Security spending has rarely been higher and security confidence has rarely been lower. The common cause is not a missing tool. It is that control activity has become detached from the business services it exists to protect, so nobody can answer the only question that matters: if this went wrong tomorrow, what would actually stop working, and for how long?
That disconnection produces a recognisable pattern — a control catalogue that grows every year, an alert volume nobody has the capacity to action, a policy set that is technically current and operationally ignored, and a risk register that records concerns rather than resolving them.