Join our Newsletter — 33% off our NHI Course

What are the signs that a security programme is stuck in the Big Disconnect?

Common signs include large backlogs of unresolved issues, weak visibility into which findings affect critical assets, and teams that can only remediate a small fraction of what they discover. Another indicator is when cloud protections exist but unauthorized access can still go unnoticed. These symptoms show that tooling exists, but operational understanding of risk does not.

What the Big Disconnect looks like in practice

A programme stuck in the Big Disconnect usually has motion without closure. Findings are generated, dashboards are updated, and meetings continue, but the organisation cannot turn that activity into reduced exposure on the systems that matter most. The clearest sign is not the volume of work, it is the gap between what is known and what is actually fixed.

Another practical symptom is weak criticality context. Teams may know that a control failed or a scan returned issues, but they cannot reliably say whether the affected asset is business-critical, internet-facing, privileged, or a downstream dependency that changes the risk. That makes triage mechanical instead of risk-led.

A third sign is remediation capacity that never catches up with discovery. When the intake of issues is far larger than the rate of meaningful closure, the programme is collecting evidence of exposure rather than reducing it. That is especially common when ownership is unclear, handoffs are slow, or the same issue pattern reappears across many assets.

  • Backlogs grow faster than aged items are retired.
  • Findings are tracked, but few are tied to an accountable owner or deadline.
  • Prioritisation is based on count or severity labels alone, not on business impact.
  • Control coverage exists, but exceptions and blind spots remain invisible.

Why tooling can exist while risk still goes unseen

The Big Disconnect is often not a tooling failure, it is an operating-model failure. Organisations buy scanners, cloud posture tools, ticketing, and reporting layers, but never create a reliable path from signal to action. The result is a programme that can describe risk in aggregate while still missing the small number of issues that actually create material exposure.

This becomes obvious when cloud protections are present on paper, yet unauthorised access can still go undetected. That tells you the problem is not just control presence, but control effectiveness, telemetry quality, and the ability to interpret activity in context. A control that exists but cannot surface abuse in time is not giving the programme the assurance it claims.

The most useful way to read the symptoms is as a breakdown in operational understanding. The organisation may be measuring outputs such as alerts, findings, or completed checks, but not measuring whether those outputs changed the security state of important systems. If leaders cannot show which findings affect crown-jewel assets, which are being remediated, and which are stale, the programme is disconnected from risk reduction.

Risk and Threat Considerations

When a security programme stays disconnected, the main risk is not theoretical weakness, it is accumulated exposure. Large unresolved backlogs, poor asset context, and undetected access paths create a situation where exploitability can rise faster than the organisation’s ability to respond.

Failure mechanism: Signals are collected without a dependable prioritisation and ownership chain, so high-impact issues stay buried among lower-value work and controls appear healthier than they are.

Impact: Material risk persists on critical assets, attacks can go unnoticed longer, and leadership may incorrectly believe that coverage equals control.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 42001:2023 define the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.RM — Risk Management Strategy Links programme backlogs and weak closure to enterprise risk treatment.
ID.AM — Asset Management Criticality context depends on knowing which assets matter most.
DE.CM — Continuous Monitoring Disconnected programmes often miss whether controls detect misuse in practice.
Recommendation — Align remediation priorities to the highest-risk assets and overdue findings. Maintain an accurate asset inventory with business criticality and ownership. Validate that monitoring produces actionable alerts on critical systems.
CIS Controls v8 07 — Continuous Vulnerability Management Backlogs and slow closure are classic signs that vulnerability remediation is not effective.
05 — Account Management Unauthorized access going unnoticed points to weak account and access visibility.
Recommendation — Track remediation age and reduce the backlog of high-risk findings first. Review account activity and revoke stale or unneeded access paths promptly.
ISO/IEC 42001:2023 6.1 — AI risk assessment Selected only where automated security analysis and decision support need governance.
Recommendation — Assess whether automated findings are actually improving risk decisions and outcomes.

Practitioner Guidance

What to verify: Ask whether every significant finding can be tied to a named asset owner, a business criticality rating, and a remediation SLA. If any of those three are missing, the programme will continue to confuse activity with progress.

What to prioritise: Focus first on the small set of findings that combine high exposure, weak visibility, and high business dependence. A programme regains traction when it can prove that the top risks are being removed, not just logged.

What good looks like: Decision-makers can show how many critical findings remain open, how long they have been open, which control gaps are repeated, and whether telemetry proves the control is working where it matters most.

Practitioner takeaway: The Big Disconnect is exposed when a programme can produce evidence but cannot produce risk reduction, so the real test is whether operations change the security state of critical assets.