VOOZH about

URL: https://thenewstack.io/want-real-cybersecurity-progress-redefine-the-security-team/

⇱ Want Real Cybersecurity Progress? Redefine the Security Team - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2022-01-31 04:00:09
Want Real Cybersecurity Progress? Redefine the Security Team
contributed,sponsor-torq,sponsored,sponsored-post-contributed,
DevOps / Security

Want Real Cybersecurity Progress? Redefine the Security Team

Stagnated cybersecurity progress is contributing to more cyberattacks and increased threats. Here's how organizations can get back on track.
Jan 31st, 2022 4:00am by Chris Tozzi
👁 Featued image for: Want Real Cybersecurity Progress? Redefine the Security Team
Featured image via Pixabay
Torq sponsored this post. Insight Partners is an investor in Torq and TNS.
Chris Tozzi
Chris has worked as a Linux systems administrator and freelance writer with more than 10 years of experience covering the tech industry, especially open source, DevOps, cloud native and security. He also teaches courses on the history and culture of technology at a major university in upstate New York.

The state of cybersecurity today is, in a word, catastrophic. Breaches have become endemic. Not only do they continue at dizzying rates, but they are actually increasing in frequency by the month.

Why are things so bad? And why do businesses seem so helpless to make them better?

Those are complicated questions without simple answers, of course — but I believe that a major part of the answer has to do with the fact that, at most organizations, security remains the domain of elite security teams. Unlike many other functions, which have been “de-siloed” or even “democratized” across the business, security remains the mission primarily of security engineers and analysts alone.

If businesses want to see progress on the cybersecurity front, they’ll need to change this state of affairs by making security a collective responsibility. Here’s why and how.

What’s ‘Not’ Solving Today’s Cybersecurity Challenges

Before discussing why collective responsibility for security is the key to making real progress in the war against cyberattacks, let’s first observe which cybersecurity solutions are clearly not working — at least not on their own.

To be clear, I’m not suggesting that any of the resources or practices described below are bad ideas. They have all helped organizations to cope more effectively with security threats. Although, they haven’t definitively solved our pervasive cybersecurity challenges.

Security Tools

Today, the typical security team has an extensive set of fancy tools at its disposal. From SOARs, SAST, and DAST to CSPM, threat intelligence databases and beyond, modern security teams can leverage a litany of tools and resources that, for the most part, didn’t exist a decade ago.

These tools mean that security experts have a greater ability than ever to automate threat detection and remediation, secure software supply chains, hunt for threats and so on.

Yet, the attacks continue.

DevSecOps and Shift-Left Security

New security philosophies — above all, DevSecOps and the closely related concept of shift-left security — fall into the same boat. Over the past five or six years, the DevSecOps concept has encouraged security engineers to collaborate more closely with developers and IT operations teams, leading to a partial de-siloing of security.

That’s great. DevSecOps makes good sense. Here again, if DevSecOps were the key to cybersecurity success, we should be seeing better results by now. In reality, the opposite has happened. Although something like 70 percent of developers have embraced DevSecOps and shift-left security, their organizations are more likely than ever to be breached. As DevSecOps adoption has surged, so has the frequency of cyberattacks.

Compliance Rules

You could draw similar conclusions about compliance. Compliance mandates designed to protect digital privacy have grown considerably stronger over the past several years, with new regulations like GDPR and CCPA/CPRA coming online.

Although for many businesses these laws may have spawned more secure data management practices, the overall state of cybersecurity has only gotten worse since these regulations have taken effect. Here again, we’re not seeing real progress.

Torq is a no-code automation platform for security and operations teams. Easy workflow building, endless integrations, and out-of-the-box templates deliver value in minutes — not weeks. Torq and TNS are under common control.
Learn More
The latest from Torq

A New Solution: The Shift to Collective Security

The strategies described above share one trait in common: They all leave security mostly in the hands of an elite security team. No matter how many security tools a business buys, how far left it shifts security, or how many compliance rules it enforces, security operations still remain the realm primarily of security engineers and analysts (perhaps with just a bit of help from developers and IT Ops teams at businesses that take DevSecOps seriously).

That fact is part of what makes the concept of collective security so innovative. It fundamentally breaks a mold that has been in place for decades: the mold that forces a single team to “own” security across the entire business, leaving little opportunity for stakeholders who are not security experts to contribute to security initiatives.

By shifting to a strategy in which security is everyone’s responsibility — and, just as important, where everyone has the ability to define security rules and validate resources without having to know how to code or use sophisticated security tools — businesses make it possible for everyone to understand the state of cybersecurity in their organization, as well as to help enforce cybersecurity standards.

That’s not to say that the cybersecurity team should go away. On the contrary, placing security into the hands of everyone only makes the cybersecurity team more important and more valuable. It frees security engineers to focus on truly complex problems and to get the most value out of the complex tools that only they know how to use. More mundane security tasks — like configuring line of business tools and services to integrate with security scanning or defining security governance rules for a particular business unit — can be handled by “ordinary” users, with no development or elite security skills required.

Conclusion

In short, cybersecurity is still in a broken state, and the solutions we’ve tried so far haven’t even managed to hold the line. We need true innovation, like empowering everyone in the business to drive security operations instead of placing that burden in the hands of an overworked elite security team.

Torq is a no-code automation platform for security and operations teams. Easy workflow building, endless integrations, and out-of-the-box templates deliver value in minutes — not weeks. Torq and TNS are under common control.
Learn More
The latest from Torq
TRENDING STORIES
Chris Tozzi has worked as a Linux systems administrator and freelance writer. He has more than 10 years of experience covering the tech industry, especially open source, DevOps, cloud native technology and security.
Read more from Chris Tozzi
Torq sponsored this post. Insight Partners is an investor in Torq and TNS.
SHARE THIS STORY
TRENDING STORIES
TNS owner Insight Partners is an investor in: Pragma, Torq.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.