Benjamin Fabre is the cofounder and CEO of DataDome.gettyThere's a meeting that happens at almost every technology company, usually triggered by a crisis, a market shift or a competitor's launch. Someone opens a slide deck, points to a new threat and says: "We need to build for this."This sounds like the right response; but in reality, it is often where the problem begins.In security, I have seen this pattern repeat again and again. Companies build for the threat in front of them, only to find that the threat has changed by the time the product, architecture or strategy is fully in place.Five years ago, many teams were focused on traditional bots. Then came more sophisticated fraud networks. Then AI-powered scraping. Now, AI agents are creating a new category of traffic that barely existed in any meaningful form 18 months ago.Each shift changes the question companies need to answer. Each one can expose products that were built too narrowly around the previous wave.The organizations that remained relevant through those changes were not the ones that perfectly predicted the next threat. Instead, they built on a foundation that could survive the next shift.The Problem With Problem-Driven BuildingWhen security teams or product leaders design for a specific threat, they usually build something that works well for that threat: The detection logic is calibrated to today's attack patterns, the data model is structured around today's traffic categories and the product roadmap is organized around today's customer pain.Then the threat mutates, and the foundation doesn't hold.This isn't unique to cybersecurity. Platform shifts (from on-premises to cloud, from desktop to mobile, from search-driven discovery to AI-mediated everything) have repeatedly exposed the fragility of products built around a specific moment rather than a durable principle.I'm not suggesting that you need to predict each shift, only that your foundation must be built to navigate these transitions.The Question Worth Building AroundFor years, cybersecurity centered on identity: Is this a human or a bot? The binary made sense when automated traffic was almost universally malicious. But as automation became embedded in legitimate business workflows (helping users shop, research and complete transactions), that binary collapsed.The question that replaced it was: What is this request trying to do?Identity tells you what something is. Intent tells you what it's after. And unlike identity, which becomes harder to verify as systems grow more sophisticated, intent reveals itself through behavior. You don't need to know whether a request comes from a human or a machine to understand whether it aligns with the purpose of your system or works against it.Intent as a foundational concept doesn't care what type of traffic it's analyzing. It applies equally to a legacy credential-stuffing bot, a modern AI agent booking travel and whatever comes next. That's what makes it a durable foundation rather than a point solution.This applies well beyond security. If you're building in a fast-changing environment, the question is whether the concept at the core of your product remains relevant regardless of how the interface or infrastructure around it changes.What A Durable Foundation Actually RequiresIdentifying the right foundational question is the beginning, not the end. Actually building on it demands three operating commitments that most organizations underinvest in.The first is real-time processing without compromise. Decisions made on sampled data, or data that's hours old, are decisions made about a world that no longer exists. In environments where threats evolve intraday (as they do in fraud), your architecture needs to run at the speed of the problem, not the speed of the budget cycle.The second is continuous learning infrastructure. No model trained on last year's patterns is adequate for this year's threats. The gap between what a system learned and what it's currently seeing is where failures happen. If every decision feeds back into your detection quality, improving the model rather than just being recorded, you compound your advantage over time in a way that point-in-time solutions never can.The third, and perhaps most underappreciated, is shared signals. The most powerful networks are ones where participants make each other smarter. In security, every attack pattern encountered anywhere in a system should inform every node's defenses. Isolated data is far less valuable than connected data. The Strategic Implication For LeadersTechnology leaders need to move from asking, "What do I need to build for the next 12 months?" to asking, "What do I need to build to remain relevant for the next 10 years?"Those questions lead to very different architectural choices. The first produces roadmaps loaded with feature responses to current conditions. The second produces investments in infrastructure, data architecture and detection that improve with scale and time.Building for the second question usually handles the first one, too. A foundation built around a durable question tends to solve today's specific problems with more precision than a product built exclusively for them.The disruptions won't stop. The threat patterns, the attack vectors, the user behaviors—all of it will look different five years from now than it does today.The only question is whether you're investing now in the foundations that will still matter on the other side of those changes, or whether you'll still be reacting to the last threat when the next one arrives.Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?
To Build For The Future, Stop Trying To Predict It
The disruptions won't stop, so organizations should invest in a foundation that will still matter on the other side of the constant changes,






