Ryan Ikeler is the President of MOXFIVE, advancing business resilience and technical recovery for organizations navigating cyber incidents.gettyThe most honest view of a security program is the one you get on its worst day. Having watched that day unfold, again and again, across organizations that never expected to be there, changes how you think about cybersecurity. By the time we are brought in, defenses have already failed. Our job is to reconstruct what happened, determine what the attacker reached and explain why trusted safeguards did not perform as expected.The most useful insight into a security program comes from a live investigation, where assumptions are replaced by evidence. Across enough of those investigations, one pattern becomes impossible to ignore: companies consistently overestimate how much visibility they have, how quickly they can respond and how well their controls will hold under pressure. The gap between what leaders believe and what is actually true is where most incidents live.The latest industry data reinforces that reality. The 2026 Verizon Data Breach Investigations Report found that exploitation of software vulnerabilities has overtaken stolen credentials as the leading initial access vector, accounting for 31% of breaches.Tools Are Not The Same As ReadinessMost organizations believe they are prepared because they have checked the boxes prepared companies are supposed to check: they purchase cyber insurance, an incident response retainer and tools for endpoint detection, backups and a steadily growing stack of security products. Then an incident arrives and the gaps appear anyway.The problem is rarely the wrong purchase. It is a half-finished one. A company deploys an endpoint detection and response solution but has no one monitoring it around the clock, or it keeps backups that cannot be restored quickly enough to matter. The capability was purchased to prevent this exact scenario. It just wasn't fully in place, which nobody discovered until the day it was needed most. Maturity is not the number of tools an organization owns. It is how effectively those tools are deployed to reduce risk.Breaches Are Built, Not TriggeredUnlike Hollywood portrayals of a single genius exploit, real incidents are quiet and cumulative. Attackers succeed because small, individually forgivable weaknesses accumulate until they form a path: a patch deferred, a credential that outlived its purpose, an unverified segmentation boundary, a gap in monitoring. Investigations seldom trace back to one failure. They trace back to a chain of them, each link reasonable on its own and consequential in combination.This is why grounding security decisions in forensic reality matters so much. It keeps resources focused on what genuinely fails, not noise from peers, vendors or whatever is loudest that quarter.Detection Has Gotten Harder, Not EasierAttackers have mostly gotten quieter, not louder. Deloitte's 2025 Cyber Threat Trends Report notes that attackers continue to blend credential theft, social engineering, AI-assisted phishing and exploitation of existing vulnerabilities in ways that make malicious activity more difficult to distinguish from normal enterprise operations.Heavy obfuscation and living-off-the-land techniques, along with slow, patient movement through an environment, mean that many intrusions no longer widely announce themselves with a ransom note or a black screen. Dwell time has always determined how bad an incident gets, but attackers’ tactics used to leave more detectable breadcrumbs for you along the way. Now the clock starts more silently, and the organizations that catch it early are the ones actively looking, not the ones waiting to be told.AI does not change this dynamic; it accelerates it. The result is more attempts, harder-to-distinguish activity and less time before one gets through.Despite the shifting trends accelerating threats, enterprises resurfacing from a cyber incident still have the same options as before. The common post-incident instinct is to fill a gap by buying emerging security tools and listening to new product demos. The better answer is to invest in battle-tested tools proven against real adversaries. Product comparison marketing material and closed-loop demos do not help you understand which tools will hold up under the pressure and which will quietly fail. This insight comes only from watching them perform in real incidents, not in theory.That same evidence also answers a harder question: what attackers do once inside, not in theory, but as demonstrated across real incidents. Using that knowledge to prioritize defenses based on how intrusions actually unfold, rather than how they are assumed to unfold, makes clear what deserves attention and what is just noise.Find The Budget Before A Major Cyber Incident Here is the part every security leader will recognize. The money usually appears after the incident. Initiatives that stalled for months suddenly become urgent. Everyone agrees, too late, that the company never wants to endure this again.The most resilient organizations do something counterintuitive: they adopt post-incident clarity before an incident. They ask one disciplined question while there is still time to act on the answer. If we were breached tomorrow, what would we wish we had already done? The answers are usually specific, affordable and far less exotic than the market would suggest.That clarity does not have to come from your own incident. Firms that investigate breaches across many industries and many clients accumulate exactly this kind of evidence: patterns in what fails, what holds and how intruders move once inside. Engaging that evidence before an incident, rather than waiting to generate your own, is itself a form of preparedness.Staying Ahead, Not Bouncing BackThe strongest organizations are the ones that hold an honest picture of how their program would behave under real conditions, because they closed the gap between what they believed and what was actually true, often using evidence gathered by others before an attacker found it for them.The breach is not the story. The gap is. The question facing leaders is not whether their program looks strong on paper. It is whether they know, with evidence from real incidents rather than confidence, how it would actually hold up on its worst day.Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?
Security Readiness Looks Good On Paper. Investigations Say Otherwise
The strongest organizations are the ones that hold an honest picture of how their program would behave under real conditions.






