For years, businesses were told that cyber security was relatively simple. Put a firewall around the network, install antivirus on the computers, keep everything patched, don’t click suspicious links and job done.
Except the world has changed.
The attackers have changed. The threat has changed. The way we defend cannot stay the same.
Firewalls and antivirus are still important. I’m not suggesting businesses throw them away. The problem is believing that having them means you are secure because it doesn’t.
The attacker doesn’t have to break the door down
Traditional security was largely designed around the idea of stopping something malicious from getting into the business.
A firewall controls traffic and Antivirus looks for malicious software. Both remain useful layers of protection.
Here are some questions for you to consider:
- What happens when the attacker doesn’t look malicious?
- What happens when they use a legitimate account?
- What happens when they have stolen someone’s password?
- What happens when they use an application already installed on the computer?
- What happens when they steal a session token and effectively become the user?
There may be nothing for traditional antivirus to detect and the firewall may be doing exactly what it was designed to do.
The attacker can still be inside your business.
That’s the uncomfortable part.
Attackers don’t always “hack in”
One of the biggest changes in cyber security is the way attackers gain access. They don’t necessarily need to find a technical way through your firewall. They can persuade someone to give them access, or they steal credentials through phishing. The criminals use an infostealer to collect passwords and steal session information. If they want an easier option, they simply buy compromised credentials.
We see attackers that compromise a supplier to gain access to your business or exploit a vulnerability in an application or exposed service. The modern attacker can take over a legitimate Microsoft 365 account and operate from there. Once the criminals have legitimate credentials, the security system may see what looks like a legitimate user doing legitimate things.
The attacker isn’t necessarily breaking any obvious rules. They’re using someone else’s identity.
That changes the security problem completely.
The threat has become quieter
We also need to stop thinking about cyber attacks as dramatic events. Most business owners picture a cyber attack as:
Attack → alarm → response → problem solved.
Real attacks can be very different. An attacker may gain access and then sit quietly while they learn how you work and read your emails, policies and procedures. Once they know who has access and know how you operate, they steal your information or trigger the ransomware.
If they can steal credentials, sensitive information, customer data, financial information or access to other systems without being detected, why would they announce themselves?
The best attack, from the criminal’s perspective, is often the one you don’t notice.
This is where legacy protection starts to struggle
Imagine your business has:
- A firewall protecting the network.
- Antivirus installed on every laptop.
- Email filtering.
- Regular patching.
- Strong passwords.
That’s a good starting point, but now imagine an employee’s Microsoft 365 credentials have been stolen. The attacker logs in using the correct username and password.
- They access email.
- Search for invoices.
- They identify customers and suppliers.
- They look for conversations about payments.
- They create a mailbox rule.
- They monitor communications.
- They eventually change bank details on an invoice.
This is why the conversation has to move beyond “What tools do we have?”
We need to ask:
- “What can we see?”
- “What would we detect?”
- “Who is watching?”
- “What happens when something gets through?”
Prevention is only one part of security
I believe prevention remains essential. We should absolutely make it difficult for an attacker to gain access, but we also have to accept something uncomfortable:
Eventually, something will get through.
This is where modern cyber security needs to introduce another layer:
Visibility.
- If someone logs into your environment from somewhere unusual, can you see it?
- If a user suddenly accesses sensitive information they’ve never accessed before, can you see it?
- If someone creates a suspicious mailbox rule, can you see it?
- If an endpoint begins behaving differently, can you see it?
- If an attacker starts moving through your environment, can you see it?
And perhaps most importantly: Is someone actually looking?
Security tools don’t equal security
This is a distinction that businesses need to understand. You can have ten different security products and still have significant blind spots. Security technology generates information. Cyber security capability turns that information into action.
That’s why modern security needs to bring together:
Protection: Stop what you can.
Visibility: Know what is happening.
Detection: Identify something that doesn’t look right.
Investigation: Understand whether it is actually a threat.
Response: Do something about it before it becomes a business crisis.
This is the shift from simply having security to building cyber resilience.
The way we defend has to change
At J2, we look at this across five areas of digital risk:
Users. Email. Data. Machines. Internet.
Because an attacker doesn’t care which security product you bought.
They care about finding a weakness. This weakness might be a person, an email account, a stolen credential, an unprotected machine or exposed infrastructure. All of these things are connected.
That’s why protecting one part of the business in isolation isn’t enough. You need visibility across the environment and the ability to connect the dots.
An unusual login might not look particularly dangerous on its own.
A suspicious email might not look particularly dangerous on its own.
A device communicating with something unusual might not look particularly dangerous on its own.
Put them together and you have an attacker.
That is where modern security becomes intelligent.
The question businesses should be asking
Traditional security measures are no longer enough.
They are part of a layered cyber resilience programme; they cannot be the whole strategy.
The attackers have evolved, so must your protection.
You cannot protect what you cannot see.
Cyber resilience starts with visibility. It continues with protection, monitoring, detection and response.
Because the goal isn’t to pretend that nothing will ever get through.
The goal is to make sure that when something does, you are ready.