Why Most Cybersecurity Budgets Go to Waste
Download resourcesAbout this session
Ross Young, former CIA officer and CISO at Caterpillar Financial, draws on his book Cybersecurity's Dirty Secret to argue that most security budgets are wasted because CISOs are never taught the financial skills the role actually requires. He gives industry benchmarks (roughly 10% of IT spend, or about 5% by Gartner's count) and splits spending into risk-reduction versus mandatory-compliance buckets that should be funded differently: buy the best tool where it truly lowers risk, buy the cheapest option where it is only a checkbox. He introduces a nine-box prioritization matrix (maintenance cost versus confidence of successful implementation), a 'murder board' method for scoring deployed tools by an effective-protection score (coverage times configuration completeness) to find shelfware, and a total-cost-of-ownership formula (labour plus licensing plus hosting) applied to a CIS 18-style service catalog for zero-based budget reviews. A worked example shows funding a legacy-app rewrite by quantifying maintenance-labour savings against migration cost to produce an ROI case both engineering and finance can back. He closes with tactics for winning budget: tiered 'trim level' options with explicit risk acceptance for lower tiers, and framing spend against the revenue or customers it protects rather than as an abstract cost.
What if a presentation could save your company thousands to millions in wasted cybersecurity spending? That’s not hype, it’s the reality when you stop treating spending dollars like a bottomless pit and start treating it like a business strategy.
Most executives assume the more money they throw at cybersecurity, the safer they’ll be. Wrong. In fact, the bigger your budget, the more likely you’re bleeding cash on shelfware, pointless meetings, and “solutions” that solve nothing. This book flips the script: it shows you how to slash costs, cut risk, and still move faster than your competition.
By attending, you’ll discover:
How to finally answer the question, “How much should we spend on cybersecurity?”
Why your ROI math is broken and the simple fixes that make sense in the boardroom.
Which budget cuts backfire, and how to cover yourself with smart risk approvals.
When to switch tools, when to double down, and when to pull the plug.
Why automation, AI, and even neurodiverse talent are already slashing IT labor costs.
The budget killers (bad contracts, endless meetings, and accountability gaps) quietly devour millions.
Key takeaways
- Split every security spending decision into risk-reduction versus mandatory-compliance buckets and fund them differently: best-of-breed where it truly lowers risk, cheapest option where it is only a compliance checkbox.
- Run a 'murder board' on existing tools: score each one by coverage (percent of endpoints/scope actually running it) multiplied by configuration completeness to get an effective-protection score, and use low scores to justify fixing, replacing or killing shelfware.
- Prioritize competing initiatives with a nine-box matrix (maintenance cost versus confidence you can actually implement it) instead of funding whatever was loudest in the room; low-maintenance, high-confidence items go first.
- Build a total-cost-of-ownership figure (labour plus licensing plus hosting) per security capability and map it to a CIS 18-style service catalog so budget reviews can be zero-based instead of last year's number plus inflation.
- When asking for budget, present tiered options with named trade-offs and require an explicit risk acceptance from the business for anything you are told to cut, rather than silently absorbing scope with the same budget.
Speakers

From CIA spy to CISO, Ross Young has spent two decades pushing the boundaries of cybersecurity. Ross is the co-host of CISO Tradecraft, creator of the OWASP Threat and Safeguard Matrix (TaSM), and a seasoned cybersecurity leader. He has served as… Read moreRead less
From CIA spy to CISO, Ross Young has spent two decades pushing the boundaries of cybersecurity. Ross is the co-host of CISO Tradecraft, creator of the OWASP Threat and Safeguard Matrix (TaSM), and a seasoned cybersecurity leader. He has served as CISO in Residence at Team8, CISO of Caterpillar Financial, and an instructor at Johns Hopkins University. Previously, Ross was a divisional CISO at Capital One and has over a decade of cybersecurity experience across CIA, NSA, and the Federal Reserve Board.
Ross holds master's and bachelor's degrees from Johns Hopkins University, Idaho State University, and Utah State University. Ross is also designated as a Boardroom Certified Qualified Technology Expert (QTE) and a Certified Information Systems Security Professional (CISSP).

