📣 Send us your press release
Site updates every 15 minutes
Technology

Security Design Creates Friction, Limits Business Value, Finds Info-Tech Research Group

Info-Tech Research Group states that many security programs are designed around controls rather than the business services they enable, creating friction and limiting value.

23 July 2026
Security Design Creates Friction, Limits Business Value, Finds Info-Tech Research Group

A new report from Info-Tech Research Group argues that organizations commonly design their security programs around controls, rather than focusing on the business services these controls are meant to support. This approach often creates friction and diminishes the actual business value derived from security investments.

The research firm's blueprint, "Build Security Services for Business Value," highlights that when security controls are implemented without clear context, alignment, or defined outcomes tied to business operations, they tend to disrupt workflows, be bypassed, or go underutilized.

Diana MacPherson, research director at Info-Tech, stated, "Security that isn't designed in the context of the business will always struggle to gain traction." She added that CISOs need to shift their focus from controls to a service-oriented narrative that clearly articulates purpose, stakeholders, and value.

This disconnect erodes trust and makes it challenging to justify security spending, ultimately hindering the organization's ability to sustain effective security practices. The report introduces a three-phase framework designed to help security leaders define, align, and operationalize security services to better enable business outcomes.

The framework aims to help security leaders articulate the costs and benefits of their services, thereby improving their ability to secure necessary funding and demonstrate tangible value to business stakeholders.

Original source: prnewswire.com