International Cyber Expo International Cyber Expo
  • About Us
Wednesday, 7 October, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Verify it, don’t assume it: why untested security controls are making life easy for attackers

by Lara Joseph
October 7, 2026
in Featured
Verify it, don’t assume it: why untested security controls are making life easy for attackers
Share on FacebookShare on Twitter

This year’s Cybersecurity Awareness Month theme, “Don’t Make It Easy for Them”, is usually read as advice for individuals. Cynthia Overby, director of strategic security solutions, ZCOE, at Rocket Software, says it should be read just as closely in the boardroom. “As Cybersecurity Awareness Month commences, the theme, ‘Don’t make it easy for them’ must apply to organizations just as much as individuals,” she says. “The past few months have shown no shortage of evidence as to why building cyber resilience is more crucial than ever before, and we will no doubt see this evolve further over the coming year.”

She is clear about what has changed. “The most significant shift over the past year is not that attackers are using entirely new techniques, but that AI has dramatically increased the speed, scale and sophistication with which existing methods can be executed.”

Victoria Dimmick, CEO of Titania, makes a similar point about where attacks begin. “Cybersecurity Awareness Month’s theme, ‘Don’t make it easy for them,’ is a useful reminder that many successful attacks don’t start with a highly sophisticated technique. They start with an opportunity we’ve left open,” she says. “Attackers rarely need to innovate when basic network infrastructure remains neglected and exposed.”

“That could be an unpatched vulnerability, an unnecessary route to the internet, an overly permissive access rule or a temporary exception that was never removed,” Dimmick continues. “Individually, these can seem like small issues. But attackers increasingly have automation and AI to help them find and exploit weaknesses faster, making the basics more important, not less.”

The speed gap

Mark Kuhr, CTO and co-founder of Synack, says speed is the defining story of the year. “Cybersecurity Awareness Month invites the usual reminders about passwords and phishing, but the more urgent story this year is speed,” he says. Synack’s 2026 State of Vulnerabilities Report, Kuhr explains, was “built on more than 11,000 exploitable vulnerabilities our Synack Red Team researchers validated across live customer environments,” and “showed that remote code execution findings rose 39 percent in 2025, brute force findings rose 17 percent, and content injection rose 8 percent. Those three categories share a purpose, moving an attacker past the perimeter and toward the systems that matter most.”

“Attackers have also picked up speed,” he continues. “The window between a vulnerability’s disclosure and its exploitation has fallen from months to hours, and in some cases, our researchers are seeing exploitation before a vulnerability is even publicly disclosed. AI-enabled adversaries can now automate reconnaissance and scanning continuously across thousands of assets at once, with no scope limitations.”

Meanwhile, much of the attack surface goes untested. Synack’s research alongside Omdia, Kuhr says, “found that the average enterprise only tests 32 percent of its exposed attack surface. The other 68 percent becomes a target, as attackers routinely find infrastructure that security teams never knew existed.”

The assumption trap

Overby believes many organizations are taking false comfort from the controls they have deployed. “One of the biggest mistakes organizations are making amidst the current threat climate is assuming that security controls are working just because they have been implemented,” she warns. “In an environment shaped by AI-driven threats, cloud services, third-party dependencies, and hybrid infrastructure, security measures can quickly become outdated, and organizations simply cannot afford to stay still.”

Dimmick sees the same pattern at the network level. “The challenge is that organizations often assume the controls they have put in place are still working as intended. Networks change constantly. Devices are added, firewall rules are updated, permissions change and configurations drift,” she says. “A policy that was correct six months ago does not tell you whether your network is secure today.”

Andrew Costis, Engineering Manager of the Adversary Research Team at AttackIQ, is blunter still. “A security control that has never been tested against the behavior it’s supposed to stop is still an assumption,” he says. “Cybersecurity Awareness Month should encourage organizations to challenge more of those assumptions.”

He offers a set of questions every security team should be able to answer. “Would an endpoint control catch the lateral movement technique your threat model says you’re worried about? Would an identity control interrupt privilege escalation? If one defense failed, would another detect or stop the attack before sensitive data was reached? These questions can, and should, be tested before an incident.”

From compliance to continuous assurance

Regulation is pushing in the right direction, Overby says, but cannot do the job alone. “In line with this rising threat landscape, regulations such as the Cyber Resilience Act (CRA) are now increasingly demanding secure-by-design development, vulnerability management, incident reporting, software supply chain transparency and operational resilience,” she says. “While this is a positive first step, regulation simply cannot keep pace with every change in the threat landscape, meaning that businesses must look beyond check-box compliance and prioritize continuous assurance and predictive defense measures.”

“This means a transition from asking ‘Do we have security controls?’ to ‘Can we prove they are working today?’” Overby adds. “Ultimately, the organizations best placed to manage this new era of risk will be those that make continuous assurance a core part of how they operate, not just a periodic exercise.”

Costis points to continuous threat exposure management (CTEM) and validation as the way to turn that ambition into evidence. “CTEM gives organizations a continuous way to identify and prioritize exposure. Adversarial exposure validation adds evidence by testing defenses against real-world attacker tactics and techniques,” he says. “The result goes beyond a theoretical risk score. Teams can see where tested protections work, where they fail and whether remediation closed the gap.”

Kuhr agrees that cadence is now the deciding factor. “Cybersecurity Awareness Month should be a reminder that speed now favors whoever tests continuously, not whoever tests hardest once a year,” he says. “Pairing AI that can watch an attack surface around the clock with researchers who can apply human judgment is how security teams will close that distance before attackers do.”

Fewer places to go

For Dimmick, making life harder for attackers comes down to disciplined basics, checked regularly. “Making life harder for attackers means reducing the opportunities available to them. Harden your infrastructure. Segment your network. Remove access that isn’t needed. Apply least privilege, and, importantly, regularly validate that those controls are actually being enforced.”

“Good cybersecurity isn’t just about responding quickly when something goes wrong. It’s about making sure attackers have fewer places to go in the first place,” she concludes. “Verify it. Don’t assume it.”

Costis sums up the distinction: “Awareness helps you understand what attackers might do. Validation shows how your defenses respond when those behaviors are tested.”

ShareTweet
Previous Post

ASOS app turned into ransom note as hackers claim Snowflake breach

Recent News

Verify it, don’t assume it: why untested security controls are making life easy for attackers

Verify it, don’t assume it: why untested security controls are making life easy for attackers

October 7, 2026
ASOS app turned into ransom note as hackers claim Snowflake breach

ASOS app turned into ransom note as hackers claim Snowflake breach

October 7, 2026
Tenant isolation becomes a buying criterion as FusionAuth opens UK office

Tenant isolation becomes a buying criterion as FusionAuth opens UK office

October 6, 2026
AI Autonomy

UK public sets limits on AI autonomy as security concerns persist

October 6, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol