Skip to content
Silicon Shecky

Silicon Shecky

Infosec Practitioner

  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General
  • Gatekeeping and Treatment of Others Rants

Security is Reactionary, No Matter What

Posted on August 20, 2026 By Michael Kavka No Comments on Security is Reactionary, No Matter What

Originally cyber security was just an afterthought. Something to be added on later to networks, protocols, software, and hardware. No matter what happens, security is always secondary. It creates limits, slows down both deployment and development, and yet it is so critical. Yes, there is a call to be proactive, but the reality is that will likely never be possible.

Don’t get me wrong, we have gotten better. SDLC, secure initiatives, micro segmentation and more have brought us a long way. Security is thought about in many instances, but it is still all reactionary. You design, develop and deploy in a more secure manor, but that was a reaction, due to past issues. Patches still happen, flaws still found, and cost(hardware, software or personnel) prohibits better security. We do what we can.

Then there is the realization that security is a journey not a destination, which is not what the executives and board want to hear. The journey costs more, and there is no way to truly stay a step ahead. It is all mitigation of some sort, and everything can be gotten around. There is no magic button. Attackers have the advantage, not because you have to secure everything, but because they have no rules. The world of AI is starting to realize this. In fact, if some countries regulate AI, it doesn’t mean it is any safer, as countries that don’t have those regulations will have no rules. Just look at what Hugging Face had to use when thy had gotten breached by an AI.

All security is a best effort. Figure out where you are weak and strengthen it or find a way to mitigate it. We get tested and repeat. All reactionary to the idea that we might get breached. Even if back when the internet was created, when the protocols written, if security was “baked in” we still wouldn’t be secure, because there is always a way around. It is a matter of time and patience.

So, when your executives want to be more proactive about security, nod and say sure. Do what you can, but understand it is all a reaction, and in this case a reaction to the executive’s desire to not wind up having to talk about a breach. You can always be more secure, and fight the good fight, and win battles, and wars, but in the end, it is all reactionary.

Does it mean that it is not worth it? Of course not. In fact, ask any law enforcement officer if they think stopping criminals is not worth it. It is the same thing. We have been trying to be secure since the dawn of time. The digital world is no different. So are you in, or out?

Security Tags:AI, Blue Team, Red team, Security

Post navigation

Previous Post: New Year, New Post, from the start

Related Posts

  • Defender, KQL and Lockbit Microsoft
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General
  • Are you sure it is the execs? Ramblings
  • The one about banking passwords… Rants

More Related Articles

Defender, KQL and Lockbit Microsoft
Defense Layers: A Case Study Microsoft
Device vs. User Microsoft
Ransomware, Are You Ready? General
Are you sure it is the execs? Ramblings
The one about banking passwords… Rants

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP
  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

RSS feed: iFin Intel Feed iFin Intel Feed

  • CenterPoint Energy confirms customer data stolen in cyberattack September 15, 2026 Bill Toulas
  • Iranian cyber spies used fake MRI scan results to hack ‘enemy of regime’ September 15, 2026
  • Cisco email security boxes can be rooted by... an email September 15, 2026
  • Cisco warns customers of actively exploited zero-day in email gateways September 15, 2026 Matt Kapko
  • AI is now leading driver of new cybersecurity spending September 15, 2026 David Jones
  • MacOS 27 - First Boot, (Tue, Sep 15th) September 15, 2026
  • Zelensky appoints former police chief to lead Ukraine’s cyber coordination center September 15, 2026
  • Who's governing your AI? A trust framework for enterprise agents and models September 15, 2026
  • BambooToken malware controls Windows and Linux systems via MQTT September 15, 2026 Bill Toulas
  • Companies’ AI strategies don’t account for their agentic tools September 15, 2026 Eric Geller
  • Hackers target WordPress sites via third-party WooCommerce plugin September 15, 2026 Bill Toulas
  • There’s a 100% Chance AI Agents Are Already Ruining the Internet September 15, 2026 Jason Koebler

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP

RSS feed: iFin Intel Feed iFin Intel Feed

  • CenterPoint Energy confirms customer data stolen in cyberattack September 15, 2026 Bill Toulas
  • Iranian cyber spies used fake MRI scan results to hack ‘enemy of regime’ September 15, 2026
  • Cisco email security boxes can be rooted by... an email September 15, 2026
  • Cisco warns customers of actively exploited zero-day in email gateways September 15, 2026 Matt Kapko
  • AI is now leading driver of new cybersecurity spending September 15, 2026 David Jones
  • MacOS 27 - First Boot, (Tue, Sep 15th) September 15, 2026
  • Zelensky appoints former police chief to lead Ukraine’s cyber coordination center September 15, 2026
  • Who's governing your AI? A trust framework for enterprise agents and models September 15, 2026
  • BambooToken malware controls Windows and Linux systems via MQTT September 15, 2026 Bill Toulas
  • Companies’ AI strategies don’t account for their agentic tools September 15, 2026 Eric Geller
  • Hackers target WordPress sites via third-party WooCommerce plugin September 15, 2026 Bill Toulas
  • There’s a 100% Chance AI Agents Are Already Ruining the Internet September 15, 2026 Jason Koebler
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General
  • Gatekeeping and Treatment of Others Rants

Social Media

  • Bluesky
  • Mastodon
  • Twitter

Copyright © 2026 Silicon Shecky.