I have spent 27 years responsible for keeping businesses running — the kind of
role where one person handles the servers, the network, the backups, the email, the vendors, and the
phone that rings at 2 a.m.
In that time I have learned that the businesses that come through an attack and the
businesses that do not are not separated by which security products they own. They are separated by
how many of their assumptions turn out to be true.
Every business has a set of beliefs about its own security that nobody has ever checked.
The backup that runs but has never been restored. The tool that is installed but not monitoring what
you think it is monitoring. The provider you assume is handling something that was never in scope.
The plan in a folder nobody has read.
None of that is carelessness. It is what happens when the people responsible are busy,
which is always.
An incident is where you find out which beliefs were true.
That is a
terrible time to find out.