Scott Alldridge is CEO of IP Services, a visionary leader, and author of the bestselling VisibleOps book and series.
Cybersecurity has an assumption problem. Most organizations today have firewalls, endpoint protection, multifactor authentication, backups, vulnerability scanners, security awareness training and incident response plans. On paper, that sounds pretty good. But over many years in cybersecurity and IT operations, I have learned that what exists on paper and what actually works under pressure can be two very different things.
I suggest asking a different set of questions. When was the last time you restored a critical system from backup? Can ransomware move from one compromised laptop to a production server? Are there privileged accounts with more access than they need? Would your team know exactly what to do if an attack began at 2 a.m. on a Sunday?
That is where I believe the real “tip of the spear” in cybersecurity exists. It is not the newest tool, another dashboard or a compliance certificate. It is the small set of capabilities standing between an initial compromise and a major business event.
These capabilities are not necessarily the most visible parts of a security program, but they are the ones that determine whether your defenses hold when something goes wrong. I recommend focusing on eight areas:
1. Know what you have.
One of the oldest lessons in IT operations remains one of the most important in cybersecurity: you cannot protect what you cannot see. Organizations need visibility into systems, applications, cloud resources, data, users, privileged accounts, service accounts and, increasingly, AI agents. The objective is understanding your crown jewels and what can reach them.
I have been involved in assessments where the biggest surprise was discovering sensitive data or access paths leadership did not know existed. In one case, we found a significant amount of confidential data sitting in places the organization had not considered part of its primary risk profile. That immediately changed the security conversation.
2. Treat identity as a security perimeter.
Multifactor authentication is important, but MFA alone is not an identity strategy.
Modern organizations have employees, contractors, administrators, service accounts, applications and machine identities accessing sensitive systems every day. The operating principle should be simple: authenticate strongly, authorize narrowly, monitor continuously and revoke quickly. Dormant accounts, inherited permissions and excessive administrative rights can turn one compromised identity into much broader access.
3. Assume that someone will get in.
For decades, cybersecurity centered on keeping attackers out. Prevention remains essential, but the better question today is, if an attacker gets in, how far can they go?
That is why zero trust, segmentation and microsegmentation matter. Their real value is reducing the blast radius. Compromising one laptop should not provide a pathway across the entire business.
I have seen environments where everyone believed segmentation was in place because the firewalls, VLANs and policies looked correct. Once we tested actual communication paths, we found systems communicating in ways nobody intended. The documentation looked secure, but the environment told a different story.
4. Fix what attackers can actually use.
Vulnerability management often becomes a numbers game. An executive hears, “We have 4,000 vulnerabilities,” but that number by itself says very little.
The better question is, “Which vulnerabilities create realistic paths to critical systems and sensitive data?” Prioritization should consider exposure, exploitability, business impact and system relationships.
This is also where traditional IT discipline matters. Poor change management, configuration drift and unmanaged systems quietly undermine cybersecurity. Advanced security tools cannot indefinitely compensate for weak operational practices. Security maturity cannot sustainably exceed operational maturity.
5. Detect behavior, not just known attacks.
Attackers increasingly use legitimate tools and valid credentials, making behavioral detection more important. Instead of only asking whether malware was detected, ask whether a user’s behavior changed, a workload is communicating somewhere unusual, large amounts of data are moving unexpectedly or an AI agent is operating outside its intended scope.
AI can help, but it should amplify disciplined security operations, not replace them. A fool with an AI tool is still a fool. Good cybersecurity requires context, judgment and people who understand what “normal” looks like.
6. Prove that you can recover.
Backups make executives feel safe. Successful recovery should make them feel safe. Those are not the same thing. A backup that has never been restored is an unproven recovery strategy.
I have seen organizations with dashboards showing successful backup jobs every night, yet nobody could say when a critical business system had last been fully restored and tested. The objective is not proving that data was copied. It is proving that the organization can operate again.
Organizations should test protected or immutable backups, recovery sequencing, credentials, dependencies and recovery time objectives. At the board level, ask one question: When was the last time we proved we could restore the systems that generate revenue, deliver services or run this organization?
7. Test the humans, too.
Many organizations conduct phishing simulations, but fewer simulate the actual crisis. What happens when ransomware is discovered? Who has authority to isolate systems? Who contacts legal counsel? Who communicates with customers? Who calls the insurer? What happens if the CEO or CIO is unavailable?
Tabletop exercises expose these gaps before attackers do. Properly trained and supported, employees can become an important first line of defense.
8. Make governance about proof.
Boards and executives should not manage cybersecurity by admiring dashboards. They should ask better questions: What do we know? What have we tested? What failed? What changed? What are we doing about it?
I describe this as “Trust, but verify—always.”
Compliance matters, but compliance should be the floor, not the finish line. A compliant organization can still be breached. Excellent technology can still fail operationally. A well-written incident response plan can still collapse if nobody has exercised it.
The strongest organizations are not necessarily those with the most cybersecurity products. They know what matters, limit attacker movement, recognize abnormal behavior quickly, recover reliably and continually prove their defenses work.
That is what I consider the true tip of the spear. Cybersecurity cannot be built on hope, assumptions or dashboards alone. Monitor it, validate it, test it, improve it and then test it again.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?








