← Signal to Noise
Episode 3/Deep Dive/10 June 2026/16:25

Proactive vs Reactive Cyber Security

Steve and Dave discuss the balance between reactive and proactive cyber security

Watch
Listen

In this short video, Steve and Dave explain the difference between proactive and reactive approaches to cyber security - and why they are both critical. Oh, and we talk about Mythos. because cyber.

Transcript

Machine-generated from the recording, so expect the odd mis-hearing. 3,086 words.

Dave: Hey Steve, how you doing? So then what about ⁓ what about AI, right? Because everything's AI at the moment, you know. ⁓ anyone who was at InfoSec recently, every single stand was ⁓ agentic powered AI, this, that, or the other. ⁓ there's a there's a whole thing around AI powered detection tools, but I think we you we we've talked about the the you know, bit about detection and response. I don't think need to go back around that boy again.

But Steve: I am all right, Dave. How are Dave: I'm okay, thank you. So we're not in the same room today. We're going to try doing this remotely, but I'm sure it will all be fine.

Steve: in a I'm in a booth of shame at the office. ⁓ Dave: Yeah, and I'm, as you can tell, ⁓ in the home office surrounded by all the random things that are in here.

So Steve: Yeah.

Dave: we'll let people who watch this ⁓ try and figure out my life story from ⁓ what's going on behind Obviously, one of the big cybersecurity stories of the year has been ⁓ Claude Mythos and then the other frontier models, ⁓ and their ability to find cyber vulnerabilities and exploit ⁓ new vulnerabilities or chain together exploits much more quickly than previously. ⁓ what does that mean in this in this model of ⁓ proactive and reactive security?

Steve: absolutely.

Dave: So we're going to talk today about something we touched on when we talked about our services and our approach, but we're going to deep dive a little bit into the idea of proactive security and why our approach and our philosophy is very much about getting upstream, doing things proactively rather than reactively. So we'll talk a bit about the concepts. We'll talk about Steve: Yeah. I mean it's a really good question. And you're right, like AI is everywhere. ⁓ for for good reason, right? There's there's there's a lot of, you know, human progress that's being made right now as as a result of AI. Obviously we need to get the balance right, as with anything in humanity.

Mm Dave: how it can be done and how we do it. But let's just start with the basics. So what do we mean when we talk about proactive and reactive security when we're talking in terms of cybersecurity?

Steve: Yeah. ⁓ well, I think this is a really good topic and and ⁓ one that we like to make a lot of a lot of focus ⁓ put a lot of focus on. What do we mean? ⁓ well so so we always try and kind of focus on risk and try and stay risk centric. From a cybersecurity perspective, though, there's a little bit of hyperbole in it. And what do I mean by that? Well, ⁓ yes, it's true that mythos ⁓ ⁓ rapidly changing the the pace which vulnerabilities in software are found, right? And what do we mean by risk? Well, the the the the breakdown of risk is risk equals threat times likelihood times impact or probability and impact, if you want to ⁓ use that language. And it it's so it's the summation of those three different variables. ⁓ Now, ⁓ when we're talking about cybersecurity, we don't really have an awful lot of control over the threat piece. The threat piece is controlled by somebody else. The best thing that we could possibly do is is understand the threats that we're we're facing as ⁓ an entity or organization so threats controlled by the bad guys. So that really means that we've got two ⁓ variables, two levers that we get to pull to try and control the risk. ⁓ And and those are probability or likelihood and impact. When we talk about proactive reactive, reactive cyber is is an important part of the calculus. But reaction tends to be more focused on impact management. So something is happening, a key part of managing the impact of that bad thing happening is being able to spot it. Right. So this is where like traditional security operations centers, 24-7 monitoring, you know, these these types of things I guess the the the flip side to it is, well, if you if you get if you get it right, then ⁓ software are also going to be use ⁓ using large language models. ⁓ Come into it. And that's about impact management. To patch these systems and to create ⁓ you know fixes for the vulnerabilities that are found in that software. Now, this is the you know, this is a traditional thing that's been going on since software was invented. ⁓ the the difference here is that we've just got large language models that are changing the pace at which these things happen. But it's not only variable that we get to control or the only lever that we get to pull. We we also have another lever, which is the probability piece. And probability management is about. configuring your digital estate so that the bad thing doesn't happen in the first place. Right? It's about ⁓ preventing that thing from happening and reducing the probability you're that you're facing an issue to begin with. And that comes from things like configuring your digital estate for security, layering in controls, following a ⁓ you know, a a a security philosophy like defense in depth and zero trust. And, you know, these these types of ⁓ the other thing I'd suggest is our philosophy is something defense in depth. We don't we don't rest on ⁓ one control. We used to do this as as cybersecurity professionals. We'd stick at the edge ⁓ and we call it a walled garden and that the the walls were firewalls, right? Like we'd literally put firewalls at the edges of the networks.

Dave: you Steve: frameworks that we can put in place, these controls that we can put in place to reduce the probability of something happening in the first place. Our philosophy is yes, we have to do the the the impact management. We have to do the detection and response piece. But philosophically I I would rather focus the majority of our efforts on preventing the bad thing from happening in the first place. We still have firewalls, but we don't just rely on We have A whole series of controls that cover each other off, right? And so what that means is even if there was a vulnerability in some software, we have a whole series of other controls that can try and manage the risk of that, right?

Dave: Yeah, that makes sense. So there's an analogy I like to use here. If you think about your business's physical security or protection. So detection and response, the reactive part of security, I guess is like having CCTV systems and sensors and maybe having a company who's monitoring those. Maybe you've got like a third party security company monitoring those and sitting there ready to react when those sensors trigger or when something's on CCTV and they will turn up.

Steve: So so yes, ⁓ it's something that we need to be aware of as a society. But do we need to be terrified of this in way that some people are finding? ⁓ No.

Dave: you know, and maybe, you know, chase away the bad guys or whatever. Um, but, but the reality is like, if you never lock the doors, if you leave, you know, all the doors open and the windows open, then the reality is that you're still going to get robbed. Um, somebody's still going to able to get in and steal something. Um, even if that response happens, um, even if they turn up every single time and then proactive security then for me is about, okay, we lock the doors and the windows.

Steve: the exploitability of every system on the planet in the way that some people are believing. I I just don't think that's the case.

Dave: Yeah, I I would agree with that. And the way I just describe this is look, you know, this these tools, this this new approach, it's accelerating something which happened anyway. But it doesn't change the fundamental principles. Defense in depth, you've talked about, ⁓ limited access, you know, ⁓ controlling who's got privileged access, zero trust, ⁓ you know, knowing who is inside your system and who's got access to what data, these things will all continue to protect you, you know, strong multi-factor authentication, ⁓ ensuring that but also like control the keys. You we know who has got access to what, or maybe certain doors are only opened at certain times when they need to be. There's only a requirement to open the loading bay door when you're doing some loading because that's the time at which somebody could get into it. that's an analogy I sort of like to think of here. ⁓ So I guess thinking that through there, I mean, you touched on some of the sort of controls, but what does that look like? What are the models for implementing that?

Steve: Absolutely.

Absolutely. Dave: That the right people have got access to the right things, ⁓ and that you know their identity is verified, these these principles all still stand true ⁓ and actually form the core of a hardened security system. ⁓ actually, coming back to my my analogy, ⁓ which I'm gonna stretch even further, you know, maybe Mythos is just ⁓ accelerating the the speed at which somebody can find those open windows and open doors, ⁓ and rather than having to proactive security Steve: So so there's there's different ways of implementing it. And I and I would suggest that every organization's going to have a different approach here, and there's no ⁓ kind of one size fits Dave: you know, search manually for them, well now it can scan in an automated way and f and find those open windows and doors really, really quickly. But if we make sure that the windows and doors are closed and also that you know the secure data is in a safe unlocked in a vault and again we've controlled the keys and all the rest of it, then then actually it doesn't really change the principles.

Steve: And so ⁓ if you look at the way that we implement that, we do that in various models. So one model is we actually take on the entirety of the delivery, right, for our clients. So we've got a couple of clients where, you know, they just they just want to turn the key and say, you handle all of our digital estate, both the provision of the assets and the and the the utilization of the assets, in this case laptops and accounts and you know these types of things, but also the security of those of those systems, right? And the risk is managed, right? The risk is managed. And I think that's the key thing. So ⁓ And so we we can certainly do that. We don't tend to do that an awful lot. What we tend to do is work more either with an internal cybersecurity team. So ⁓ think ⁓ you know a company that's big enough that they have a, you know, a a small team or even a large team internally who focuses on the IT provision, so the provision of the the digital assets, and we just come alongside of them and sit alongside of them as their cybersecurity kind of partners. Yep, it's something to be aware of. I I don't think we need to be terrified of it in the way that it is. ⁓ you know, it's it's just a ba a matter of sticking to the core principles of zero trust, defense and depth, a and and ⁓ you know, making sure that we're doing that over time, which are, you know, the things that we've talked about here. And so we in collaboration are responsible for the provision of the assets, but the provision of the assets in a way that manages the risk, right? Coming back to the risk. Another model could be they just want to outsource their IT and they have an external provider, ⁓ somebody who's external to the organization. And again, ⁓ we we ⁓ we like to take a approach here.

Dave: Super. Well, we've covered quite a lot of ground there in quite a short time. ⁓ I think that's probably ⁓ enough for today. So there's some things that we'll know to come back to. ⁓ I'm sure we'll talk about AI in pretty much ⁓ every time we we get together and speak. ⁓ but but for now, ⁓ good to chat. ⁓ enjoy the booth of misery and we'll speak soon.

Steve: Probably. Thanks. Yeah, we'll talk to you soon. Take care. What we do is we come alongside and sit alongside of them and work very closely with them. Obviously, getting that right is going to be really key because there are going to be times where timing matters. And so we need to work very closely with them to figure out, you know, who's responsible, who's accountable for certain things, who's informed, how do we consult, But the idea is that we want to work in collaboration with these entities. We're not there to anybody's homework.

Dave: And I think the thing that that says to me is that the importance of of the understanding of security and the importance of understanding what proactive security actually looks like. So ⁓ an IT service provider who's focused on availability has probably got some good ideas about about security and quality of those services may vary. And we know that we see that. But, know, an IT service provider is primarily focused on making sure that the lights are green and everything is blinking. And what I've certainly seen is, is an IT provider will maybe, or an internal team will buy some security tooling, but invariably that's focused on the impact management side of things, you know, buying a managed detection and response tool or service or whatever that might be. And then you get this gap. And I think that gap is where so much of that risk is ⁓ where ⁓ that You're just not managing the likelihood of a cyber incident happening. You're not managing the probability. If we think about a risk matrix, a risk vector, where you can put as much tooling in place as you want to detect things as quickly as possible and to respond as quickly as possible. That's great. And all of that will bring the risk further along ⁓ one axis in terms of the impact. But it does absolutely nothing about the probability or the likelihood of an attack or an incident happening in the first place. So that for me is where...

Steve: Absolutely.

Dave: this understanding of, what does a secure enterprise look like? What is hardening all about? What does it mean to implement conditional access? What does it mean to ensure that only compliant devices can get access to certain, know, bits of data or applications?

Steve: Yeah, a hundred percent. And and I'll be honest, ⁓ a lot of companies, you know, lots of cybersecurity companies don't like doing this. Why? Because it's really hard. You know, whenever you're changing your, you know, you're you're you're making changes to a digital estate in a in a in a client's kind of systems, you have to work with them. You have to do a bunch of change management, communications, you have to kind of be part of their team. And that's and and that's a hard thing to do. And l and a lot of cybersecurity companies, you know, they don't like doing that. That's where we love it. That this is this is what we love doing is working really closely with these organizations to not just tell them when to do the security, but actually to get in and do the security, right? And yes, of course, we will then go into 24-7, 365 monitoring. It's a key part of the the calculus. But at that point, if we've got that right, the the number of times that we actually have to respond are you know, they're they're a lot less than if we if we didn't do the work in the heartening.

Dave: Yeah, I think, I think that's right. And I think one of the other things that, that I've certainly seen in different conversations is, kind of, okay, when, when do you need to do this hardening? When do you do proactive security? ⁓ is it a, is it a project, you know, stand up a new business or a new, you think, you know, can you, can you do it, do it once and then you're kind of, you're kind of good. ⁓ or actually I think as we, you know, as we would say, the reality is, know, this is an ongoing challenge and whether it's. changes in threats, ⁓ changes in business requirements, or just Microsoft changing something because they like to do that and not tell anybody, this is a constant effort, Steve: A hundred percent, yeah. we come back to risk equals threat times probability times impact. Anytime you're making changes to a digital estate, the probability changes. ⁓ And that's just by nature of the fact that things are changing. But the threat environment is changing. You know, hackers are finding new ways of exploiting systems, there are new vulnerabilities that are discovered. ⁓ New threat actors come online and they may may take a ⁓ very approach to exploitation. You know, these types of things they they have a big impact on how the kind of threat changes or how the risk changes over time. And so, ⁓ you know, looking at something ⁓ you know as a snapshot a a at a point in time is gonna help for that point in time, but it's not gonna help in perpetuity. And so to really get this right, we have to create ⁓ you know, an enduring and durable kind of campaign of cybersecurity. To manage the risk over time.

Cyber SecurityMicrosoft 365Identity and MFAZero TrustMIDAS
TALK TO A HUMAN

If any of this sounds like your organisation, a 30-minute assessment call will tell you where you actually stand - no obligation, no sales script.

Book an assessment