Perhaps one of the largest balancing acts is effectively managing risk and maintaining a reasonable security posture.

This makes your role as a trusted advisor crucial: you need to help your clients adequately balance proactive and reactive cybersecurity controls, all while building a strong cyber resilience strategy.

To help you easily navigate these conversations, we created a guide explaining the value of proactive and reactive controls and how they work together to produce the most consistent security posture.

Though proactive and reactive security controls for an organization are equally important, they may not actually bear equal weight.

For clarity, consider the potential costs and effectiveness of proactive controls such as the implementation of MFA, deployment of an Endpoint Detection and Response (EDR) platform, or the use of Conditional Access policies to further enforce company device controls.

While examining these, we should not lose focus on the reactive elements, including cybersecurity insuranceManaged Security Services Provider (MSSP) alignment, or an Incident Response (IR) firm retainer as well.

The reality: each of these elements has a specific place along the continuum—no single one is the most important.

“An ounce of prevention is worth a pound of cure,” but what if you don’t invest in that ounce?

Organizations may lean heavily on reactive controls (cyber insurance, IR Firm, MSSP) for a variety of reasons, but cost and convenience tend to lead that pack.

Consider what happens when an organization focuses on having cybersecurity insurance as their only safety net:

Your client is a smaller organization with a single accounts payable person.

One day, an email arrives from a known vendor stating that there’s a change to their ACH information for payment remittance.

The request seems legitimate, it’s from the correct point of contact, the change is made, and like usual that vendor’s invoices get paid.

Except they don’t.

The “trusted contact” at the known vendor experienced a Business Email Compromise (BEC) and the attacker was the one talking to AP about changing the payment destination.

All of that money is now gone and in the mysterious third party’s bank account.

If this is not discovered right away, it may be too late to stop the payment.

But this organization has a cybersecurity insurance policy—they should be protected, right?

Unfortunately, if “Funds Transfer Fraud” was not explicitly selected as part of the insurance, the event will not be covered.

While this may have been a cost-saving move for the company or the result of inadequate validation controls, this organization is now left still owing a vendor and losing the money paid to the attacker.

If the pendulum swings too far in the other direction and your clients focus solely on proactive cybersecurity investments, it may lead to similar situations where they don’t have the right level of protection or support that they need.

In most cases, security controls are the counterbalance to user conveniences.

The path of least resistance is often the one chosen, as enforcing too many controls on a user base can have the opposite effect to what was intended.

In an effort to gain back some of that convenience, users may find ingenious ways to work around the control, thereby invalidating the strength it added to the overall security posture.

A medium-sized business has just shifted from on-premises infrastructure to being 100% cloud-based using Software as a Service (SaaS) solutions for file storage, collaboration, accounting, ERP, etc.

The organization implements Conditional Access policies within their collaboration platform to enforce MFA for all accounts. This setup provides a strong unified control environment to protect against opportunistic attackers.

Shortly after deployment, however, it is determined that there is a critical business process that relies on a shared account. The implementation of these controls has made process execution challenging.

To the end users, the security controls make their jobs more difficult to accomplish. They lobby to have an exception for the MFA control, ultimately winning the battle.

Unfortunately, now a single account represents the break in the armor: a shared generic account used for a mission-critical business function that also needs a password that can be easily remembered by all relevant teams.

The result? The account’s password is “sprayed” successfully by an attacker and taken over due to the lack of MFA.

Ultimately, your clients’ security posture decisions need to keep the organization balanced.

Too much in any one direction can offset that balance and lead to financial impact, productivity impact, reputational impact, or, in a worst-case scenario, lead to a business closure.

The question is not “proactive or reactive”— it’s a balance of the two, considering the implications that each has on the organization’s ability to function. Achieving this goal is the core of effective cyber risk management.

Before selecting proactive controls, your clients must understand the actual threats to their organization.

This knowledge is often formed by engaging in a risk assessment and establishing a risk register so that a very clear and objective method identifies the threats, underscores the existing controls, and weighs that threat’s ability to impact the organization.

Only then can practical controls be considered, as the organization can more clearly see where its defenses are weak and where threats are originating from.

Each of the above elements carries with it a cost component. As such, that has to be weighed out to make sure that the continuum of security posture is balanced.

Just as each control has a cost component to implement, lack of these controls has a cost component as well whether in terms of the reactive control (cyber insurance, IR Firm, MSSP) or direct cost due to a compromise.

This phrase is often said by an organization to convince themselves NOT to invest in proactive controls.

The reality is that if an organization has money, makes money, or deals with monetary transactions from its customers, it can be and often IS a target.

An account manager with a weak/sprayable password has their account compromised; an unauthorized person now has direct access to this person’s entire mailbox and any other services tied to that collaboration platform.

The attacker sets up some mailbox rules to conceal their actions and may set up forwarding to an external account so that they can keep tabs without having to keep checking that person’s email.

After monitoring the mailbox, the attacker selects a recipient who receives mail often enough to suggest a “good relationship,” yet rarely enough that a slight change in tone wouldn’t be noticed.

The attacker emails that AP person at the other organization with updated instructions on how to remit payment due to a change in the bank account.

The changes are made, the money is sent, and the attacker walks away with a payday, leaving quite a wake in the process with both entities.

In keeping with the theme of balance, reactive and response controls are as necessary as proactive controls in maintaining a strong security posture.

A risk assessment should help to identify areas in which the controls are deficient. This evaluation includes not only preventative controls designed to reduce the likelihood of an incident, but also the response actions necessary to manage one.

Similarly to proactive controls, the reactive ones have their own cost as well. This is also often a case of “you get what you pay for,” though the most expensive may not always be the best.

An organization has just experienced a security incident.

A compromised VPN account allowed an attacker to traverse the network laterally and identify high-value targets, which are then targeted with a ransomware attack.

In the wake of the incident, the organization needs to evaluate where the controls had shortcomings.

The incident made the organization aware that their lack of any/enough security-knowledgeable employees may have been a contributing factor.

How does an organization decide on the course of action to take?

Hiring or training staff to become security experts is neither cheap nor easy, and often leaves organizations with “all their eggs in a single basket” when one person has that job role.

Consider this: Arctic Wolf found that the cost of building a fully staffed, 24/7 Security Operations Center (SOC) could average more than $1 million annually.

Alternatively, an MSSP or an IR firm may present a more cost-attractive solution for what can be provided.

When factoring in the costs associated with in-house staff members, after salary, benefits, and intangible costs are included, an MSSP is usually a more appropriate direction to take—especially for SMBs.

MSSPs will have teams of staff members with built-in redundancies so that there are multiple eyes on the control environment and/or multiple responders to an incident.

The organization must weigh the lower cost of an employee with the benefit of having an entity to turn to with the expertise at their fingertips and the capability to respond quickly when an incident occurs.

Now, your clients have an important decision to make: what do they invest in for the best cybersecurity ROI?

This is not a dissimilar question even outside of the context of security. This is also not a decision that should be made purely by dollars and cents, but instead with proper consultation.

A trusted insurance agent can help to steer your clients in the right direction as far as coverage is concerned for cybersecurity insurance. As a fractional CFO, understanding this direction can help you build a clearer picture of overall risk.

Don’t guess, ask the expert. See if they can cut through the lingo and go straight to some examples of “when a situation like this occurs, what coverage is provided?”

A trusted subject matter expert or cybersecurity company can provide guidance on specific technologies or technological controls.

You are going to an SME because you aren’t one, so don’t hold back a question because you believe you should already know. A good SME will take the time to explain.

While discussing, don’t hesitate to bring up scenarios so that you can better see and understand how the control defends the organization from the threat.

Oftentimes, you can leverage a trusted SME to aid in the risk assessment process and help identify the threats that need defense based on the organization’s controls.

Avoid buzzwords—there are many of them. There are often claims of “conceptual controls” that have no actual bearing on the reality of the security posture. They can present a checkbox or a false sense of good posture.

Always examine all of the options, because there are no one-size-fits-all security solutions or controls. What works for a large enterprise may fail miserably in a small-to-medium sized business.

You can implement enough controls to control an organization out of business, or to trigger a mutiny from the staff.

Your clients should choose the appropriate proactive and reactive controls to create a reasonable cyber resilience strategy that shields them from attacks while providing meaningful coverage in the event of an incident.

Choosing only proactive controls or only reactive controls could open them up to a host of risks.

Remember: security posture is all about balance.

Scroll to Top