Most organizations think they’re protected.
Firewalls. Antivirus. A password policy. Maybe MFA on email. On paper, it looks solid. In reality, most of it hasn’t been pressure tested.
This isn’t about effort. Most teams are doing a lot with limited time and budget. It’s about visibility into whether the controls are working. And that gap between ‘installed’ and ‘effective’ is where most of the risk lives.
Organizations are investing in security. The problem is they don’t have a clear picture of whether those investments are doing what they’re supposed to do. That’s a visibility problem. And it’s one of the most common things we walk into.
What we keep finding
When we sit down with a new client, we’re not usually there because something catastrophic happened. We’re there because someone in leadership has a nagging feeling that their security posture isn’t as strong as they’d like it to be. And often, that feeling is right.
Three gaps show up more than any others:
- Controls that were set up once and forgotten. Firewalls with rules from five years ago. Antivirus that hasn’t been reviewed in months. Tools nobody owns anymore. The technology is there. It’s just no longer doing what they think it is.
- MFA that isn’t everywhere. Multi-factor authentication is one of the most effective defenses against unauthorized access. Most organizations have it on email. Far fewer have it on remote access, financial systems, or the operational tools people use every day. These gaps are exactly where the exposure is.
- No real visibility into what’s happening. Logging and monitoring feel optional until something goes wrong. When it does, the ability to understand what happened, when, and how far it spread is the difference between a contained incident and a full-blown crisis. A lot of organizations find out too late that they were flying blind.
Technology decisions are no longer IT decisions
They directly impact revenue, risk, and insurability. And it’s a shift most organizations haven’t fully reckoned with yet.
Cyber insurance carriers are asking harder questions at renewal. They want to know specifically whether MFA is in place, whether an organization has endpoint detection rather than just antivirus, whetherbackups are immutable and tested. If the company’s controls don’t hold up to scrutiny, their coverage might not either. That’s a business problem, not an IT problem.
Clients and vendors are sending security questionnaires before signing contracts. We’ll dig into that more in an upcoming post, but the pattern is clear: security posture is becoming a factor in whether companies win or keep business. Again, a business problem.
The organizations navigating this well aren’t the ones with the biggest security budgets. They’re the ones that know exactly where they stand.
Where to start
If you don’t have that level of visibility today, here’s a simple place to start. We have put together a self-assessment with thirteen questions across five categories:
- Identity and access
- Endpoint and infrastructure
- Email and communications
- Resilience and recovery
- People and policy
Work through it with your IT team or bring it into a leadership conversation.
While having 12 to 13 controls in place demonstrates that you are in a pretty good place from a cybersecurity perspective, it does not automatically mean your organization is secure. The effectiveness of each control—combined with strong governance, continuous monitoring, and a well-tested incident response capability—ultimately determines your organization’s ability to prevent, detect, and respond to threats.
Even the strongest technical controls can be bypassed, making preparedness and resilience equally important.
Download the self-assessment here.
And if you’d rather pressure-test your environment with someone who does this every day, we’re happy to spend 30 minutes walking through where you stand.
Most organizations don’t have a cybersecurity problem. They have a visibility problem. And they don’t find out until something forces the answer.
This is the first post in our Field Notes from the Front Lines series, practical insights from what we’re seeing with clients across New Jersey and beyond. Next up: Why Your Cyber Insurance Policy is Quietly Becoming Your Security Standard.
