Cybersecurity has board-level visibility and standing, which means engagements with information security consulting firms have never been as important as they are today. Missteps can lead to disaster, with regulatory, customer, and legal implications for the company, not to mention potential professional consequences for security leaders. In this report, we delve into the lessons learned from unproductive security consulting engagements and explore the characteristics of those that work.