Taming tool sprawl: Streamlining cyber security programme performance
Abstract
Financial services institutions face increasing pressure from regulators, boards, and customers to demonstrate the effectiveness of their cyber security controls. Many organisations, however, operate extensive portfolios of security tools without clear evidence that these investments deliver measurable risk reduction. This paper examines the operational and governance challenges associated with tool sprawl and introduces the concept of ‘security debt’ as the accumulation of unvalidated exposures and misconfigurations. Drawing on practitioner experience and industry research, it argues that the core issue is not the absence of technology but the lack of systematic validation of control effectiveness. The paper proposes a structured four-phase model to streamline cyber security programme performance: baseline, integrate, remediate what matters, and automate and scale. The model emphasises alignment with recognised frameworks, including MITRE ATT&CK, the National Institute of Standards and Technology Cybersecurity Framework, the Center for Internet Security Critical Security Controls, and the Digital Operational Resilience Act, alongside continuous measurement of control performance. By shifting from activity-based to effectiveness-based metrics, organisations can improve visibility, prioritise remediation, and strengthen governance. The paper concludes that a disciplined focus on validation enables financial institutions to reduce exposure, improve returns on existing investments, and provide more meaningful, evidence-based reporting to senior stakeholders. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
The full article is available to subscribers to the journal.
Author's Biography
Tim Dickinson is Customer Lead at Nagomi Security. He has held roles across four cyber security companies in Canada, the UK, and Australia, supporting customers in North America, Europe, and Asia Pacific. Tim has served as a vendor point of contact for leading global banks and insurers. His work focuses on helping organisations reduce measurable risk, validate control performance, and improve executive reporting using existing security investments.