MyCISO Security Budget Cybersecurity_Post Preview

The Wright Brothers’ Lesson for Modern Cybersecurity Leaders

By Jason Ha | CISO, MyCISO | By Chris Gordon | US Market Lead, MyCISO |

October 9, 2026

In the fall of 1903, two flying machines were racing toward the same goal. One was the Aerodrome, built by Samuel Langley, one of the most respected scientists of his era, backed by a substantial budget, a skilled team and national attention. The other was built by two brothers who ran a bicycle shop in Dayton, Ohio, on a budget reported at under $1,000. 

On December 17, 1903, at Kill Devil Hills, North Carolina, Orville Wright flew for 12 seconds and covered 120 feet. It was the first sustained, controlled, powered flight in history. 

The difference was not resources. It was focus. Many early aviation pioneers concentrated on building more powerful engines. Wilbur and Orville recognized that the real unsolved problem was control: how to keep a machine balanced and steerable once it was in the air. They solved that first, with gliders, before they ever added an engine. And when the published lift data they relied on proved inaccurate, they built their own wind tunnel and tested more than 200 wing shapes, replacing assumptions with evidence. 

Security leaders work through a version of the same question every budget cycle. Not “how much can we do,” but “which problem, solved first, moves the program furthest?” 

Measurement Is Now the Top Priority 

State CISOs have already reached this conclusion. Implementing effectiveness metrics is now the number one cybersecurity initiative for State CISOs at 49%, up from 25% in 2024 and 15% in 2022 (2026 NASCIO-Deloitte Cybersecurity Study). In four years, measurement has moved from a niche concern to the top of the agenda, a clear sign of how quickly Public Sector security leadership is advancing toward data-driven decision-making. 

The shift comes at the right time. Every dollar of public funding carries an expectation of careful stewardship, and new priorities continue to emerge. GenAI governance is a leading example: 94% of State CISOs are now involved in developing GenAI security policy (2026 NASCIO-Deloitte), and IBM’s 2026 Cost of a Data Breach Report found that breaches involving shadow AI averaged $5.39 million, compared with $4.63 million overall. As the list of priorities grows, the ability to identify the most impactful investment first becomes a real strategic advantage. 

That ability comes down to three questions. Where does the program stand today? Which improvement delivers the most risk reduction per dollar? And how can that be communicated clearly to stakeholders who do not work in security every day? 

Build the Wind Tunnel: An Evidenced Baseline 

The Wrights did not trust a number they could not verify. The same principle applies to a security baseline. A strong baseline has four properties. 

It is control-level. “Aligned to NIST CSF 2.0” is a statement of intent. “106 controls assessed across all six Functions, each with a maturity rating, supporting evidence and a named owner who attested to it” is a baseline. Stakeholders do not need to read all 106. They need confidence that the work behind them was done. 

It is current. A point-in-time Gap Assessment captures a single moment. A living baseline, with controls owned by named people, evidence attached and status updating as work completes, means the number presented in March and the number presented in September come from the same instrument. The difference between them tells the story of progress. 

It is comparable over time. Consistent measurement is what makes progress visible. The value of inter-mapped frameworks is that CJIS, TX-RAMP, GovRAMP, HIPAA and PCI DSS obligations resolve back to a single underlying control set, so one program of work advances several obligations at once, with the evidence to show it. 

It is anchored to risk. Control maturity is valuable, but on its own it does not set priorities. Linking each control to the key risks it addresses, and to how much an uplift will reduce that risk, is the foundation for measuring Return on Security Investment. 

Assessing controls through four lenses adds further clarity: Compliance, Maturity, Coverage and Effectiveness. Compliance shows whether a control is required. Maturity shows how well it is built. Coverage shows how much of the environment it reaches. Effectiveness shows how well it addresses the risk it is meant to reduce. A control can be fully compliant and well documented while reaching only 30% of endpoints. The four-lens view surfaces exactly that kind of opportunity, which is often where the most cost-effective risk reduction is found. 

Solve Control Before Power: Prioritize by Impact 

MyCISO Security Budget Cybersecurity_Embedded in Blog

With an evidenced baseline in place, prioritization becomes a clear, data-driven exercise. 

Model exposure across the triad of Human Risk, Supplier Risk and Technology Risk, and then ask the question the Wrights asked: not “what is the biggest component we could build,” but “which improvement unlocks everything else?” In security terms, the most valuable question is not “which control is weakest,” but “which control uplift reduces the most risk for the least cost.” Those are rarely the same control. The weakest control in an assessment might depend on a larger platform project and touch only 4% of the estate. A mid-maturity control sitting upstream of eleven others might cost a quarter as much and advance all eleven. 

That is the kind of business case stakeholders respond to: a ranked set of investments, each with a cost, an expected maturity gain and a count of the downstream obligations it satisfies. 

Transparency strengthens the case further. A prioritized plan that shows the three initiatives selected, the six deferred, and the residual risk of each deferral demonstrates rigorous, good-faith planning and builds lasting trust with the people who fund the program. 

Placing GenAI Governance Alongside Everything Else 

GenAI governance is most effective when it is evaluated on the same terms as every other investment. Treating it as a control domain keeps decisions consistent: acceptable use, data classification at the prompt boundary, model and tool inventory, supplier assessment of AI services already embedded in existing products, logging and human review thresholds. Scoring these controls the same way as everything else, and placing them in the same ranked list, lets the evidence determine where they belong. 

In many programs, GenAI governance will rank near the top, because the control cost is mostly policy and training rather than new licensing. In others, it may rank fourth, and that is a well-reasoned answer leadership can stand behind. Either way, a consistent method ensures that each decision, including what moves down the list to make room, is visible and deliberate. 

Turn Control Maturity Into an Outcome Stakeholders Recognize 

The final step is translation. Leadership and funding bodies invest in outcomes. The chain from technical work to outcome needs to be complete and visible: current maturity, target maturity, the specific controls that close the gap, the cost of closing it and the reduction in probable loss that results. Expressed as a ratio, that becomes a single sentence a non-technical audience can understand and repeat. MyCISO’s customer data puts that ratio at 3.7:1, meaning every dollar invested in security uplift avoids $3.70 in probable losses. Each organization’s ratio will be its own. What matters is having one and being able to show the working behind it. 

Two things make that ratio credible. First, the loss estimate is built from the organization’s own environment rather than a national average. Second, the maturity improvement is evidenced, which leads back to the baseline. Strong outcomes at the end depend on good measurement at the start. 

The Wright brothers did not succeed by outspending anyone. They succeeded by measuring carefully, focusing on the problem that mattered most and proving each step before taking the next. The same discipline helps Public Sector security programs direct every dollar toward its greatest impact. 

Real-Life Example 

MyCISO partnered with a Local Government agency to: 

  • Build a cyber operational risk register and identify the priority cyber risks for the agency to focus on; 
  • Assess current cyber controls against NIST CSF and the relevant local jurisdictional framework; 
  • Identify the highest-priority areas for uplift, based on the combination of risk reduction and value for money; 
  • Deliver real-time reporting that sponsors and stakeholders used to build the business case for funding and to define requirements for procuring those uplifts; and 
  • Provide ongoing reporting and visibility of those uplifts, evidencing the reduction in risk and giving sponsoring stakeholders confidence that their investment was delivering results. 

Join Us 

On November 4th, Jason Ha and Chris Gordon will walk through the full method: establishing an evidenced baseline, ranking control uplifts by risk reduction per dollar, placing GenAI governance alongside other priorities, and turning control maturity into an outcome stakeholders recognize. 

Attendees will leave with a structured approach to building a security business case that non-technical leadership can understand and support. 

Register for the webinar 

MyCISO is the Office of the CISO platform, SecurityOS, used by Public Sector and enterprise security leaders to run Gap Assessments, manage supplier risk, track maturity and report to leadership in real time. Security Simplified.

Carahsoft Technology Corp. is The Trusted Government IT Solutions Provider, supporting Public Sector organizations across Federal, State and Local Government agencies and Education and Healthcare markets. As the Master Government Aggregator for our vendor partners, including MyCISO we deliver solutions for Geospatial, Cybersecurity, MultiCloud, DevSecOps, Artificial Intelligence, Customer Experience and Engagement, Open Source and more. Working with resellers, systems integrators and consultants, our sales and marketing teams provide industry leading IT products, services and training through hundreds of contract vehicles. Explore the Carahsoft Blog to learn more about the latest trends in Government technology markets and solutions, as well as Carahsoft’s ecosystem of partner thought-leaders.


Related Articles