The Breach You Haven't Had Yet

"We haven't had any issues" isn't a security posture. It's a description of yesterday.

Survivorship isn't a security posture either. It's a coin flip you haven't lost yet.

Every company that has ever been breached spent some amount of time saying they hadn't been breached. Every house that has burned down spent some amount of time not burning down. Past performance isn't predictive in either direction. Saying "we haven't had any issues" is a description of yesterday. It tells you nothing about today, and even less about tomorrow.

The framing isn't wrong because the speaker is lying or careless. It's wrong because it substitutes absence of evidence for evidence of absence, and those aren't the same thing. The fact that you haven't detected a breach is consistent with two scenarios. One: you aren't being attacked. Two: you're being attacked but can't tell. The second scenario is way more common than SMB owners want to believe, because most SMBs don't have the monitoring capability to know when they're being probed, much less compromised.

The data is unflattering. According to cybersecurity insurance carriers and incident response firms, the average dwell time for an attacker inside a small business network before detection is between two and four months. That's the gap between getting in and getting caught. If you've been compromised today, your odds of finding out about it before next quarter aren't great. "We haven't had any issues" actually means "I'm not aware of any issues at this time." The two statements are different, and the second one is much less reassuring.

Stop using the absence of bad news as evidence of good practices. They aren't the same thing. They're barely related.

The survivorship argument breaks on compounding risk. Every year your business operates without serious security investment, the value of what you're protecting goes up, the sophistication of the attackers goes up, and the surface area you're protecting goes up. You added customers. You added employees. You added systems. You added vendors with access to your data. You added integrations. Each of these is a new entry point. Each is also a new asset worth attacking. The longer you operate without commensurate investment in security, the wider the gap between what you're protecting and what you have the capability to protect.

The gap closes one of two ways. Either you invest into closing it, or an attacker closes it for you.

Panic is the wrong response. The right response is to acknowledge that the absence of a breach isn't evidence of security, and to start measuring security the way a security professional would measure it. Not by what has happened. By what would happen if something tried.

Get a real picture of your attack surface. What systems are internet-facing. What credentials exist for those systems. What employees have access to what. What vendors have access to what. Most SMBs have never compiled this list. The exercise of compiling it is itself the start of a security program. Once you can see the surface, you can prioritize.

Find out if anyone is trying. The cost of monitoring has dropped dramatically over the last five years. EDR tools that used to cost enterprise money are within reach of SMBs. Managed detection services are within reach of SMBs. The point isn't to watch for breaches that have already happened. The point is to detect the attempts and respond before they become breaches. You can't do that if you have no visibility into your own environment.

And plan for the day it happens. Incident response, business continuity, communications, customer notification, legal obligations. Most SMBs have none of this written down. Then the day comes, and the next two weeks are improvised on adrenaline, in front of an audience of regulators, customers, and the press. The plan doesn't have to be perfect. It has to exist. The first 30 minutes of an incident are when the plan matters most.

Survivorship bias is a powerful drug. It tells you that things will keep being fine because they've been fine. It doesn't work for hurricanes. It doesn't work for car accidents. It doesn't work for cancer. It doesn't work for breaches either.

Plan for the breach you haven't had yet. The plan is the security posture.

Back to Blog