Governance & the Boardroom

The "Watermelon" CISO: How a Compliance-First Approach is Destroying Australia's Cyber Resilience

Compliance optics have replaced technical ability in our leadership ranks. Long-term, this will harm Australia's national resilience.

Dean Kastelic5 min read

Australia’s cyber industry is suffering from a crisis of competence. A growing demand for “compliance optics” has replaced the technical abilities required to actually solve the problem.

The crisis of competence

We see senior cyber roles (Head of Cyber, Director, CISO) filled by risk practitioners, many who lack the technical depth to mitigate the risks they report. They are masters of the risk register, fluent in policy language, and present well in executive settings. But they lack the deep technical knowledge to understand adversary techniques or architect a program to defend against real-world threats.

This has created a “competence vacuum” at the highest levels. The result is the “Watermelon Effect”:

  • Green on the outside: the board sees “mature” dashboards, completed risk assessments, and clean audit reports.
  • Red on the inside: the organisation is riddled with technical gaps, misconfigurations, and architectural flaws that a moderately skilled adversary can, and will, exploit.

How did we get here? The “safe hire” paradox

This trend wasn’t born from a single decision but from a systemic failure in how we hire.

  • GRC as the “default” track: vetting deep technical skill is difficult. Vetting GRC qualifications (CISA, CISM, CRISC) is easy. Hiring managers and HR departments, often lacking the expertise to differentiate a great architect from a good one, default to the “safe” GRC background. It’s a known quantity.
  • The “malleable hire” paradox: boards and executives, who are non-technical, prefer leaders who speak their language: the language of risk, finance, and governance. A technical specialist who warns of complex attack chains can sound “in the weeds” and alarming. A GRC practitioner who presents a “mature” controls dashboard sounds reassuring and strategic. For the hiring manager, the CIO, a lack of technical depth is an asset, not a liability. It ensures the CISO never enters the legacy environment, and the underlying chaos remains unreported.

As GRC becomes the main pipeline to leadership, we are systemically filtering out the technical experts who actually build and break systems, inadvertently skewing leadership away from technical competence.

The real cost of “compliance theatre”

A financial black hole: multi-million dollar spreadsheets of opinions and half-truths, while the core systems remain vulnerable.

This “Watermelon” program isn’t just ineffective; it’s a profound business risk.

  1. Financial waste: budgets are poured into low-value “compliance activity” and “dashboard management” without measurably reducing risk. It creates a financial black hole, multi-million dollar spreadsheets of opinions and half-truths, while the core systems remain vulnerable.
  2. False confidence: the board is lulled into a false sense of security, believing their “green” dashboard means they are safe. This “competence illusion” is the single most dangerous part of the problem.
  3. Fiduciary and legal risk: when a breach inevitably occurs, the “compliance optics” will be exposed as a facade. Boards and officers who relied on a non-technical leader and paper-based reports may be found to have failed in their duty of care. The legal and reputational exposure is immense.

This isn’t just a theory. Ask this simple question: would a GRC-led program have stopped the Qantas breach? Based on publicly available information, the answer is no. The breach was not caused solely by weak policy or inadequate third-party vetting; specific technical control failures were a critical part of the root cause.

These are controls that would be missed by a GRC analyst armed with a checklist but identified by a cyber specialist or architect armed with a threat model.

At Vyfority we are so confident in this thesis that, when assessing purely GRC-led programs, we are yet to encounter a GRC-led program a red team could not get into.

The path forward

The solution is not to try and turn GRC practitioners into cyber specialists. That’s fitting a square peg in a round hole.

The real solution is to improve the executive fluency of our deep technical specialists and redefine what “real” cyber leadership looks like. It is not just a risk manager; it is a technical strategist who can speak the language of the board.

Hiring managers and boards need a new vetting framework:

  • Can this leader describe the last three major breaches (like Qantas or Medisecure) at the technical control level?
  • Can they whiteboard a defensible architecture for our cloud environment right now?
  • Are they abreast of threats targeting our industry, and can they demonstrate threat modelling by conducting a kill-chain analysis?

This is the standard we must demand. We must get back to anchoring every decision, budget, and control to a specific, understood threat: this is the way cyber programs were meant to be designed. It distils our efforts down to what actually matters, avoids boiling the ocean, and automatically exposes the blind spots inherent in a “compliance-first” method.

Key Takeaway

This doesn’t mean abandoning GRC; it remains an essential gear in the overall operating model. But when leadership is laser-focused on what matters, resilience is the result, and compliance comes as a byproduct.

It’s time to stop funding the illusion and start building defensible programs.

Where this leads

Cyber Readiness Assessments

Evidence-based posture, not self-reported confidence

Explore Cyber Readiness Assessments