Leadership

The Speed Paradox: When Velocity Becomes Vulnerability

G
Jonathan Garzon
Founder & CEO, Garzon Cyber Solutions
April 2026 · 6 min read
The Speed Paradox, Part 3 of Leadership and Cyber Governance, Garzon Cyber Solutions

In Part 1 of this series, we examined why the boardroom is where most organisations’ cyber resilience breaks down. In Part 2, we looked at the CISO’s dilemma: accountability without authority, and regulation arriving faster than any team can operationalise it.

This instalment addresses the third structural pressure reshaping enterprise security. The tension between business velocity and security capacity.

Every board wants speed. Faster product cycles. Faster cloud migration. Faster AI adoption. The competitive logic is sound. But when the organisation accelerates and the security function does not, what emerges is not efficiency. It is exposure.

The Velocity Imperative

The pressure to move fast is not imaginary. It is existential.

Sixty per cent of organisations now release software at least daily. Cloud migration timelines that once spanned years have compressed into quarters. The race to deploy generative AI has moved from exploratory to operational in under eighteen months. And in nearly every case, the team responsible for securing these deployments was not consulted at the pace the business demanded.

I speak regularly with CISOs who describe the same pattern. A cloud migration was approved at board level and executed before the security architecture review was complete. An AI tool was deployed across three business units before anyone assessed the data governance implications. A third party vendor was onboarded through procurement with no security due diligence because the commercial team needed the integration live by quarter end.

The business did not intend to create risk. It intended to move quickly. The risk was a byproduct of structural misalignment between the speed at which decisions are made and the speed at which security can evaluate them.

Security as the Department That Says No

The consequence of this misalignment is cultural as much as operational.

When security cannot keep pace with the business, it becomes the function that slows everything down. Eighty one per cent of professionals report that application security testing often slows development and delivery. Nearly half of organisations still rely on predominantly manual processes to integrate new projects into their security testing queues. And over 71% of security alerts are noise, including false positives and duplicate results that consume analyst time without reducing actual risk.

The rational response from the business is predictable: go around security. Eighty per cent of employees now use applications that have not been sanctioned by IT. The average enterprise believes it runs 91 cloud services. The actual number is 1,220. Only 8% of organisations have full visibility into their shadow IT footprint.

This is not negligence. It is the market’s natural response to friction. When the formal path through security takes longer than the business can afford, the business finds an informal path. And that informal path has no controls, no visibility, and no incident response plan attached to it.

The Cost of the Shortcut

The data on what happens when speed outpaces security is unambiguous.

Third party involvement in breaches doubled in the past year, rising from 15% to 30% of all confirmed incidents in the 2025 Verizon Data Breach Investigations Report. These are not sophisticated nation state operations. They are the consequence of vendor integrations that moved faster than security could evaluate them.

Shadow AI, the deployment of artificial intelligence tools without governance oversight, has already contributed to security incidents in 20% of organisations. Those incidents add an average of $670,000 to the cost of a breach. And 63% of organisations have no AI governance policies in place.

Meanwhile, the adversary is getting faster. CrowdStrike’s 2026 Global Threat Report recorded an average breakout time of 29 minutes, the interval between initial compromise and lateral movement. Down from 48 minutes the year before. The fastest observed breakout was 27 seconds. In one case, data exfiltration began within four minutes of initial access.

The mismatch is stark. Organisations are deploying technology in weeks that attackers can exploit in minutes, while the security team is still waiting for the architecture review to be scheduled.

The Speed Paradox, Speed gap, shadow ecosystem, and threat acceleration statistics

The Structural Problem

What connects the three pressures examined across this series is a single structural failure.

In Part 1, we showed that boards recognise cyber as a business risk but have not translated that recognition into governance and investment. In Part 2, we demonstrated that CISOs carry accountability without the authority, headcount, or budget to deliver on it. And in this instalment, we see the operational consequence: the business accelerates, security cannot keep pace, and the gap between them becomes the attack surface.

These are not three separate problems. They are three symptoms of the same organisational design failure.

The board sets the risk appetite but does not fund the capacity to manage it. The CISO absorbs the accountability gap. And the business, under pressure to deliver, routes around whatever controls exist because the alternative is missing the quarter.

IBM’s 2025 data quantifies the resolution. Organisations that integrate security into their development lifecycle, the DevSecOps approach, reduce the average cost of a breach by $227,192. Those using AI and automation extensively save $1.9M per incident compared to those without. The average breach lifecycle has dropped to 241 days, a nine year low, driven almost entirely by organisations that embedded security into their operating model rather than bolting it on after the fact.

The evidence is not theoretical. Organisations that treat security as a structural capability, embedded into how the business operates, move faster and lose less. Organisations that treat it as a checkpoint to be routed around move quickly until they do not.

What This Means for the Board

The speed paradox is resolvable. But it requires three things that most organisations have not yet put in place simultaneously.

The first is strategic security leadership. Not a CISO buried three levels below the board, but security intelligence that sits at the table where investment decisions are made. The person advising on risk needs to be in the room when the cloud migration is approved, not consulted after the contract is signed.

The second is regulatory architecture. NIS2, DORA, the EU AI Act, the UK Cyber Governance Code, and the SEC disclosure rule are not going away. They are compounding. The organisations that will manage this are not the ones hiring more compliance analysts. They are the ones building frameworks that allow a single governance structure to satisfy multiple regulatory obligations simultaneously.

The third is talent. ENISA has concluded that NIS2 compliance is structurally impossible through human capital alone. The European Union faces a deficit of 299,000 cybersecurity professionals. The UK has the widest workforce gap in Western Europe. No organisation can hire its way out of this at market rates and market timelines. The ones that will close the gap are those with access to specialised recruitment capability that understands what a modern security function actually needs.

These three capabilities, strategic advisory, regulatory readiness, and specialist talent acquisition, are precisely what Garzon Cyber Solutions was built to deliver. Not as three disconnected services, but as an integrated model designed to close the structural gap between how fast the business wants to move and how effectively it can manage the risk created by that movement.

In Part 4, we will examine the role that has quietly become the most consequential in enterprise security: the CTO. As the boundary between technology strategy and security governance dissolves, the CTO’s mandate is evolving in ways most organisations have not yet recognised.

At Garzon Cyber Solutions, we work with boards, CISOs, and technology leaders to resolve the structural pressures that make organisations slower, more exposed, and less resilient than they need to be. From CISO advisory and board level risk translation to compliance readiness across NIS2, DORA, the EU AI Act, and the UK Cyber Governance Code, and from security leadership recruitment to workforce strategy, we provide the strategic intelligence that turns cybersecurity from an operational constraint into a competitive advantage.

Speed and security are not competing priorities. The organisations that understand this will outperform the ones that do not.

Sources: IANS Research and Artico Search, State of the CISO 2025 · IBM, Cost of a Data Breach Report 2025 · Verizon, 2025 Data Breach Investigations Report · CrowdStrike, 2026 Global Threat Report · Checkmarx, DevSecOps Evolution 2025 · ENISA, 2025 NIS Investments Report · DSIT, Cyber Security Skills in the UK Labour Market 2025 · Gartner, Board of Directors Survey on Cybersecurity 2025 · Garzon Cyber Solutions, CISO Advisory Intelligence, 2026

Where does this sit on your own risk register?

A short, practical conversation about where the exposure actually is, and what a proportionate response looks like. No obligation and no product pitch.

Start the Conversation →
#Leadership#CyberSecurity#Governance#BoardRisk#CISO#GarzonCyberSolutions