Free Agentic AI Workshop Map your footprint, identify your highest-risk gaps, and leave with a leadership-ready summary. Book a Workshop→
Start assessment

Quicksand and Brick Walls: Common Enterprise Security Obstacles (and how to overcome them)

December 3, 2024 · Jason Garbis

Information security (and life for that matter) is not a video game, and we unfortunately can’t overcome obstacles simply by pressing the jump button. In our real, three-dimensional and resource-constrained world, we are often faced with problems that require ingenuity, hard work, budgets, time, and sometimes a high pain tolerance to overcome.

Easy problems are straightforward and in some ways fun to solve, but hard problems are hard. This can be frustrating, especially when the hard problems are of our own making. This came to light, along with two metaphors, through several recent conversations I had with enterprise security practitioners.

Quicksand

Information security teams that are mired in quicksand will often struggle to get projects or initiatives started. Symptoms include a lack of engagement among stakeholders, unenthusiastic responses to projects, a view of security as purely a cost center, or cultural resistance to any restrictions on user access to data resources.

The key to extricating yourself from quicksand is to recognize your situation, and avoid putting additional time and effort into fruitless endeavors. Instead, take a deep breath, and look for elements of stability or activity that you can leverage. 

For example, if your organization has a decent and regularly-used Service Desk system, you can build on that to add security-related processes such as access request and approval. With this approach you could introduce some basic level of identity governance into your organization, without having to justify, deploy, and “sell” a separate identity governance platform. 

Another example: if your organization has an ongoing business initiative to migrate on-premises applications to IaaS, you could collaborate with the IT and application teams to automate the configuration and deployment of the IaaS environment. Your primary benefit is that you’re automating work that would otherwise have to be done manually by those teams – so they should embrace your assistance. Your secondary benefit is that you’re building in security best practices.

The worst thing to do in a quicksand environment is to “try harder” with approaches that haven’t worked. Look for something solid that you can leverage and build on.

Brick Walls

Another common problem—to some degree you can consider this the opposite problem of quicksand—is when security teams have the support and resources to get started with projects, and make headway very quickly. However, then they hit a “show stopper” obstacle that halts them in their tracks—the metaphorical brick wall. And just like in the real world, running into a metaphorical brick wall is unplanned and can be extremely painful.

These brick walls manifest themselves as technical, organizational, or procedural obstacles that put a halt to all progress until they can be overcome. The worst brick walls are those that can’t be overcome, and have to be either worked around, or force us to take an entirely different path. Somewhat ironically, the technical obstacles are usually those that can be more easily overcome, either with vendor support or “creative” approaches (sometimes referred to as “ugly hacks”).

But it’s the organizational or procedure obstacles that are sometimes insurmountable. You may encounter a business owner, executive, or other stakeholder who simply is unwilling or unable to accommodate the necessary changes. These brick walls can be particularly embarrassing or disheartening, especially when the inevitable finger-pointing leads to a conclusion that the security team didn’t do enough homework or briefing of stakeholders.

Clearly, the best way to avoid hitting brick walls is to do the requisite prep work to ensure they don’t exist in the first place. But, that’s an unhelpful and obvious answer. The harder question is, what do you do when you encounter one of these brick walls?

We have three possible approaches:

  • Take the brick wall out of scope: Proceed with your initiative for other parts of the organization, leaving the brick wall in place and unchanged. Note that this strategy can work for some types of technologies and projects, but not all
  • Appeal to a higher power: Acknowledge the stakeholder and the obstacle, but counter that with a more powerful argument, such as a mandate or audit finding. If these exist, they will work, although they will probably burn any goodwill you have with the stakeholder. Note that sometimes, this is necessary.
  • Create a small hole in the wall, and sell the value to dismantle the rest: Negotiate a non-disruptive trial scenario or pilot environment, then “sell” the value to the remaining users. Ideally there will be appealing aspects to your project, and other users will want to be onboarded.

Finding the Magical “Jump” Button

I  hate to disappoint you, but there is no magical jump button here. However, the closest thing we have is to clearly tie security initiatives to business value. By showing that you’re supporting a higher-order business need (such as expanding to a new market, or enabling secure collaboration with partners), you can often gain support for what otherwise would be an uphill battle.


In general, there are approaches and strategies that will work in most environments and can help you overcome obstacles. However, sometimes they don’t work, and you simply have to punt (to mix metaphors). But, in most environments, you’ll find that talking to your counterparts and really listening to their concerns and needs will lead you to a positive outcome. And sometimes, you’ll discover that the people offering the most resistance actually have legitimate and reasonable reasons for doing so. And that you’re the one that needs to adapt, not them. Life’s funny that way.

Discover more from Numberline Security

Subscribe now to keep reading and get access to the full archive.

Continue reading