---
title: "The Future of Cybersecurity: Tech Still Loses to People"
description: "New tools keep arriving. Breaches keep happening. The deciding factor is still the humans running the program, not the stack they bought."
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Person",
      "@id": "https://christianespinosa.com/#person",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "image": "https://christianespinosa.com/__l5e/assets-v1/de07e44b-a8e0-4bcc-bcb0-13aec15421f1/headshot-front.jpg",
      "sameAs": [
        "https://www.facebook.com/christian.espinosa.official",
        "https://x.com/Ironracer",
        "https://www.instagram.com/christian.espinosa.official/",
        "https://www.youtube.com/@ChristianEspinosaOfficial",
        "https://www.linkedin.com/in/christianespinosa/"
      ],
      "jobTitle": "Bestselling Author, Keynote Speaker, Entrepreneur",
      "worksFor": {
        "@type": "Organization",
        "name": "Blue Goat Cyber",
        "url": "https://bluegoatcyber.com/"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://christianespinosa.com/#website",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "publisher": {
        "@id": "https://christianespinosa.com/#organization"
      },
      "inLanguage": "en-US"
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://christianespinosa.com/#organization",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "logo": {
        "@type": "ImageObject",
        "url": "https://christianespinosa.com/logo.svg"
      },
      "founder": {
        "@id": "https://christianespinosa.com/#person"
      },
      "sameAs": [
        "https://www.facebook.com/christian.espinosa.official",
        "https://x.com/Ironracer",
        "https://www.instagram.com/christian.espinosa.official/",
        "https://www.youtube.com/@ChristianEspinosaOfficial",
        "https://www.linkedin.com/in/christianespinosa/"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "The Future of Cybersecurity: Tech Still Loses to People",
      "description": "New tools keep arriving. Breaches keep happening. The deciding factor is still the humans running the program, not the stack they bought.",
      "image": "https://christianespinosa.com/__l5e/assets-v1/cc6df7bf-774e-4c01-a206-0b15fe1ed209/the-future-of-cybersecurity-innovations-in-technology-still-not-as-critical-as-people-card.png",
      "datePublished": "2022-08-15T00:00:00+00:00",
      "dateModified": "2026-06-26T00:00:00+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://christianespinosa.com/blog/the-future-of-cybersecurity-innovations-in-technology-still-not-as-critical-as-people"
      },
      "author": {
        "@type": "Person",
        "name": "Christian Espinosa",
        "url": "https://christianespinosa.com/about"
      },
      "publisher": {
        "@type": "Organization",
        "name": "Christian Espinosa",
        "logo": {
          "@type": "ImageObject",
          "url": "https://christianespinosa.com/logo.svg"
        }
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Are you saying technology does not matter?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. Technology matters a lot, and most organizations underinvest in fundamentals like asset inventory, identity, and patching. The point is that adding more technology on top of an unprepared team does not move the outcome."
          }
        },
        {
          "@type": "Question",
          "name": "What does an investment in people actually look like in a security budget?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Communication training, decision-making exercises like tabletops, paid time for analysts to develop technical depth, manager training that is not just about ticket throughput, and a hiring process that selects for judgment instead of trivia. Most programs spend less than five percent of their budget here. It should be closer to twenty."
          }
        },
        {
          "@type": "Question",
          "name": "How do I convince a board that the people layer is the gap?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Walk them through your last three incidents and identify the human decision point in each one. Then show them what training, staffing, or process change would have changed the outcome. Boards respond to specific stories with specific dollar figures, not to general statements about culture."
          }
        },
        {
          "@type": "Question",
          "name": "Does AI change this argument?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "It sharpens it. AI handles more of the pattern work, which means the work left for humans is exactly the high-judgment work that requires the skills most teams have not invested in. The people layer becomes more important, not less."
          }
        },
        {
          "@type": "Question",
          "name": "Where should a CISO start if the budget is already locked for the year?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Start with one team. Run a six-week experiment on decision rights, communication, and ownership. Measure mean time to triage, mean time to escalate, and analyst-reported clarity. Bring the results into the next budget cycle. You do not need permission to run the experiment."
          }
        }
      ]
    }
  ]
---

[Skip to content](#main)

[](/)

[About](/about)[Speaking](/speaking)[Cybersecurity](/cybersecurity)[Programs](/programs)[Books](/books)[Media](/media)

Writing

Search Ctrl K[Connect](/connect)

[Cybersecurity](/blog/category/cybersecurity)

# The Future of Cybersecurity: Why People Still Beat Technology

August 15, 2022 3 min read 698 words 

I saw the numbers. Two hundred billion dollars for cybersecurity and still more breaches. If technology alone were the answer, we'd already be safe

![](/__l5e/assets-v1/71bc2bd5-d81d-42a8-b9a1-c9a2d5bab23f/the-future-of-cybersecurity-innovations-in-technology-still-not-as-critical-as-people-hero.webp)

Published

August 15, 2022

Read time

3 min

In this essay

1.  [01 The technology is doing its job ](#the-technology-is-doing-its-job)
2.  [02 Where the breaches actually start ](#where-the-breaches-actually-start)
3.  [03 The talent problem is a people problem in disguise ](#the-talent-problem-is-a-people-problem-in-disguise)
4.  [04 What the next decade actually rewards ](#what-the-next-decade-actually-rewards)

Jump to

1.  [01 The technology is doing its job ](#the-technology-is-doing-its-job)
2.  [02 Where the breaches actually start ](#where-the-breaches-actually-start)
3.  [03 The talent problem is a people problem in disguise ](#the-talent-problem-is-a-people-problem-in-disguise)
4.  [04 What the next decade actually rewards ](#what-the-next-decade-actually-rewards)

The takeaways

1.  01 
    
    The stack keeps getting better. The outcomes are not keeping pace because the constraint is human, not technical.
    
    What to do next Ask your security lead this week for the one-page view of stack in your environment, and read it end to end.
    
2.  02 
    
    Most breaches still start with a person clicking, misconfiguring, or being socially engineered.
    
    What to do next Run a 20-minute tabletop with your team this month using breaches as the scenario.
    
3.  03 
    
    Zero trust, XDR, and AI are useful tools, not strategies. A strategy includes the people who run them.
    
    What to do next Add trust to the next leadership review as a standing item, not a one-time slide.
    
4.  04 
    
    Talent shortage is real, but it is also a symptom of how the industry hires and develops people.
    
    What to do next Open your current talent plan today and identify the one gap you would not want an auditor to find.
    
5.  05 
    
    The teams that will win the next decade are the ones who invested in communication, judgment, and ownership, not just licenses.
    
    What to do next Run a 20-minute tabletop with your team this month using teams as the scenario.
    

I look at the analyst reports every year. The charts all look the same, just with a new date. Cybersecurity spending is up. Breach counts are up. Dwell time might be down a little, but the cost of each breach is way up. The gap between what attackers can do and what we can defend against? It's not closing. If you showed me a chart from 2015 and one from last year, I doubt most people could tell the difference.

The vendors don't want to talk about that part. Their technology keeps improving, they say. But the results? They're not. There's only one other thing to consider.

## The technology is doing its job

This is not a complaint about the tools. Modern EDR catches things signature antivirus never would have. Cloud-native SIEMs ingest volumes that would have crushed an on-prem deployment a decade ago. Zero trust architectures genuinely reduce blast radius. Identity providers have made MFA something a non-technical user can actually live with.

If you graded the technology in isolation, the industry has made real progress. The problem is that you do not get to grade it in isolation. The technology lives inside organizations, run by humans, against attackers who are also human.

## Where the breaches actually start

Look at the post-incident reports for the last twelve months. The opening move is almost never a novel zero day. It is a phishing email a tired person clicked, an S3 bucket someone left public, a third-party token that was never rotated, an MFA fatigue prompt that finally got approved at two in the morning, a developer who pasted a secret into a public repo, or a help desk that reset a password for someone they should not have.

The technology was there. The technology often even flagged it. Someone closed the alert, or no one was watching, or the runbook said escalate and there was nobody on the other end of the escalation.

## The talent problem is a people problem in disguise

The industry has been telling itself there is a talent shortage for a decade. There are roughly four million unfilled cybersecurity roles globally. That number does not move much no matter how many bootcamps run.

A shortage of bodies is not the real issue. The real issue is that the industry hires for the wrong things, then wonders why retention is bad and burnout is high. Job descriptions ask for ten years of experience in a tool that has existed for four. Interviews test trivia instead of judgment. New hires are dropped into a SOC, handed a queue, and asked why they are not communicating better with the business they have never been introduced to.

Fix the people pipeline and the tools start to actually return what you paid for them.

## What the next decade actually rewards

The security programs that will look good in 2035 are not the ones with the biggest stack. They are the ones that did three unglamorous things at the same time.

**They built communication into the role.** The analyst who can explain risk to a product manager in two sentences is worth three analysts who cannot. This is a teachable skill that almost nobody teaches.

**They made ownership clear.** Every alert has a name on it. Every system has a name on it. Every decision to accept a risk has a name on it. Ambiguity is where breaches live.

**They invested in judgment.** Tools surface signals. Humans decide what they mean. The teams that practice that decision-making, in tabletop after tabletop, get faster at it. The teams that just buy more tools do not.

This is the entire premise of the [Secure Methodology](/blog/how-to-build-a-cybersecurity-team-from-scratch-using-the-secure-methodology) and of [The Smartest Person in the Room](/books/the-smartest-person-in-the-room). The technology is necessary. It is not sufficient. The variable that has been ignored the longest, the human one, is the one with the most upside left.

The future of cybersecurity is not a smarter tool. It is a team that knows how to use the smart tools it already has.

> “Every new layer of technology eventually meets a human, and that human becomes the decision point. You can either prepare them or pretend they do not exist.”

Frequently asked

### Are you saying technology does not matter?

### What does an investment in people actually look like in a security budget?

### How do I convince a board that the people layer is the gap?

### Does AI change this argument?

### Where should a CISO start if the budget is already locked for the year?

[](/blog/the-future-of-cybersecurity-innovations-in-technology-still-not-as-critical-as-people)

Share this essay

[X ](https://twitter.com/intent/tweet?url=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fthe-future-of-cybersecurity-innovations-in-technology-still-not-as-critical-as-people&text=The%20Future%20of%20Cybersecurity%3A%20Why%20People%20Still%20Beat%20Technology) [LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fthe-future-of-cybersecurity-innovations-in-technology-still-not-as-critical-as-people) [Facebook](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fthe-future-of-cybersecurity-innovations-in-technology-still-not-as-critical-as-people) [Email](mailto:?subject=The%20Future%20of%20Cybersecurity%3A%20Why%20People%20Still%20Beat%20Technology&body=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fthe-future-of-cybersecurity-innovations-in-technology-still-not-as-critical-as-people)Copy link 

![Christian Espinosa, headshot](/__l5e/assets-v1/de07e44b-a8e0-4bcc-bcb0-13aec15421f1/headshot-front.jpg)

About the author

[Christian Espinosa](/about) · Founder & CEO, Blue Goat Cyber

I'm the founder and CEO of Blue Goat Cyber, a medical device cybersecurity firm where my team has supported 250+ FDA submissions with zero failing to clear on cybersecurity. I previously founded and sold Alpine Security. I host The Med Device Cyber Podcast and wrote The Smartest Person in the Room and The In-Between: Life in the Micro, with Medical Device Cybersecurity: An In-Depth Guide out in 2026. Air Force Academy grad, 24x Ironman, climber of two of the Seven Summits.

Keep reading

-   [
    
    ### Will AI Help or Hurt Cybersecurity?
    
    AI shifts the workload but does not remove the human decision point. This is why.
    
    Read essay → ](/blog/will-ai-and-machine-learning-help-or-hurt-cybersecurity)
-   [
    
    ### Building a Cybersecurity Team With the Secure Methodology
    
    If people are the gap, this is the operating model that closes it.
    
    Read essay → ](/blog/how-to-build-a-cybersecurity-team-from-scratch-using-the-secure-methodology)
-   [
    
    ### Why Technical People Struggle With People Skills
    
    The cultural root cause of the people gap, and what to do about it.
    
    Read essay → ](/blog/why-do-technical-people-struggle-with-people-skills-and-how-can-companies-fix-it)

[← Previous essay 

Reskilling and Upskilling Talent Can Help Shrink the Cybersecurity Skills Gap - Christian Espinosa

](/blog/reskilling-and-upskilling-talent-can-help-shrink-the-cybersecurity-skills-gap)[Next essay → 

Why Cybersecurity Deserves a Seat at the Leadership Table - Christian Espinosa

](/blog/why-cybersecurity-deserves-a-seat-at-the-leadership-table)

Related, Cybersecurity

### Need medical-device or offensive security expertise?

Blue Goat Cyber, Christian's firm, runs FDA-aligned premarket submissions, penetration testing, and SBOM/SOUP analysis for medtech and high-stakes industries.

[Explore Blue Goat Cyber](/cybersecurity)

Christian Espinosa

Bestselling author, keynote speaker, and Founding CEO of [Blue Goat Cyber](https://bluegoatcyber.com/). Helping technical leaders develop the soft skills that turn brilliance into impact.

[](https://www.linkedin.com/in/christianespinosa/)[](https://x.com/Ironracer)[](https://www.instagram.com/christian.espinosa.official/)[](https://www.youtube.com/@ChristianEspinosaOfficial)[](https://www.facebook.com/christian.espinosa.official)

Explore

-   [About](/about)
-   [Timeline](/timeline)
-   [Speaking](/speaking)
-   [Cybersecurity](/cybersecurity)
-   [Programs](/programs)

Read

-   [Books](/books)
-   [Guides](/guides)
-   [Blog](/blog)
-   [Media](/media)
-   [Podcast Interviews](/podcasts)
-   [Success Stories](/success-stories)

Connect

-   [Contact Christian](/connect)
-   [LinkedIn ↗](https://www.linkedin.com/in/christianespinosa/)
-   [Blue Goat Cyber ↗](https://bluegoatcyber.com/)
-   [Resources](/resources)

© 2026 Christian Espinosa. All rights reserved.

[Privacy](/privacy-policy)[Terms](/terms-of-use)