Skip to content
Silicon Shecky

Silicon Shecky

Infosec Practitioner

  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

A role for every tool

Posted on September 20, 2018 By Michael Kavka No Comments on A role for every tool

Recently, I heard some discussion about how our field comes up with new tools to help augment the workforce. They attempt to make life easier for us by automating menial tasks, or bringing things under one easy shell (pun intended). I also have come to understand that part of the reason for this is that more and more information security professionals are not coming from a solid IT background. What I mean is that they do not understand the basics, how networking works, how firewalls work, etc… Now to be fair there are plenty of people in our field that did not work in that IT field who are fantastic, and know the basics, but they took the time to learn them at least.

The problem I (and hopefully many of you) are seeing is the plethora of solutions out there. Multiple solutions for everything. More specialized solutions for different areas. The higher ups expect us to each be more and more proficient in multiple tools, multiple disciplines. Each of these tools is supposed to not only make a difference, but make our lives easier. EDR solutions, Web Proxies, WAF, SIEM, and many more tools out there. The thing is that each is not doing one aspect, making our lives easier.

I am not going to say that each tool does not have its merits, because they do. Thing is that each tool requires a lot of time and effort to get it tuned, and many of them are never completely tuned and require frequent, if not constant, hand holding to keep them up to date. Imagine that your vehicle required you to change filters, change fluids, and do other maintenance on a daily basis. One day it is one thing, the next day it is something else. How would we ever stop spending money on it all, let alone be able to get anywhere on time? Now think of how much time defenders spend looking at SIEM or EDR, maybe having to maintain the Content Filter due to new sites that are needed to be accessed? How much time does that take? Now add on that you have a small team, and how much time are you taking away from noticing something is actually wrong?

A lot of what tools do can be done manually, for sure, but the idea of having a tool to do it is to cut down on the effort. So we spend thousands of dollars on a tool, only to realize we either need to hire a new person to own that tool, or hire a third party to take care of the tool for us. Now how attentive will that third party be, when they are doing the same thing for multiple companies? How easily can something fall through the cracks? How many more cracks are being added?

Some of the solution comes from taking care of the basics, some from staffing, and some from understanding ones environment and where to focus the resources one has. It is not the sexy stuff of our field, but without it, we risk losing everything. Security is not achieved by throwing so many things at it that we are overwhelmed. It is achieved by doing the basics well and then augmenting for the vertical we are dealing with to cover the largest risk factors. We have to realize there is no perfect security no perfect solution. Our strive for perfection is getting out of hand. We need to come to terms with accepting what is best and better before we all burn out, because the speed of change will do that to us. Just when you think you have all the answers, someone changes the questions.

Rants, Security Tags:Burnout, InfoSec, Tools

Post navigation

Previous Post: Perfect Imperfection
Next Post: Quiet week

Related Posts

  • Security is Reactionary, No Matter What Security
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

More Related Articles

Security is Reactionary, No Matter What Security
Defender, KQL and Lockbit Microsoft
Do well, not be “popular” Ramblings
Defense Layers: A Case Study Microsoft
Device vs. User Microsoft
Ransomware, Are You Ready? General

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP
  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

RSS feed: iFin Intel Feed iFin Intel Feed

  • Malicious npm packages evade install-script defenses at runtime September 20, 2026 Bill Toulas
  • Researchers escape OpenAI Codex sandbox to run commands on host September 20, 2026 Ax Sharma
  • An undercover Google analyst infiltrated a notorious supply-chain hacking gang September 20, 2026 Andy Greenberg
  • GHAPPIER - One loader, sixty-five repositories, twenty-two accounts: an unreported loader family beside DPRK's PolinRider campaign September 20, 2026
  • Google’s Gemini is the latest AI model to hack other companies September 19, 2026 Anthony Ha
  • Gemini went rogue, hacked three companies, and Google hid it September 19, 2026 Terrence O’Brien
  • BragJack attacks hijack AI browser agents through malicious extensions September 19, 2026 Ax Sharma
  • Agentic security is the billion-dollar challenge for some clever startup to solve September 19, 2026
  • North Korean WaterPlum hackers infected 30,000 devices worldwide September 19, 2026 Bill Toulas
  • ShinyHunters hacks Clop leak site, threatens to extort ransomware gang September 19, 2026 Lawrence Abrams
  • Calling viral AI actress Tilly Norwood? Agree to a face scan first September 19, 2026 Ax Sharma
  • Viral AI actress' hotline face-scans every caller, watches their mood September 19, 2026 Ax Sharma

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP

RSS feed: iFin Intel Feed iFin Intel Feed

  • Malicious npm packages evade install-script defenses at runtime September 20, 2026 Bill Toulas
  • Researchers escape OpenAI Codex sandbox to run commands on host September 20, 2026 Ax Sharma
  • An undercover Google analyst infiltrated a notorious supply-chain hacking gang September 20, 2026 Andy Greenberg
  • GHAPPIER - One loader, sixty-five repositories, twenty-two accounts: an unreported loader family beside DPRK's PolinRider campaign September 20, 2026
  • Google’s Gemini is the latest AI model to hack other companies September 19, 2026 Anthony Ha
  • Gemini went rogue, hacked three companies, and Google hid it September 19, 2026 Terrence O’Brien
  • BragJack attacks hijack AI browser agents through malicious extensions September 19, 2026 Ax Sharma
  • Agentic security is the billion-dollar challenge for some clever startup to solve September 19, 2026
  • North Korean WaterPlum hackers infected 30,000 devices worldwide September 19, 2026 Bill Toulas
  • ShinyHunters hacks Clop leak site, threatens to extort ransomware gang September 19, 2026 Lawrence Abrams
  • Calling viral AI actress Tilly Norwood? Agree to a face scan first September 19, 2026 Ax Sharma
  • Viral AI actress' hotline face-scans every caller, watches their mood September 19, 2026 Ax Sharma
  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

Social Media

  • Bluesky
  • Mastodon
  • Twitter

Copyright © 2026 Silicon Shecky.