entrustIT Insights

Cyber security isn't something you buy. It's something you run.

Written by Roxanne Dodd | Jul 27, 2026 11:30:00 AM

Most businesses are asking the wrong question about their cyber security.

The instinct is to ask, "how do we keep them out?" It's a natural question. It's the one most products are sold against, and it's the one that makes a quote easy to sign off. Buy the firewall, switch on the filtering, tick the box, feel safer.

But there's a better question, and it's the one security teams actually ask themselves: "if someone were already inside, how fast would we know?"

Your answer to that tells you far more about your real position than any list of tools ever could.

Keeping threats out is only part of the job

No business is unbreachable. Not the ones with big budgets, not the ones with every layer in place, not the specialists whose entire job is staying ahead of attackers. Given enough time and motivation, something eventually finds a gap. That isn't a reason to panic, and it isn't an admission of failure. It's just the actual shape of the problem.

And the gap is getting easier to find. AI is arming attackers with cheaper, more convincing ways in, at the same time as it gives defenders faster ways to spot them. Which is the point: the threat doesn't stand still, so neither can the thing you bought to stop it.

Once you accept that, the goal quietly shifts. If you can't guarantee nothing ever gets in, then how high your walls are stops being the thing that defines you. What defines you is what happens next: how quickly you notice, how fast you respond, and how much damage you contain before it becomes the kind of incident that makes the news, or the kind that quietly costs you customers, data and trust over the following months.

Prevention delays a breach, and response decides what it costs you. Those are two different jobs, and most businesses have invested heavily in the first while barely thinking about the second.

Good tools matter. Running them matters more.

This is worth following, because it changes how you spend.

Businesses rarely get caught out because they owned no security. They get caught out because the security they had wasn't working as one system, or because nobody was actually watching it. The firewall was fine and the antivirus was fine, each piece doing its job. But the layers didn't talk to each other, and the seat where someone should have been watching for the thing that slipped through was empty.

That's the real gap, and it isn't one you can buy your way out of with one more product. A better alarm just means more alerts. What closes it is someone, or something, actively running your security day to day: watching, joining the dots, and stepping in the moment something looks wrong. Detection you can prove, a response you've rehearsed, and people, or a partner, whose explicit job is to act rather than just be installed.

Which brings us to the point.

Security isn't something you buy. It's something you run.

A tool sitting in isolation is a purchase. Security is an ongoing activity, a discipline, a habit. The businesses that come through an incident intact aren't the ones that were never targeted. They're the ones who noticed early and moved fast, because someone was actually operating the thing they'd paid for.

 

Being ready, not just protected

Not with a shopping list. With a question, and it's the one we started with: if someone were already inside your systems, how fast would you know, and who would act?

If you can answer that cleanly, you're in a stronger position than most. If you can't, that's useful to know now, on a quiet day, rather than in the middle of an incident when the answer arrives on its own.

Because being secure was never really the goal. Being ready is what counts.