Foundations first: why security rarely lives in the newest product
The best security programmes start with the basics that quietly leave the biggest gaps. We look at what actually moves the needle.
Most organisations we meet are not short of security tooling. They are short of confidence that the fundamentals are working every day, in every corner of the estate. New products are easy to buy and hard to operationalise; foundations are unglamorous and quietly decisive.
Where the real gaps sit
- Asset visibility. You cannot protect what nobody owns. An accurate, maintained inventory of systems, data stores and third-party services is the single most useful artefact in a security programme.
- Identity and access. Joiners, movers and leavers, privileged accounts, service accounts and stale tokens cause more incidents than novel attack techniques.
- Patch and configuration hygiene. Known vulnerabilities on internet-facing systems remain a common route in, long after a fix is available.
- Logging and detection coverage. Tools generate alerts; coverage mapped to the threats you actually face generates outcomes.
- Backup and recovery you have tested. An untested restore is a plan, not a capability.
A practical sequence
Start by agreeing what "good" means for your risk appetite, then measure the current state honestly against it. Fix the controls that reduce the most plausible loss first, and make each fix operational: an owner, a runbook, a metric and a review date. Only then consider whether new technology is needed — and buy it to close a named gap rather than to cover a category.
What this looks like in practice
A typical foundations engagement runs eight to twelve weeks: a rapid health check across identity, endpoint, cloud, data and third parties; a prioritised remediation plan costed against effort and risk reduction; and hands-on delivery of the first tranche so the momentum does not evaporate when the report lands.
The result is rarely a new logo on the architecture diagram. It is a smaller, better-run estate where the controls you already paid for do the job you bought them for.
Related reading
- Data classification that people actually use — how to get visibility of your sensitive data and attach controls to it.
- The interim CISO: when to hire one — senior ownership when foundations work needs a mandate.
- Cyber security recruitment in the UK — resourcing the people who will run these controls day to day.