Gartner: We don’t need security superheroes
A better relationship between a company and its IT security department could lead to big cost savings, even in a recession, according to analyst Gartner.

Businesses and their IT security departments need to be on the same page, so that problems are prevented before security superheroes' have to put out the fire.
This was one of the messages from a Gartner analyst meeting today in London.
Research vice president Jay Heiser said that, in the past, security was managed through superheroes' who were good at reacting when something bad had already happened, but useless at preventing incidents in the future.
"Something bad happens, they come riding in fix the problem and then back away," he said. "We still need some of those people, but what we really need more than these cartoon characters are committees."
"Committees are the mechanisms where we overcome the artificial segregation inherent in today's organisations," he added.
Committees would allow information security to be properly aligned and integrated with business needs.
Earlier, another Gartner research vice president Tom Schultz explained that if IT security did "bridge the gap" and integrate with the rest of the organisation, then security could be improved even if companies were spending less.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
He said that businesses may have actually overspent on security in the past, for example going for best-of-breed security products, rather than cheaper solutions that were all they actually needed.
"I think it's fair to say there is some opportunity for cost optimisation and improved efficiencies within our organisations," Schultz said.
Rather thinking simply of keeping the bad guys out', it was now a case of being cost-effective' in keeping them out, he added.
"We can implement a lot of controls, but if we have too many controls it is too expensive and ends up being prohibitive for an organisation," Schultz said.
He added that Gartner had seen examples of big organisations with large security budgets that weren't in a good position, usually because they had over-engineered from a security perspective.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd
-
CISO job satisfaction is plummeting, and some are considering quitting altogether
News CISO job satisfaction is being plagued by mounting demands, poor c-suite collaboration, and stressful working patterns
By George Fitzmaurice
-
PyPI attack: Targeting of repository 'shows no sign of stopping'
News Greater collaboration and understanding of attackers’ tactics is key to mitigating open source security threats
By Ross Kelly
-
Capita's handling of cyber attack shows companies still fail at breach reporting
Analysis Capita initially told customers there was “no evidence” of data having been compromised in the March cyber attack
By Ross Kelly
-
Malware being pushed to businesses by search engines remains a pervasive threat
News High-profile malvertising campaigns in recent months have surged
By Ross Kelly
-
There's only one way to avoid credential stuffing attacks
Opinion PayPal accounts were breached last year due to a credential stuffing attack, but can PayPal avoid taking responsibility?
By Davey Winder
-
Five things to consider before choosing an MFA solution
In-depth Because we all should move on from using “password” as a password
By Rene Millman
-
Cyber security suffers from a communication problem
News Negative language around ‘human failures’ is eroding trust between security teams and broader business functions - it has to stop
By Ross Kelly
-
Does LastPass really deserve a last chance?
Opinion After several disastrous security incidents and a communications breakdown, it’s time to leave LastPass for pastures new
By Ross Kelly