Skip to content
Silicon Shecky

Silicon Shecky

Infosec Practitioner

  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General
  • Gatekeeping and Treatment of Others Rants

Security is Reactionary, No Matter What

Posted on August 20, 2026 By Michael Kavka No Comments on Security is Reactionary, No Matter What

Originally cyber security was just an afterthought. Something to be added on later to networks, protocols, software, and hardware. No matter what happens, security is always secondary. It creates limits, slows down both deployment and development, and yet it is so critical. Yes, there is a call to be proactive, but the reality is that will likely never be possible.

Don’t get me wrong, we have gotten better. SDLC, secure initiatives, micro segmentation and more have brought us a long way. Security is thought about in many instances, but it is still all reactionary. You design, develop and deploy in a more secure manor, but that was a reaction, due to past issues. Patches still happen, flaws still found, and cost(hardware, software or personnel) prohibits better security. We do what we can.

Then there is the realization that security is a journey not a destination, which is not what the executives and board want to hear. The journey costs more, and there is no way to truly stay a step ahead. It is all mitigation of some sort, and everything can be gotten around. There is no magic button. Attackers have the advantage, not because you have to secure everything, but because they have no rules. The world of AI is starting to realize this. In fact, if some countries regulate AI, it doesn’t mean it is any safer, as countries that don’t have those regulations will have no rules. Just look at what Hugging Face had to use when thy had gotten breached by an AI.

All security is a best effort. Figure out where you are weak and strengthen it or find a way to mitigate it. We get tested and repeat. All reactionary to the idea that we might get breached. Even if back when the internet was created, when the protocols written, if security was “baked in” we still wouldn’t be secure, because there is always a way around. It is a matter of time and patience.

So, when your executives want to be more proactive about security, nod and say sure. Do what you can, but understand it is all a reaction, and in this case a reaction to the executive’s desire to not wind up having to talk about a breach. You can always be more secure, and fight the good fight, and win battles, and wars, but in the end, it is all reactionary.

Does it mean that it is not worth it? Of course not. In fact, ask any law enforcement officer if they think stopping criminals is not worth it. It is the same thing. We have been trying to be secure since the dawn of time. The digital world is no different. So are you in, or out?

Security Tags:AI, Blue Team, Red team, Security

Post navigation

Previous Post: New Year, New Post, from the start

Related Posts

  • Defender, KQL and Lockbit Microsoft
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General
  • Are you sure it is the execs? Ramblings
  • The one about banking passwords… Rants

More Related Articles

Defender, KQL and Lockbit Microsoft
Defense Layers: A Case Study Microsoft
Device vs. User Microsoft
Ransomware, Are You Ready? General
Are you sure it is the execs? Ramblings
The one about banking passwords… Rants

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP
  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

RSS feed: iFin Intel Feed iFin Intel Feed

  • OpenAI will show visual ads in ChatGPT while you generate images October 5, 2026 Mayank Parmar
  • The US needs a real plan to defend its water systems October 5, 2026 Greg Otto
  • Microsoft: Windows KB5124010 update crashes some games and apps October 5, 2026 Sergiu Gatlan
  • Google halts open-source bug bounty program amid AI spam surge October 5, 2026 Sergiu Gatlan
  • ISC Stormcast For Monday, October 5th, 2026 https://isc.sans.edu/podcastdetail/10122, (Mon, Oct 5th) October 5, 2026
  • TTY Logs and the Data it Captures, (Sun, Oct 4th) October 5, 2026
  • Citrix patches NetScaler SAML zero-day exploited in attacks October 4, 2026 Lawrence Abrams
  • Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions October 4, 2026 Anthony Ha
  • Anthropic asks Claude users to share voice data for AI model training October 4, 2026 Mayank Parmar
  • User Agent Strings Curiosities, (Sun, Oct 4th) October 4, 2026
  • The boring state of stalled timelines… October 3, 2026 adam
  • Google Gemini could soon get full access to your Mac’s files, apps and the web October 3, 2026 Mayank Parmar

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP

RSS feed: iFin Intel Feed iFin Intel Feed

  • OpenAI will show visual ads in ChatGPT while you generate images October 5, 2026 Mayank Parmar
  • The US needs a real plan to defend its water systems October 5, 2026 Greg Otto
  • Microsoft: Windows KB5124010 update crashes some games and apps October 5, 2026 Sergiu Gatlan
  • Google halts open-source bug bounty program amid AI spam surge October 5, 2026 Sergiu Gatlan
  • ISC Stormcast For Monday, October 5th, 2026 https://isc.sans.edu/podcastdetail/10122, (Mon, Oct 5th) October 5, 2026
  • TTY Logs and the Data it Captures, (Sun, Oct 4th) October 5, 2026
  • Citrix patches NetScaler SAML zero-day exploited in attacks October 4, 2026 Lawrence Abrams
  • Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions October 4, 2026 Anthony Ha
  • Anthropic asks Claude users to share voice data for AI model training October 4, 2026 Mayank Parmar
  • User Agent Strings Curiosities, (Sun, Oct 4th) October 4, 2026
  • The boring state of stalled timelines… October 3, 2026 adam
  • Google Gemini could soon get full access to your Mac’s files, apps and the web October 3, 2026 Mayank Parmar
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General
  • Gatekeeping and Treatment of Others Rants

Social Media

  • Bluesky
  • Mastodon
  • Twitter

Copyright © 2026 Silicon Shecky.