This is yet another in my "Stuff I Say" series of posts. I like to think about concepts of security management, though these ideas can certainly be applied to IT management (and management in general). The themes of these posts are both things I think about and things I actually say.
We've all got an incredible amount of work to do. Most organizations have too many projects and ongoing development work, as well as too many existing and legacy tech assets to secure. There are not enough resources to go around and the shortage of talent has been discussed in the tech media. Prioritization is always a challenge.
Security professionals have a difficult job. Protecting individual and corporate data, and systems and networks is complex and often not well defined. We don't really know when we've got it "right" (if there is a right), but we often find out the hard way when we've got it wrong!
So, when faced with a new project, some security groups want to try to do everything at once. We can't boil the ocean... but we have to start somewhere. Some call it baby steps. Some call it putting one foot in front of the other. I call it Iterative Improvement.