
Cybersecurity has evolved rapidly. Roles are more specific, and tools are more sophisticated. Theoretically, this should improve organizational security. However, many teams still struggle with the same fundamental problems: unclear risk priorities, poor tool choices, and difficulty communicating security issues to the business.
These problems usually aren’t due to lack of effort. They stem from a more subtle issue: a gradual erosion of basic understanding as specialization increases. Specialization itself isn’t the issue; it’s the lack of big-picture context. When security teams lack a shared view of how the business, systems, and risks interrelate, even excellent technical work suffers. This disconnect becomes visible in program design, tool selection, and incident handling. This pattern has been observed repeatedly while supporting incidents and security programs across organizations of all sizes.
Cybersecurity is unique in the speed at which practitioners specialize. In many fields, broad basic training comes first, learning the entire system before focusing on a part. For example, one becomes a general doctor before specializing as a surgeon. In security, it’s often the reverse. People directly enter specialized roles like cloud security, detection engineering, forensics, or IAM with limited knowledge of the broader environment. This leads to teams highly skilled in their areas but disconnected from the overall risk landscape.
The result is a lack of complete awareness. Seeing only a segment of the environment makes it harder to understand threat movement, control interaction, or risk importance. Risk becomes a narrow, role-specific view, leading to unproductive security discussions. When a security issue is raised without connecting it to business operations, it seems abstract and fails to resonate, not because it’s unimportant, but because it lacks context.
Another recurring observation is how security decisions become product-focused, instead of process-oriented. Teams are asked about tool needs, and they cite features or industry trends instead of how the tool addresses specific organizational risks. When a tool can’t be linked to organizational risk, it usually indicates an unclear problem definition. Security becomes a purchase, rather than a designed system.
A working security program starts with understanding the business: its purpose, mission, and the essential systems and data. Without these answers, it’s impossible to know what to protect. Attackers understand this, targeting what matters most and where it will cause impact. Defenders lacking that clarity are always reacting, responding to alerts and vulnerabilities without clear priorities. Foundational knowledge prevents this, enabling teams to work from mission to assets to risk, instead of from tool to alert to fix.
Many security failures stem from teams not knowing what constitutes “normal” in their environments. Detection becomes challenging when expected behavior isn’t well-defined. Response slows when basic questions about systems, users, and data flows can’t be quickly answered. Prevention becomes guesswork when past incidents can’t be clearly explained or learned from.
This isn’t a tool problem; it’s a familiarity problem. Knowing your systems, network, and daily organizational operations is crucial. It allows anomalies to stand out and investigations to progress confidently. Skipping this step forces teams to build that understanding during incidents, when pressure is high and mistakes are costly. Advanced capabilities only work with a solid baseline understanding.
Modern cybersecurity relies on specialization, and that won’t change. However, the assumption that specialization is sufficient must change. Foundational skills help specialized teams assess risk, communicate effectively with the business, and make sound decisions under pressure. They create shared context, often missing when programs falter, tools accumulate, or incidents stall.
As environments become more complex, this shared understanding becomes essential. This May, I will be presenting SEC401: Security Essentials â Network, Endpoint, and Cloud at SANS Security West 2026 for teams and professionals seeking to strengthen their foundational skills and apply specialized knowledge with a clearer understanding of modern security programs.
Note: This article has been expertly written and contributed by Bryan Simon, SANS Senior Instructor.
© Bulletproof Servers. All rights reserved.