Many security teams are prioritizing prevention over detection, with disastrous results

Cybercrime
(Image credit: Future)

When it comes to securing the premises, the majority of businesses are prioritizing prevention over detection, investigation, and response, a new report has found. However as a result, large numbers of firms are being hit by data breaches or other attacks, with the incidents constantly getting worse.

Researchers at Exabeam surveyed 500 IT security professionals, finding roughly two-thirds of the respondents (65%) prioritize prevention as their number one endpoint security goal.

For a third (33%) - detection was the highest priority. 

Too late to the party

To make matters even worse - the businesses are actually acting on this thinking. Almost three-quarters (71%) spend between 21% and 50% of their IT security budgets on prevention, while 59% invest the same amount as they do for detection, investigation, and response.

The trouble with this approach, according to Exabeam’s Chief Security Strategist, Steve Moore, is that the firms are focusing on prevention with crooks already inside the walls, rendering their efforts futile.

“As widely known, the real question is not if attackers are in the network, but how many there are, how long have they had access, and how far have they gone,” Moore says. “Teams need to socialize this question and treat it as an unwritten expectation to realign their investments and on which to perform, placing the necessary focus on adversary alignment and incident response. Prevention has failed.” 

When asked if they are sure they can prevent attacks, most respondents answered positively. In fact, 97% said they felt confident in their tools and processes, to prevent and identify intrusions and data breaches. 

However, when asked if they’d easily tell their boss their networks weren’t breached at the time, just 62% would say yes, meaning more than a third had their doubts. 

In other words, Exabeam says, security teams are overconfident and has data to back it up. Citing industry reports, the company claims 83% of organizations experienced more than one data breach last year.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A digital representation of a lock
Exploits on the rise: How defenders can combat sophisticated threat actors
Hack The Box crisis simulation event
“Everyone will experience a hack” - how incident response can protect your organization
Abstract image of cyber security in action.
It’s time to catch up with cyber attackers
security
The true cost of a security breach
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Sounding the alarm on AI-powered cybersecurity threats in 2025
Cartoon Phishing
Hackers use GenAI to attack more frequently and effectively
Latest in Security
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Web DDoS attacks see major surge as AI allows more powerful attacks
Polish space agency says it was hit by a cyberattack
Illustration of a hooked email hovering over a mobile phone
AWS misconfigurations reportedly used to launch phishing attacks
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
A pair of hands using a keyboard
Microsoft SharePoint hijacked to spread Havoc malware
Latest in News
Bang & Olufsen Beogram 4000C Saint Laurent Rive Droite Edition
Bang & Olufsen's latest reworked turntable is a masterpiece of retro revival, in a breathtaking wooden presentation box
Apple Watch Series 10
Apple unveils new Apple Watch bands – here's what's in the Spring 2025 collection
iPad Air M3
Apple makes one hardware change to the iPad Air that might be the best indicator of its true lightweight tablet intentions
An operator fires a saw blade from a weapon
Call of Duty: Black Ops 6 Season 3 gets two-week delay, will now release in April
Apple iPad A16
Apple's new entry-level iPad ups the performance for the same price, but doesn't support Apple Intelligence
iPad Air M3
Apple updates iPad Air with powerful M3 chip and pairs it with Pro-level Magic Keyboard