Cybersecurity leaders are constantly asked to do more: deploy new tools, close more vulnerabilities, produce more dashboards, and justify larger budgets. But for Bryce Austin, CEO of TCE Strategy and a practicing fractional CISO, effective security starts with a simpler question: What problem are we actually trying to solve? Austin argues that security teams should be deliberate about what they buy, how they allocate resources, and whether a technology investment genuinely improves the organization’s security posture.
Austin brings experience advising companies ranging from 50 employees to members of the S&P 500, along with his perspective as the author of Secure Enough? 20 Questions on Cybersecurity for Business Owners and Executives. His approach puts people and decision-making ahead of technology, from assigning a human owner to every security tool to eliminating dashboards that don’t lead to action. In this edition of CISO Tips, Austin shares practical advice on cutting shelfware, communicating risk to executives, preserving evidence during incidents, and making sure security teams focus on the risks that actually matter.
Complete this sentence: “Before you buy any new security tool, first...”
…define the specific problem you are trying to solve. You buy a sports car to have an exciting driving experience, not haul a large trailer. Make sure everyone agrees on the problem before anyone starts shopping for solutions.
What’s one rule you enforce on your team that other teams would find strict?
Do not move the goalposts on a security project. I require my teams to manage project deadlines and to proactively reach out if something is going to get in the way of a deadline. For example, when decommissioning an insecure system, standing up the new system to replace it makes the cybersecurity issue WORSE while both systems are running. It is not until the old system is completely gone that you have done any good to the cybersecurity posture of the organization.
What’s a number or ratio that guides how you allocate budget, headcount, or your own time?
My ratio is 1:1: every cybersecurity tool needs a human owner. If I can’t identify someone with the time and expertise to properly manage a product before we buy it, I don’t want it. I also look hard at whether a process or procedure change can solve the same problem. New tools need additional resources to manage and maintain, and sometimes introduce new vulnerability risk (read: SolarWinds Orion in 2020) or operational risk (read: CrowdStrike in July 2024).
What’s one line that works when asking the board or CFO for a budget?
Cybersecurity isn’t perfect. We need to be Secure Enough for us. Cybersecurity issue XYZ is not one that I can make a credible argument that we are Secure Enough. Either we consciously accept this risk as a leadership team, or we find the funding to fix it.
What should a CISO cut from their program tomorrow with zero regret?
Shelfware. Kill it. If you bought a software package or service and it isn’t working out because your team doesn’t have the time or expertise to effectively utilize it, cut it ASAP.
What’s your 60-second test for whether a vendor pitch is worth your time?
I ask, “What business problem do you solve that no one else solves, or that you solve better for a given price?” If they can’t give me a 60-second answer that makes sense, I’m out.
What’s one meeting, report, or process you eliminated, and what replaced it?
Security dashboards that don’t help me make good decisions are just wall art. I eliminate them entirely, or make revisions so that reasonable action can be taken because of the information they contain. 2000 “critical” vulnerabilities on the monthly patching report are not actionable. Thirty “actively exploited by ransomware gangs” vulnerabilities on the same report are very actionable.
In the first 10 minutes of an incident, what’s the one action teams most often skip?
They forget to preserve evidence. Take screenshots. Record what you are seeing. Disconnect computers from the network but don’t reflexively reboot or power them off, as you may destroy valuable evidence in active memory. If you can’t otherwise contain an actively spreading attack, then containment takes priority. Preserving the active memory of an infected computer often leads to meaningful clues as to what is going on.
What’s one question every CISO should ask their team this week?
What is getting in your way that I can help you with?
What’s a phrase or framing you use to translate a technical risk for executives?
I’ve used this one a lot: Most car tires want around 35 psi of air in them. Having a car tire that is 3 psi low on air is not best practice, but it is not an emergency. A car tire with only 3 psi of air is a life safety issue when traveling 70 mph on the highway. A big part of my job is helping executives understand whether the cybersecurity issue in front of us is the former or the latter.
What’s your best tip for surviving the CISO role in exactly five words?
People come first. Not technology.
More tips from the series:
CISO Tips: Stefano Pasotti on Turning Cybersecurity Into Business Resilience
CISO Tips: Maurizio Imperadore on Resilience, Identity and Cutting Security Noise
CISO Tips: Jigar Shah on Buying Fewer Tools, Building More Trust
CISO Tips: Andy Curtis on Turning Cybersecurity Into Business Risk Decisions
CISO Tips: Carlos García Batista on Turning Cybersecurity Into Operational Resilience


