This is part 1 of 3 in a series of posts: The Missing Layer in Cybersecurity
The cybersecurity industry has spent thirty years and hundreds of billions of dollars building better defenses. Frameworks, certifications, compliance programs, vendor ecosystems, detection tools. The investment has been real, and it has made a difference, right? The trendline is hard to explain—as is the ROI.
Cybercrime is projected to cost $12.2 trillion annually by 2031 (Cybersecurity Ventures). U.S. cybercrime losses climbed 33% in 2024 (IC3 Annual Report). Consumer fraud losses rose 25% in the same year (FTC Consumer Fraud Data). Financial crime runs above $4 .4 trillion globally per year (Nasdaq Global Financial Crime Report), while institutions spend $190 billion annually on compliance operations just to fight it (Celent: IT and Operational Spending on Financial Crime Compliance, 2024). More spending, more programs, worse outcomes.
The standard response to those numbers is to invest more on the same things: better policies, stricter approvals, more monitoring, expanded detection, faster response. Those investments are defensible, but they share a structural limitation that the industry has been slow to name.
Governance, Behavior & Outcomes
Governance works by influencing what people do, and it reduces the probability of a bad outcome. There’s value in that, of course, and no serious organization should stop investing in it.
What governance cannot do is control what a bad outcome can reach once it occurs. A policy can make unauthorized activity less likely. It cannot prevent that activity from propagating through the network if it happens anyway. An approval workflow can require sign-off before someone accesses sensitive data. It cannot contain the exposure if that access turns out to be compromised.
There is a deeper question—one most organizations have never fully built infrastructure to answer—if something does go wrong, what can it reach? That is a different risk model. So, it requires a different kind of investment.
The Impact of Infrastructure
Security teams oftentimes analyze malware from the same machines they use for everything else. Threat intelligence analysts investigate adversary infrastructure, run persona operations, and visit hostile websites from corporate endpoints. Fraud investigators trace cryptocurrency and dig through account activity connected to criminal networks. Technology teams evaluate AI models before deployment and run code from sources they cannot fully vet, often from standard development environments.
This type of core business activity is expanding. The volume of work that requires direct engagement with untrusted content has grown significantly in the past few years, and AI adoption is accelerating it further.
Governance responds to this with controls: acceptable use policies, monitoring, approval workflows, user training. Those controls are real. But the risky activity still occurs on trusted infrastructure. If something goes wrong, the environment that’s trusted is also the environment where it goes wrong. That is an architectural problem, and governance frameworks are not designed to solve it.
The Unfunded Risk Model
While the cybersecurity industry has continued to build out a robust governance layer, there isn’t a real containment solution. There is no widely adopted, purpose-built environment where risky work can happen without directly exposing trusted systems. Governance manages behavior, true…but containment manages consequences.
Every dollar of fraud loss produces roughly $4.41 in total downstream costs (LexisNexis 2024 True Cost of Fraud Study). Every exception granted to push high-risk work through corporate infrastructure is an exposure that compounds costs. At the frequency those exceptions are now being granted, the aggregate risk is no longer a footnote in a compliance report.
The governance layer needed to come first, and it still needs investment. The next layer of risk reduction requires building something different.