Info-Tech Research: Control-First Security Designs Limit Business Value, Advocates Service-Centric Framework

Many corporate security programs are built backward, according to new research from Info-Tech Research Group. The global advisory firm found that security teams design around controls first — and only then think about the business services those controls are supposed to protect. The result is friction, blocked workflows, and security that limits business value instead of enabling it.
To fix this, Info-Tech Research Group released a new blueprint called "Build Security Services for Business Value." It lays out a service-centric model that treats security as a built-in enabler, not a bolt-on control layer. The firm says this shift is urgent for CISOs and IT leaders who want security to actually support how their organization works.
The core problem, says Info-Tech Research Group, is that most security programs start with a control — a firewall rule, an access policy, a compliance checkbox. They do not start with a question: what business service are we protecting, and how does it deliver value? That backwards approach means security teams often create obstacles for the very people they are supposed to help.
Info-Tech Research Group says this design flaw is widespread. When security is built around controls alone, it lacks clear context. It also lacks measurable outcomes. That makes it hard to explain to business leaders why security spending matters — or what it is actually doing for the organization.
The blueprint from Info-Tech Research Group offers a three-phase framework. Phase one is to define security services clearly — treating each one as a distinct object with context and purpose. Phase two is to align those services to business workflows, customers, and risk. Phase three is to operationalize them so they function inside how the organization actually delivers outcomes.
Info-Tech Research Group says each security service must be tied to governance and capability, not just technology. The goal is for a security service to map directly to a business workflow. That way, when security acts, it supports work — it does not interrupt it.
A key idea in the blueprint is that security must be defined as something with measurable value — not just a list of rules. According to Info-Tech Research Group, that means linking every security service to a clear business outcome. Think less "we block unauthorized access" and more "we protect the payment workflow that drives 40% of revenue."
Info-Tech Research Group argues this shift matters most at the leadership level. CISOs who can show how security services connect to business capabilities will earn more trust — and more budget. Right now, many cannot make that case because their programs were never built with business value in mind.
The blueprint is a practical guide, not just a critique. Info-Tech Research Group gives IT and security leaders a starting point: map your current security controls to the business services they touch. If you cannot draw that line, the control may not be well-targeted — or it may be creating more friction than protection.
The firm's advice is direct: stop building security as an add-on and start building it as infrastructure. According to Info-Tech Research Group, security designed around business services is easier to justify, easier to manage, and far more likely to actually reduce risk where it counts most.
Publishers
8
Articles
8
Reach
8