All articles

Why tools really are not always the best answer

Why tools really are not always the best answer

Security never stands still. Neither do hackers. In a world where cybersecurity is becoming increasingly important, more and more high-tech tools are appearing. But purchase, installation and administration all add up… They cost money. Are expensive tools any good? And do good tools actually protect you against hackers?

Do all tools deliver on their promises? That is why we test security tools ourselves in a lab under realistic conditions. We also carry out around 100 penetration tests each year to discover how cybersecurity tools respond to attacks. Unfortunately, our Robin Hoods still uncover alarming issues. Some state-of-the-art solutions, for example, fail to stop a simple, old hacking attempt. Oops, thanks for that. But it is not that simple, because every successful hacking attempt can be fatal to critical business processes or sensitive information…

Navigating blind with expensive tools

Although tools are not the only answer, many organisations make that mistake. “Just give us an oil tanker, then everything will be secured in one go.” You can only hope. Buying an oil tanker is one thing; knowing how to sail it is another. Too little knowledge and experience of how it works results in suboptimal configuration and administration of the tools. In short: an oil tanker without a captain or compass. There is a high risk of under- or overprotection, as with last year's impressive SOCs.

The greatest dangers lie in endpoints and the cloud

To discover which tools suit your organisation, it is important to know where the greatest dangers lie. In other words, where hackers have the best opportunity to gain entry. According to many studies, endpoints, the devices used by mobile workers, meaning laptops, together with cloud solutions, now pose the greatest danger to businesses. The reason? Digitalisation, innovation, scalability, flexibility and increasing numbers of people working from home in the Netherlands.

What stands out is that attack methods do not change. The specific entry point is usually a social engineering attack, such as phishing, or a known vulnerability they exploit. A successful attack on an organisation always requires a vulnerability, misconfiguration or lack of adequate incident response. The steps attackers then take within a network remain essentially the same.

So are tools the answer after all?

The short answer: no. The long answer: it depends. Is there enough expertise in-house to interpret and translate the data the tools generate? Of course, the security solutions a company uses should do what they promise. But you also need to know how to use those tools correctly for your particular organisation. Otherwise, it is like firing blanks.

IT managers would therefore do well to implement the five familiar basic measures to prevent unsuspecting end users from letting a Trojan horse into the company network. The National Cyber Security Centre (NCSC), the government organisation responsible for increasing the digital resilience of Dutch society, offers similar advice. But that is not all an organisation can do… (techie alert 😉).

Tools + techies = !!

It is important for an organisation always to have enough technical staff in-house. Techies who know how to use tools, interpret data correctly and connect the dots like Sherlock Holmes. That is not easy with the current shortage of security specialists in the labour market. Fortunately, our friendly team and challenging assignments naturally attract reliable security specialists and young talent, which your organisation can benefit from. 😊

Cybersecurity is not only about keeping EVERYTHING out

Tools can certainly be effective, but they are not an all-in-one solution. Tools alone will not keep EVERYTHING out. That is not what cybersecurity is about, either. It is about the right security for the right threats. And, on top of that, acting correctly and quickly IF something happens. That is why we have a SHORT playbook so an organisation can respond quickly if something does go wrong.

In summary: good tools are not enough. Security policies and business operations must also be in order. You want momentum, not stopgap fixes and lengthy recovery operations. A few tips to get started:

  • Use a security awareness campaign to make employees resilient to social engineering.
  • Organise things so people can easily report unusual events or incidents, allowing the incident protocol to take effect quickly. That way, one click on a phishing email cannot immediately encrypt the entire network with ransomware. Many employees' work involves clicking files to open them, and accidents can easily happen.

Want to get started yourself?

Request our compact checklist to analyse how your organisation can better defend itself against cybercriminals.


Back to all articles