
How to Stop Wasting Security Budget | Ross Young | Cybersecurity Mondays Season 1 EP 9
Keywords
Summary
191 words
Critical Evaluation
Value of the Information & Strength of the Argument
The video offers high practical value for security leaders, presenting actionable frameworks like the OWASP TaSM and the Murder Board, which can be directly applied to optimize security budgets and reduce waste. Ross Young’s arguments are grounded in his extensive experience, and he supports his claims with references to industry reports (e.g., Verizon DBIR) and real-world examples (e.g., patching improvement). The discussion is well-structured, moving from general principles to specific tools and questions. However, some assertions, such as the claim that ‘bigger budgets do not buy you more security,’ are presented as self-evident without rigorous empirical backing. The argumentation is persuasive but relies heavily on anecdotal evidence and expert opinion rather than systematic data.
Scientific Rigor, Source Quality, Title Accuracy
The video demonstrates good scientific rigor by referencing established frameworks like OWASP and NIST, and citing recent reports such as the Verizon DBIR and IBM Cost of a Data Breach. The sources mentioned are credible and relevant. The title accurately reflects the content, focusing on budget optimization and featuring Ross Young. The description provides links to resources and references, enhancing transparency. However, the discussion is primarily opinion-based, and some claims lack detailed citations within the video itself. The adequacy between title and content is strong, with no significant mismatch.
218 words
Title / Content Match
The title accurately reflects the content, focusing on optimizing security budgets and reducing waste, with practical advice from Ross Young.
Quality & Reliability
7/10
The video features a recognized expert with extensive experience in offensive and defensive security, and provides practical frameworks and references to established sources like OWASP and Verizon DBIR. However, it is primarily an opinion-driven discussion with limited empirical data presented directly, and some claims lack detailed evidence.
Chapters
- The cybersecurity budget myth most CISOs believe
- Why compliance often steals resources from security
- The framework that changes how you prioritize risk
- The attack trend catching most security teams off guard
- How top CISOs find hidden inefficiencies
- The tool Ross Young uses to identify wasted security spend
- The dirty secret behind most cybersecurity budgets
- Three questions every CISO should ask about AI supply chain risk
- One exercise every security leader should do this week
Cited Sources
- CISO Tradecraft Newsletter — Mentioned as a resource for templates and newsletter.
- Don't Just Spend It: How to Stop Your Cybersecurity Budget From Going to Waste — Referenced in the description as a newsletter post on budget waste.
- OWASP Top 10 for Agentic Applications 2026 — Referenced in the description as a current event/report.
- OWASP Threat and Safeguard Matrix (TaSM) — Ross Young's framework discussed in the video.
- LiteLLM supply chain attack (BleepingComputer) — Referenced in the description as a current event.
- CISO Tradecraft podcast — Mentioned as Ross Young's podcast.
- Free Cybersecurity Templates — Mentioned as a resource for templates like TaSM and Murder Board.
- Cloud Security Report 2025 (tool sprawl stats) — Referenced in the description for tool sprawl statistics.
- Eva Benn's website — Mentioned in the description as a follow-up resource.
- IBM Cost of a Data Breach Report 2025 — Referenced in the description as a current report.
- Ross Young's LinkedIn — Mentioned for connecting with Ross.
- Eva Benn's LinkedIn — Mentioned for connecting with Eva.
- Verizon 2025 Data Breach Investigations Report — Referenced in the description as a current report.
Concurring Sources
- OWASP Top 10 for Agentic Applications 2026 — Aligns with the discussion on AI supply chain risks.
- Verizon 2025 Data Breach Investigations Report — Supports the claim that vulnerability exploitation is now a top attack vector.
- IBM Cost of a Data Breach Report 2025 — Provides data on breach costs, supporting the need for budget optimization.
Contribution & Novelties
The video provides a practical framework for cybersecurity budget optimization, emphasizing the distinction between compliance and risk reduction. Ross Young’s OWASP TaSM and Murder Board offer actionable methods to evaluate and retire ineffective tools. The discussion on AI supply chain risks, including the LiteLLM attack, highlights emerging threats and provides specific questions for CISOs. The episode also introduces a process improvement exercise using Pareto charts to reduce patching times, which is a novel application of lean principles to security operations.
Pour aller plus loin :
- OWASP Top 10 for Large Language Model Applications — Relevant for understanding AI-specific threats.
- NIST Cybersecurity Framework — The framework used in TaSM for defense-in-depth planning.
- Verizon Data Breach Investigations Report — Cited for attack trend data.
- Pareto principle — The concept applied in the process improvement exercise.
- Software supply chain security — Relevant to the discussion on dependency management.
145 words
Radar Profile
The radar profile shows high scores in information quantity and technical level, indicating a content-rich and moderately technical discussion. The lower score in information quality suggests that while the information is relevant, it relies heavily on expert opinion rather than empirical evidence. Overall, the profile reflects a practical, experience-driven resource for security leaders.
💬 Sur les 0 commentaires analysés, aucune tendance n'est disponible.