.com/topic/privacy-and-data-protection)
- [Cybersecurity Awareness (134)](https://businessinsights.bitdefender.com/topic/cybersecurity-awareness)
- [Endpoint Protection & Management (126)](https://businessinsights.bitdefender.com/topic/endpoint-protection-management)
- [Endpoint Detection and Response (124)](https://businessinsights.bitdefender.com/topic/endpoint-detection-and-response)
- [Managed Detection and Response (119)](https://businessinsights.bitdefender.com/topic/managed-detection-and-response)
- [Virtualization & Data Center Security (82)](https://businessinsights.bitdefender.com/topic/virtualization-data-center-security)
- [Threat Intelligence (76)](https://businessinsights.bitdefender.com/topic/threat-intelligence)
- [IT Compliance & Regulations (71)](https://businessinsights.bitdefender.com/topic/it-compliance-regulations)
- [Bitdefender Threat Debrief (55)](https://businessinsights.bitdefender.com/topic/bitdefender-threat-debrief)
- [Managed Service Providers (53)](https://businessinsights.bitdefender.com/topic/managed-service-providers)
- [#Featured (52)](https://businessinsights.bitdefender.com/topic/featured)
- [Advanced Persistent Threats (46)](https://businessinsights.bitdefender.com/topic/advanced-persistent-threats)
- [Events (38)](https://businessinsights.bitdefender.com/topic/events)
- [Independent Testing (18)](https://businessinsights.bitdefender.com/topic/independent-testing)
- [Cybersecurity Advisory Services (9)](https://businessinsights.bitdefender.com/topic/cybersecurity-advisory-services)
- [Podcast (3)](https://businessinsights.bitdefender.com/topic/podcast)
- [top (2)](https://businessinsights.bitdefender.com/topic/top)

See all topics

### Subscribe to Blog Updates

## Read more about this topic

<https://businessinsights.bitdefender.com/seven-steps-healthcare-providers-can-take-now-to-shrink-their-security-skills-gap?hsLang=en-us>

### [Seven Steps Healthcare Providers Can Take Now to Shrink Their Security Skills Gap](https://businessinsights.bitdefender.com/seven-steps-healthcare-providers-can-take-now-to-shrink-their-security-skills-gap?hsLang=en-us)

<https://businessinsights.bitdefender.com/open-source-software-supply-chain?hsLang=en-us>

### [The State of Open Source in the Software Supply Chain](https://businessinsights.bitdefender.com/open-source-software-supply-chain?hsLang=en-us)

<https://businessinsights.bitdefender.com/security-performance-data-center-transformation?hsLang=en-us>

### [Security and performance required to support data center transformation, survey shows](https://businessinsights.bitdefender.com/security-performance-data-center-transformation?hsLang=en-us)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2685110570-png/Bitdefender-Mar2015-Theme/Images/avatar_img_footer.png)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2676149282-png/Bitdefender-Mar2015-Theme/Images/logo_white_footer.png)

- [![https://twitter.com/Bitdefender_Ent](https://businessinsights.bitdefender.com/hs-fs/file-2658233851-png/Bitdefender-Mar2015-Theme/Images/ft_soc_tw.png?width=33&name=ft_soc_tw.png)](https://twitter.com/Bitdefender_Ent)
- [![Linkedin-icon-300x300](https://businessinsights.bitdefender.com/hs-fs/hubfs/Bitdefender-Mar2015-Theme/Images/Linkedin-icon-300x300.png?width=33&name=Linkedin-icon-300x300.png)](https://www.linkedin.com/company/bitdefender-gravityzone-enterprise-security)
- [![](https://businessinsights.bitdefender.com/hs-fs/file-2676149307-png/Bitdefender-Mar2015-Theme/Images/ft_soc_yt.png)](https://www.youtube.com/user/BitdefenderSecurity)

- [Legal Terms](https://www.bitdefender.com/legal/)
- [Privacy Policy](https://www.bitdefender.com/site/view/legal-privacy-policy-for-bitdefender-websites.html)
- [EULA](https://www.bitdefender.com/site/view/legal-eula.html)
- [Contact Us](https://www.bitdefender.com/business/contact.html)

Copyright © 1997-2023 Bitdefender All rights reserved.

![](https://px.spiceworks.com/px/5rec)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "George V. Hulme",
    "url" : "https://businessinsights.bitdefender.com/author/george-v-hulme"
  },
  "datePublished" : "2018-01-08T09:07:43.000Z",
  "headline" : "Six ways security teams sabotage their own plans",
  "image" : [ "https://businessinsights.bitdefender.com/hubfs/it-team.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://businessinsights.bitdefender.com/six-ways-security-teams-sabotage-plans",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://businessinsights.bitdefender.com/hubfs/Bitdefender_Logo_Transparent-2.png"
    },
    "name" : "Bitdefender"
  }
}
```