Last week I published “Cybersecurity’s Real Problem? It’s the Software, Dummy”, examining former U.S. Cybersecurity and Infrastructure Security Agency (CISA) Director Jen Easterly’s argument that America’s cybersecurity challenge is fundamentally a software quality problem rather than simply a hacker problem.

Easterly’s central message was both simple and provocative:
“We really don’t have a cybersecurity problem. We fundamentally have a software quality problem.”
Her remarks generated an insightful response from M.E. (Manny) Marrero, President and CEO of CDI Technologies, based in Puerto Rico.
After reading the article, Marrero graciously shared his thoughts and gave me permission to discuss them with IP Probe readers.
His perspective is valuable because it comes not from government or public policy, but from an executive with decades of experience in the information technology industry. His observations help explain not simply what the problem is, but how the technology industry arrived here.
That, in my opinion, is the more interesting question.
Looking Beyond the Attackers
Cybersecurity discussions often focus on the latest ransomware attack, nation-state intrusion, or newly discovered software vulnerability.
We study the attackers.
We analyze their tactics.
We investigate how they gained access.
But far less attention is given to a more fundamental question:
Why do so many opportunities exist in the first place?
According to Marrero, the answer lies partly in decades of business decisions and market pressures that shaped software development.
How We Got Here
For years, software teams were encouraged to prioritize:
- Speed to market
- Competitive features
- Ease of use
- Reduced development costs
Security frequently became a secondary consideration.
“For many years, software teams prioritized competitive features, speed to market, reduced development costs, and usability over embedded security.”
The prevailing assumption was that perimeter defenses—firewalls, spam filters, malware protection, intrusion-detection systems, and similar technologies—would intercept threats before they reached the application itself.
Looking back, that assumption created a culture in which software security often depended more heavily on external defenses than on security embedded within the software.
Security Became Someone Else’s Responsibility
As Marrero explained, this philosophy influenced the way many organizations approached cybersecurity.
Software developers focused on functionality.
Network administrators protected the infrastructure.
Security teams monitored threats.
Third-party vendors supplied defensive technologies.
Over time, responsibility for security became distributed throughout the organization, sometimes leaving too little emphasis on embedding protection directly into the application.
Security was too often treated as someone else’s job.
The Application Layer Became the Target
This approach also contributed to a dangerous blind spot.
Application-level vulnerabilities were frequently underestimated, including:
- Weak authentication flows
- Insecure application programming interfaces
- Poor data validation
- Insufficient authorization controls
Today, these weaknesses represent many of the attack paths exploited by sophisticated cybercriminals and nation-state actors.
As applications have become increasingly distributed, cloud-based, and dependent on interconnected APIs, attackers have found more opportunities to target the application layer directly.
External Security Is Not Enough
Firewalls remain important.
Email gateways remain important.
Malware protection remains important.
Web filters and intrusion-detection technologies remain important.
But Marrero emphasized a crucial distinction:
“External security tools should supplement secure software—not substitute for it.”
That single observation captures one of the most important lessons emerging from today’s cybersecurity environment.
Security by Design
Modern cybersecurity practices increasingly emphasize Security by Design—embedding protection throughout software architecture and the development lifecycle rather than attempting to add it after deployment.
This approach includes:
- Strong authentication and authorization
- Input validation and sanitization
- Secure coding standards
- Encryption of data at rest and in transit
- Continuous vulnerability scanning
- Zero Trust architecture principles
These practices are reflected in widely recognized initiatives and frameworks, including:
- NIST Secure Software Development Framework (SSDF)
- CISA’s Secure by Design initiative
- Microsoft Security Development Lifecycle (SDL)
- Building Security In Maturity Model (BSIMM)
Each recognizes a simple reality:
Cybersecurity begins during software development—not after software deployment.
If We Know Better, Why Hasn’t Everyone Changed?
If the preferred approach is widely understood, why does insecure software remain such a persistent problem?
According to Marrero, the answer is not simply technical.
It is economic.
Security by Design requires meaningful investment. Organizations must devote additional resources, testing, training, specialized personnel, and time throughout the software development lifecycle.
Those investments compete against familiar business pressures:
- Tight release schedules
- Customer expectations
- Budget constraints
- Legacy systems
- Skills shortages
- Competitive markets
“Security by Design requires significant investment, and many companies have been reluctant to commit the necessary resources.”
Marrero summarized the challenge perfectly:
“It’s a classic case of dollars and cents outweighing what truly makes sense.”
Security Debt
Marrero also highlighted a concept that deserves broader discussion:
Security debt.
Just as organizations accumulate technical debt by postponing necessary software improvements, they accumulate security debt whenever protection is sacrificed in favor of speed, convenience, or lower costs.
Each deferred security improvement adds to that debt.
Each uncorrected vulnerability increases the potential cost.
Eventually, the debt comes due.
Increasingly, cybercriminals and nation-state adversaries are collecting the interest.
Two Perspectives… One Conclusion
Former CISA Director Jen Easterly approaches this issue from the perspective of national cybersecurity policy.
M.E. (Manny) Marrero approaches it from the perspective of an experienced information technology executive who has observed how organizations acquire, implement, manage, and protect enterprise technology.
Remarkably, both arrive at the same conclusion:
Cybersecurity failures often begin long before attackers exploit them. They begin when software is designed, developed, acquired, deployed, and maintained.
That observation changes the conversation.
Instead of asking only how to stop the next cyberattack, perhaps we should also ask how to reduce the vulnerabilities introduced into the technologies upon which organizations increasingly depend.
IP PROBE TAKEAWAY
My previous article argued that we have spent years focusing our attention on the attackers.
Manny Marrero reminds us that we should devote equal attention to the software they attack—and to the business incentives that influence how that software is developed and brought to market.
Former NSA Director General Keith Alexander famously warned that the theft of intellectual property represented “the greatest transfer of wealth in history.”
Former CISA Director Jen Easterly has described insecure software as enabling “the greatest transfer of risk since the dawn of the Internet.”
Taken together, those observations describe two sides of the same national security equation.
General Alexander warned us about what was being stolen.
Jen Easterly explains why so much of it has remained vulnerable.
Manny Marrero helps explain how decades of business priorities contributed to that vulnerability—and why changing course requires more than stronger firewalls or better antivirus software.
It requires changing the incentives that influence how technology is selected, developed, acquired, implemented, and maintained.
Perhaps cybersecurity’s greatest challenge is not simply stopping the next attack.
Perhaps it is ensuring that future software gives attackers far fewer opportunities to succeed.
Author’s Note: My thanks to M.E. (Manny) Marrero, President and CEO of CDI Technologies, for reviewing my previous article and for generously allowing me to share and discuss his observations. His practical perspective from decades in the information technology industry adds an important dimension to this discussion.
Disclaimer: IPProbe.Global is a service to the professional IP community. While every effort has been made to check the information in this blog, we provide no guarantees or warranties, express or implied, regarding the content provided in IPProbe.Global. We disclaim all liability and responsibility for the qualification or accuracy of representations made by the contributors or for any disputes that may arise. It is the responsibility of the readers to independently investigate and verify the credentials of such persons and the accuracy and validity of the information provided by them. This blog is for general information only and is not intended to provide legal or other professional advice.

0 comments on “Why Is Software Still So Insecure? An Information Technology Executive Responds”