For many organisations, cybersecurity no longer feels like a source of protection. It feels like a wall of jargon, frameworks, and conflicting advice that’s difficult to question and even harder to act on.
According to experienced Chief Information Security Officer Amy Lemberger, who is the founder of The CISO Hub, this isn’t a failure of businesses, it’s a failure of the security industry itself.
Cybersecurity, she argues, has become over-engineered and performative. In trying to prove its sophistication, the industry has made itself inaccessible to the very people who are expected to make decisions.
“Compliance and security are not the same thing,” she says. “But they’re constantly conflated. You can be compliant and still exposed in all the ways that matter.”
Instead of clarity, businesses are often met with dense language, vendor-driven narratives, and technical detail that obscures rather than informs. Security discussions become abstract, detached from real priorities like growth, delivery, and resilience.
The result is a strange contradiction. Organisations invest heavily in security yet remain unsure about what they are actually protected against. Risk is documented but not properly understood. Decisions are deferred because the conversation feels too complex to engage with.
Recommended reading
- The Digital Operations Resilience Act | One Year On
- Gartner Reveals Six Emerging Cybersecurity Trends for 2026
- Rubrik Cybersecurity Summit | From Recovery to Resilience
- Workers Are More Confident Than They Should Be on Cybersecurity
She argues that effective security leadership is less about adding more layers and more about stripping things back. Plain language. Honest trade-offs. Clear explanations of what matters now and what can wait.
Cybersecurity, she says, should help leaders make better decisions, not make them feel inadequate for not being technical specialists.
Until the industry confronts its own role in creating confusion, the gap between effort and outcome will remain. Businesses will continue to spend, comply, and report, while still feeling uncertain about their true level of protection.





