How to Stop Wasting Security Budget | Ross Young | Cybersecurity Mondays Season 1 EP 9

How to Stop Wasting Security Budget | Ross Young | Cybersecurity Mondays Season 1 EP 9

🎙 Eva Benn 👥 101K 📅 June 15, 2026 ⏱ 28 min 👁 8K 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

budgetshelfwaremurder boardthreat matrixAI supply chain

Summary

In this episode of Cybersecurity Mondays, host Eva Benn interviews Ross Young, a former CIA, NSA, and Federal Reserve Board offensive security expert turned CISO. The discussion centers on why most cybersecurity budgets are wasted and how to fix it. Ross introduces the OWASP Threat and Safeguard Matrix (TaSM), a framework for prioritizing material threats and building defense-in-depth plans. He emphasizes the distinction between compliance and actual risk reduction, advocating for ‘minimum viable compliance’ to free resources for security improvements. The episode covers the ‘Murder Board’ method to evaluate and retire ineffective security tools based on coverage and utilization metrics. Ross also shares a process improvement exercise using Pareto charts to drastically reduce patching times, citing an example of cutting mean time from 300 days to 30. The conversation shifts to AI security, discussing the OWASP Top 10 for Agentic Applications and the LiteLLM supply chain attack, highlighting the need for robust dependency management. Ross concludes with three questions CISOs should ask their teams about agentic supply chain risk, emphasizing the importance of controlling and vetting software dependencies. The episode provides practical templates and resources from CISO Tradecraft for immediate implementation.

191 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video offers high practical value for security leaders, presenting actionable frameworks like the OWASP TaSM and the Murder Board, which can be directly applied to optimize security budgets and reduce waste. Ross Young’s arguments are grounded in his extensive experience, and he supports his claims with references to industry reports (e.g., Verizon DBIR) and real-world examples (e.g., patching improvement). The discussion is well-structured, moving from general principles to specific tools and questions. However, some assertions, such as the claim that ‘bigger budgets do not buy you more security,’ are presented as self-evident without rigorous empirical backing. The argumentation is persuasive but relies heavily on anecdotal evidence and expert opinion rather than systematic data.

Scientific Rigor, Source Quality, Title Accuracy

The video demonstrates good scientific rigor by referencing established frameworks like OWASP and NIST, and citing recent reports such as the Verizon DBIR and IBM Cost of a Data Breach. The sources mentioned are credible and relevant. The title accurately reflects the content, focusing on budget optimization and featuring Ross Young. The description provides links to resources and references, enhancing transparency. However, the discussion is primarily opinion-based, and some claims lack detailed citations within the video itself. The adequacy between title and content is strong, with no significant mismatch.

218 words

Title / Content Match

The title accurately reflects the content, focusing on optimizing security budgets and reducing waste, with practical advice from Ross Young.

Quality & Reliability

7/10

The video features a recognized expert with extensive experience in offensive and defensive security, and provides practical frameworks and references to established sources like OWASP and Verizon DBIR. However, it is primarily an opinion-driven discussion with limited empirical data presented directly, and some claims lack detailed evidence.

Chapters

Cited Sources

Concurring Sources

Contribution & Novelties

The video provides a practical framework for cybersecurity budget optimization, emphasizing the distinction between compliance and risk reduction. Ross Young’s OWASP TaSM and Murder Board offer actionable methods to evaluate and retire ineffective tools. The discussion on AI supply chain risks, including the LiteLLM attack, highlights emerging threats and provides specific questions for CISOs. The episode also introduces a process improvement exercise using Pareto charts to reduce patching times, which is a novel application of lean principles to security operations.

Pour aller plus loin :

145 words

Radar Profile

The radar profile shows high scores in information quantity and technical level, indicating a content-rich and moderately technical discussion. The lower score in information quality suggests that while the information is relevant, it relies heavily on expert opinion rather than empirical evidence. Overall, the profile reflects a practical, experience-driven resource for security leaders.

Reliability 7/10

💬 Sur les 0 commentaires analysés, aucune tendance n'est disponible.