Breach Shaming Won't Fix Your Incident Response Strategy
- Simon Woods
- 2 hours ago
- 3 min read

United we stand, divided we fall…
Tonight's one of those nights where I'm lighting the candle at both ends, but before I sign off and hit the hay, I've had the thought: "who will get breached tonight?" It's a question that says a lot about the state of cyber security risk mitigation right now, there's always somebody, and when it's a high-profile case, the jungle drums start beating. Platforms like LinkedIn are awash with sneers and jibes, and industry vendors start dreaming up rumours about why these organisations didn't have the right data breach response in place (it usually has something to do with them not using that particular vendor's tech).
Now, I'm probably being a little cynical because it's late and I'm perennially tired, but it's often as if the security community loves scoring points when there's a breach. What gets lost in the noise is the reality most security teams live with every day: chronic under-resourcing, teams stretched thin, and an incident response strategy that's only as strong as the time and budget behind it. Vendors get a double joy out of a breach too, because they get to whip up tales creating further fear, uncertainty and doubt. There's an air of schadenfreude amongst the "community."
The Schadenfreude Problem
Personally, I feel that we need to be a little bit more responsible about how we look at these things and not tittle-tattle. Instead we should recognise that breaches can happen to any organisation, they’ve even happened to some of the large, well-known security vendors.
Three Truths About Breaches
If you don’t work there, you don’t actually know what happened
Unless the breached have released a detailed statement, you don’t actually know what happened.
Unless you’re the attacker yourself, you don’t actually know what happened.
Let’s give our clients / potential clients some respect. They know that somebody, somewhere is under scrutiny and probably have a good idea of how that would feel if the boot was on the other foot. They probably know that there are vulnerabilities on their own network and they are probably struggling to gain support internally as such, they’re doing the best they can with limited time and resource. I speak with many security teams; I never see an over-resourced team.
Why There's No Silver Bullet for Your Incident Response Strategy
Let’s also be honest, there isn’t a silver bullet that can fix the problem, it’s always about mitigating the risk and making best efforts. We do this by ensuring that the correct people are in situ and are carrying out the correct processes. Once these are in place, the correct technology can assist.
Allow me to reiterate:
There’s no silver bullet
Teams are under-funded and over stretched
It could happen to you
With that in mind, why are we sneering? Let’s not forget, a security team has to be on their game 24/7 whereas an attacker only needs to get it right once! Shouldn’t we be a little more supportive and understanding rather than putting the fear of God into people?
I despair.
What to Do Instead
If you have had the fear put into you and you would like to talk about how you can review your strategy without the unlimited budget and resource, feel free to get in touch with our team.
Whether that's a fresh look at your incident response plan, a conversation about where your current gaps sit, or simply a second opinion on what "good enough" looks like for your size and sector, we're happy to help your security effort and Face Everybody and Rule...




Comments