Academy Sports + Outdoors [NASDAQ: ASO]

Mark Alvarado, Executive Director of IT Security & Compliance (CISO)

Why Cybercriminals Keep Winning-and What Businesses Can Do

Mark Alvarado

Mark Alvarado

Mark Alvarado Operator Catalyst

In early 2024, the retail world was shaken when VF Corporation—the parent company of The North Face, Vans and Timberland—disclosed that a ransomware attack compromised the personal data of 35.5 million customers. The breach underscored an unsettling truth: despite billions spent annually on cybersecurity, criminals continue to score high-profile wins. Why do cybercriminals appear to be winning—and what can businesses realistically do to change the narrative?

Technology Alone Isn’t Enough

Firewalls, intrusion detection systems and endpoint protection are standard fixtures in corporate defense. Yet these tools are reactive by design. They rely on patterns of known threats, which means criminals who develop new tactics often slip through before the defense catches up. Technology is also hampered by scale. A large retailer might process millions of transactions daily, each one a potential target. Even with sophisticated monitoring tools, distinguishing legitimate traffic from malicious activity is a monumental task. Attackers, on the other hand, operate with no such constraints. They can launch thousands of probes simultaneously, adapting their approach in real time.

The Human Factor

Cybersecurity tools generate endless streams of data, but they don’t interpret context. That requires people. Analysts identify subtle anomalies, connect dots across systems and make judgment calls that software cannot. Employees also remain the first line of defense— and often the weakest. Phishing emails, for instance, remain one of the top attack vectors. In the VF Corporation breach, ransomware likely spread after criminals gained initial access through compromised credentials. One careless click can undermine millions in technical investments. That’s why training is critical. A workforce that understands common attack tactics is far less likely to become the entry point for criminals. Education, not just technology, builds resilience.

The Criminals’ Advantage

Cybercriminals enjoy several inherent advantages over defenders:

1. Asymmetry of Effort – A single successful exploit can yield millions, while businesses must defend every system, every day, without fail.

2. Global Safe Havens – Many attackers operate in jurisdictions unlikely to prosecute them, insulating them from consequences.

3. Speed and Agility – Attackers can pivot strategies overnight, while corporations navigate budget cycles, procurement rules, and regulatory reviews before implementing new defenses.

This imbalance makes it appear as though defenders are always one step behind.

Cybercrime isn’t about achieving perfect security— it’s about building resilient systems that adapt, recover and endure.

Why Leadership Matters

At the center of any successful cybersecurity program is leadership—particularly the Chief Information Security Officer (CISO). A strong CISO does more than oversee technology; they serve as the bridge between technical teams and executive leadership. Cybersecurity initiatives often struggle to secure funding because they are framed as cost centers. A strong CISO can translate risk into business language, showing how a security investment protects revenue, customer trust, and shareholder value. Without that translation, even the most talented teams and robust tools may lack the resources they need. Leadership also ensures alignment. In large organizations, departments often operate in silos. A visionary CISO rallies disparate groups around a shared mission: protecting the business. In a landscape where attackers exploit gaps between teams, that unity is a competitive advantage.

A Blended Path Forward

So how can businesses tip the scales? The answer lies in integration:

Technology as Foundation – Automated monitoring, AIdriven threat detection, and layered defenses provide essential speed and coverage.

• People as Analysts and Defenders – Skilled professionals interpret data, investigate anomalies, and anticipate attacker behavior.

• Employees as the Human Firewall – With targeted, continuous training, every employee becomes a stakeholder in defense.

• Leadership as the Anchor – Strong CISOs and security leaders secure buy-in from executives, align resources, and champion resilience.

Shifting the Balance

Cybercrime is not going away. If anything, it will continue to grow more sophisticated, leveraging tools like artificial intelligence and exploiting global instability. But businesses are not powerless. By acknowledging that technology alone is insufficient, investing in skilled professionals, cultivating security-minded employees, and empowering strong leaders, companies can turn the tide. The fight against cybercrime isn’t about achieving perfect security—it’s about building resilient systems that adapt, recover and endure. In that fight, success comes not from any single tool or person, but from the strength of the combined defense.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.