The technical aspects of cyber security are pretty much resolved.
The industry knows how adversaries breach networks, and we have proven techniques, technologies and procedures to stop them.
So why do breaches keep happening?
Why is it that even though large enterprises spend millions on cyber security, they can fail at even executing the basics?
My experience says that 95% of enterprise cyber security is about dealing with office politics and dysfunctional work cultures:
In the end, most people simply give-up.
When people give up, it doesn't matter how much money you throw at a problem.
Benjamin Mossé