Skip to content

Why Most Cyber Programs Stall (And How To Fix Them)

Look across midmarket and enterprise cybersecurity and the pattern is hard to ignore: teams are busy, budgets are growing, yet risk levels remain stubbornly high.

Activity is not being translated into meaningful progress.

The Mid‑Market Problem: Nobody Really Owns Cyber

In midsized organizations, cybersecurity often exists as a side job. A CFO, CEO, or IT director “has cyber” alongside five other responsibilities. That structure naturally leads to reaction instead of intent: chasing the latest alert, buying whatever tool a trusted vendor recommends, and leaning heavily on an MSP (managed service provider) to “handle security.”

When no one is accountable for a clear security program, service providers quietly fill the vacuum. Their tooling and operating model become the default strategy. That might keep the lights on, but it rarely reflects the organization’s unique risks, their regulatory exposure, or anything inclusive of growth plans.

 

The Enterprise Problem: Strategy That Never Becomes Reality

Enterprises tend to have the opposite challenge. They have programs, frameworks, assessments, and roadmaps. On paper, things look mature. In practice, the breakdown often happens between decision and execution.

Security leaders receive detailed reports and thoughtful recommendations. Those documents make it into steering committees and board decks. Then they stall. Initiatives are not funded, ownership remains vague, and timelines slip behind other priorities. The assessments and roadmaps were technically correct, but they never become part of daytoday operations.

That’s how shelfware is created: not through bad work, but through a missing bridge between insight and action.

17-1

How Compliance Work Turns Into Drag

Add compliance to the picture and the friction increases. Many organizations pursue CMMC, HIPAA, NIST CSF, ISO, and sectorspecific requirements independently. Each new framework introduces its own language, artifacts, and audits. Teams do their best to respond, but often end up duplicating controls and processes under different labels.

This creates a form of compliance overhead that grows over time. Instead of a single, cohesive program mapped to multiple obligations, the organization carries several parallel structures. That consumes capacity, complicates communication, and makes it harder to see which controls actually reduce risk versus simply satisfying an auditor.

AI Exposes Old Weaknesses In New Ways

AI is now stresstesting these weaknesses in real time. To deliver value, AI needs consistent access to data. Security teams, by design, are trained to limit access and reduce exposure. Those two forces collide quickly when the board, CIO, or business units push for rapid AI adoption.

CISOs are being asked to clear a path for AI while still protecting information and meeting regulatory expectations. That requires new kinds of collaboration with the business, clarity about which data can be used and how, and updated thinking on identity, logging, and monitoring. Where accountability and alignment are already fuzzy, AI simply makes those gaps more visible.

What Actually Moves Programs Forward

When you strip away the noise, stalled programs share one core trait: the security effort is not grounded in the organization’s real constraints and decisionmaking structure.

The programs that make tangible progress tend to do a few things consistently:

  • They turn strategy into specific initiatives with owners, timelines, and budgets instead of stopping at highlevel recommendations.
  • They design one coherent control environment, then map that to multiple frameworks, rather than reinventing their approach for every new acronym.
  • They define who owns which risks so security, business leadership, and the board understand their roles in accepting, reducing, or transferring that risk.

In that environment, tools support a known direction, compliance reinforces an existing program, and technologies like AI are evaluated against clear guardrails.

 

The work is still hard, but the effort starts to accumulate instead of evaporating.

 


Reveal Risk’s practitioners have sat on both sides of the table, running programs inside pharma, life sciences, manufacturing, and midmarket environments before advising clients on them. That operator experience lets us design assessments, strategies, and roadmaps that match realworld constraints, consolidate overlapping frameworks, and actually get implemented instead of turning into shelfware.

If your security program feels busy but stuck, bringing in a team that has built and run these programs themselves can help you turn insight into action and align cyber work with the way your business really operates.

Book a meeting to get started! 

 

About the author
Chris Adickes
Chris is a recent practitioner with 20+ years of security risk management experience and over 15 years working in pharma and life sciences organizations. He’s worked in the cybersecurity programs at Merck & Co., Inc., C.R. Bard/Becton Dickinson, and Catalent Pharma Solutions. Chris specializes in program development across several domains in cyber security, including strategy, internal/third-party risk, vulnerability management, engineering, operations, incident response, and data security.​