Skip to content
Cybersecurity

The Future of Cybersecurity: Why People Still Beat Technology

August 15, 20223 min read698 words

I saw the numbers. Two hundred billion dollars for cybersecurity and still more breaches. If technology alone were the answer, we'd already be safe

The takeaways

  1. 01

    The stack keeps getting better. The outcomes are not keeping pace because the constraint is human, not technical.

    What to do nextAsk your security lead this week for the one-page view of stack in your environment, and read it end to end.

  2. 02

    Most breaches still start with a person clicking, misconfiguring, or being socially engineered.

    What to do nextRun a 20-minute tabletop with your team this month using breaches as the scenario.

  3. 03

    Zero trust, XDR, and AI are useful tools, not strategies. A strategy includes the people who run them.

    What to do nextAdd trust to the next leadership review as a standing item, not a one-time slide.

  4. 04

    Talent shortage is real, but it is also a symptom of how the industry hires and develops people.

    What to do nextOpen your current talent plan today and identify the one gap you would not want an auditor to find.

  5. 05

    The teams that will win the next decade are the ones who invested in communication, judgment, and ownership, not just licenses.

    What to do nextRun a 20-minute tabletop with your team this month using teams as the scenario.

I look at the analyst reports every year. The charts all look the same, just with a new date. Cybersecurity spending is up. Breach counts are up. Dwell time might be down a little, but the cost of each breach is way up. The gap between what attackers can do and what we can defend against? It's not closing. If you showed me a chart from 2015 and one from last year, I doubt most people could tell the difference.

The vendors don't want to talk about that part. Their technology keeps improving, they say. But the results? They're not. There's only one other thing to consider.

The technology is doing its job

This is not a complaint about the tools. Modern EDR catches things signature antivirus never would have. Cloud-native SIEMs ingest volumes that would have crushed an on-prem deployment a decade ago. Zero trust architectures genuinely reduce blast radius. Identity providers have made MFA something a non-technical user can actually live with.

If you graded the technology in isolation, the industry has made real progress. The problem is that you do not get to grade it in isolation. The technology lives inside organizations, run by humans, against attackers who are also human.

Where the breaches actually start

Look at the post-incident reports for the last twelve months. The opening move is almost never a novel zero day. It is a phishing email a tired person clicked, an S3 bucket someone left public, a third-party token that was never rotated, an MFA fatigue prompt that finally got approved at two in the morning, a developer who pasted a secret into a public repo, or a help desk that reset a password for someone they should not have.

The technology was there. The technology often even flagged it. Someone closed the alert, or no one was watching, or the runbook said escalate and there was nobody on the other end of the escalation.

The talent problem is a people problem in disguise

The industry has been telling itself there is a talent shortage for a decade. There are roughly four million unfilled cybersecurity roles globally. That number does not move much no matter how many bootcamps run.

A shortage of bodies is not the real issue. The real issue is that the industry hires for the wrong things, then wonders why retention is bad and burnout is high. Job descriptions ask for ten years of experience in a tool that has existed for four. Interviews test trivia instead of judgment. New hires are dropped into a SOC, handed a queue, and asked why they are not communicating better with the business they have never been introduced to.

Fix the people pipeline and the tools start to actually return what you paid for them.

What the next decade actually rewards

The security programs that will look good in 2035 are not the ones with the biggest stack. They are the ones that did three unglamorous things at the same time.

They built communication into the role. The analyst who can explain risk to a product manager in two sentences is worth three analysts who cannot. This is a teachable skill that almost nobody teaches.

They made ownership clear. Every alert has a name on it. Every system has a name on it. Every decision to accept a risk has a name on it. Ambiguity is where breaches live.

They invested in judgment. Tools surface signals. Humans decide what they mean. The teams that practice that decision-making, in tabletop after tabletop, get faster at it. The teams that just buy more tools do not.

This is the entire premise of the Secure Methodology and of The Smartest Person in the Room. The technology is necessary. It is not sufficient. The variable that has been ignored the longest, the human one, is the one with the most upside left.

The future of cybersecurity is not a smarter tool. It is a team that knows how to use the smart tools it already has.

“Every new layer of technology eventually meets a human, and that human becomes the decision point. You can either prepare them or pretend they do not exist.”

Frequently asked

Share this essay

Christian Espinosa, headshot

About the author

Christian Espinosa · Founder & CEO, Blue Goat Cyber

I'm the founder and CEO of Blue Goat Cyber, a medical device cybersecurity firm where my team has supported 250+ FDA submissions with zero failing to clear on cybersecurity. I previously founded and sold Alpine Security. I host The Med Device Cyber Podcast and wrote The Smartest Person in the Room and The In-Between: Life in the Micro, with Medical Device Cybersecurity: An In-Depth Guide out in 2026. Air Force Academy grad, 24x Ironman, climber of two of the Seven Summits.

Keep reading