Skip to main content

How I Predicted the Future of Security

·1089 words·6 mins
FTC Disclosure: As an Amazon Associate, I earn from qualifying purchases. Some links on this site are affiliate links.
Ben Piper
Author
Ben Piper
Wiley bestselling author — 100k+ copies, AWS Solutions Architect Associate (SAA) & Cloud Practitioner (CLF) bestsellers, 7+ books. 45 Pluralsight courses (4.7-star, 3,003 ratings). 10+ yrs 100% remote, solo CCNP ENCOR.

A Look Back from the Future
#

In September 2012, I published an article titled “Too Much Prevention, Not Enough Cure.” Its core argument was simple: IT leaders were focusing too much energy on preventing security breaches and not nearly enough on planning for when they inevitably happen.

Looking back from today’s landscape of massive, high-profile data breaches, that observation proved to be unnervingly accurate. Every year, another major organization learns this lesson the hard way. Let’s revisit that decade-old argument and how I was able to make this prediction.

The Core Argument From 2012
#

My original argument centered on a strange double standard within IT strategy. I contrasted the industry’s attitude toward data loss with its attitude toward security breaches.

For data loss, IT professionals have long accepted that it’s a matter of “when,” not “if.” No one aims for a mistake-free environment where user error or bit rot never occurs. Instead, the industry focuses on robust contingent actions, namely maintaining and testing data backups.

In stark contrast, security was often treated as a “no mistakes allowed” discipline focused almost exclusively on prevention. The goal was to build an impenetrable fortress, a posture I argued was doomed to fail. As I wrote then, the same axiom applies: it’s not a question of “if” you’ll have a breach, but “when.”

The reasons for this prevention-only focus were clear. Preventive actions are easier and highly visible. But more than that, blocking an attack is exciting and rewarding. Planning for failure, by comparison, is not nearly as glamorous.

Why That Prediction Was Right: Technology, Risk, and Human Nature
#

The accuracy of the “when, not if” prediction for security wasn’t the result of a crystal ball. It was based on an understanding of fundamental truths that remain unchanged, starting with our own psychology.

Humans are notoriously bad at accurately assessing risk. We tend to discount low-probability events, even when their consequences are catastrophic. The likelihood of a serious breach on any given day may feel close to zero, so we psychologically default to prevention. This flawed risk assessment is the foundational reason why so many leaders fail to plan for an event they see as inevitable in theory but unlikely in practice.

Beyond this blind spot, the prediction was grounded in two other constants:

  1. The Nature of Technology: Complex systems fail. It’s an unavoidable reality. The pursuit of a “mistake-free” technological environment is a fool’s errand. As I noted back then, “failures happen,” and an effective strategy must be built on the acceptance of this fact, not the denial of it.
  2. The Nature of People: Technology is operated by people, who are fallible. Whether through simple user error or the malicious intent of a “rogue employee,” the human element makes a 100% prevention rate impossible. No firewall or security policy can completely eliminate this risk.

My prediction held true not because I could see the future of cyberattacks, but because I understood these foundational principles. Our risk assessment is flawed, technology will always have vulnerabilities, and people will always be imperfect.

The Enduring Lesson: Plan for the Cure, Not Just Prevention
#

History has consistently proven the value of contingency planning over prevention-only strategies. The most powerful example remains the one I used in 2012.

Data backups are the model security strategy should have followed from the beginning. The entire IT industry accepts the “when, not if” axiom for data loss, and as a result, a mature, robust set of best practices for contingent action (backing up and restoring data) already exists.

To make the point tangible, consider the scenario I posed a decade ago.

Imagine for a moment that you are awakened at some unholy hour of the morning with the news that someone, somewhere, is in your network downloading confidential data. What do you do?

If your immediate, confident answer isn’t a pre-defined set of steps, you are left with only one option: to “figure it out as you go.” In a crisis, that is a recipe for catastrophic failure. As I warned then, you’re one breach away from looking for a new job.

A Blueprint for Your Contingency Plan
#

A contingency plan isn’t about planning for every possibility, but for plausible scenarios that could realistically occur. Consider these examples from the original article:

  • A rogue employee makes off with confidential data.
  • An attacker breaches your network and begins collecting data.
  • Data is intermittently leaking out, but you don’t know how or when.

For scenarios like these, a solid contingency plan should include three core elements.

  1. Stopping: This is your first move, cutting off the attacker’s access. The goal is to staunch the bleeding immediately, even if it means disrupting operations. The priority is to prevent further data exfiltration.
  2. Freezing: Once the immediate threat is stopped, you must preserve the “scene of the crime.” This means taking steps to ensure that all relevant data and systems are maintained in their current state for a full forensic analysis.
  3. Recovering: This final stage involves revising your prevention plan based on what you’ve learned from the breach and, finally, getting your operations back to normal.

It’s critical to understand what a contingency plan is not for. As I stated in 2012, notice I said nothing about “getting back” any data. That’s impossible. Once confidential information is stolen, it’s gone. The goal of contingent action is to limit the damage and, if possible, prosecute the responsible party. There are no winners, and that’s why contingent action is rarely on IT’s radar.

It’s Still a Matter of “When”
#

A decade later, the central message remains unchanged and is more critical than ever. The focus on prevention at the expense of contingency planning is a failing strategy. The organizations that thrive in the face of modern threats will be those that accept the inevitability of failure and plan accordingly.

This brings me back to the final question I posed in 2012, a challenge that is as relevant today as it was then: “What other areas of your life and organization have you failed to create contingency plans for?”

Embracing the reality that things will go wrong is not a sign of weakness. It’s the first step toward building true, lasting resilience.

Recommended Reading#

Featured image by Mohamed Marey on Unsplash