< BACK

Prevention Isn’t Enough Anymore

MDR SIEM cyber insurance

By Jeff Aiken, Cyber Security Manager

Key Takeaways

  • Prevention still matters, and insurers, auditors, and business partners still require it. What’s changed is that resilience has become the outcome the business gets judged on.
  • The sharper question today is how quickly you can detect, contain, investigate, and recover, rather than whether you can stop every attack.
  • You can’t confidently recover from an incident you don’t understand. MDR and SIEM supply the visibility and historical evidence that make good decisions possible during a crisis.
  • AI has raised both the speed and the volume of attacks, which makes “we’ll prevent everything” an unsafe assumption to build a program on.
  • Cyber insurers increasingly underwrite recovery capability: immutable backups, tested disaster recovery, a documented incident response plan, and 24/7 monitoring.
  • Recovery restores operations, though it can’t undo a data theft, which is why prevention and detection still carry real weight.

For years, cybersecurity conversations revolved around a single goal: prevent the breach. Buy a firewall. Deploy antivirus. Turn on multi-factor authentication. Patch systems. Train users. In other words, build higher walls.

Those investments still matter. Many of them are still required by cyber insurance carriers, auditors, customers, and business partners. But the conversation is shifting, because the threat landscape has shifted underneath it.

The old question was simple: how do we stop every attack?

The better question today: how quickly can we detect, contain, investigate, and recover when one succeeds?

That shift is a sign of maturity. Cybersecurity has grown into a business resilience conversation rather than a purely technical one.

You Can’t Investigate What You Never Recorded

Think about how an accident investigation goes when there’s a flight recorder on board, compared to when there isn’t. With the data, investigators reconstruct the sequence precisely, identify the cause, and tell everyone with confidence what has to change. Without it, they’re assembling fragments and living with uncertainty for years.

The COVID-19 Lesson Nobody Wants to Repeat

One of the most frustrating aspects of the COVID-19 pandemic was not only the disruption it caused, but the uncertainty surrounding its earliest moments. Years on, many people still debate exactly how the outbreak began. Why? Because there was limited visibility into the beginning of the event. Countless resources have been spent trying to reconstruct what happened after the fact.

Cybersecurity incidents can create the same kind of frustration inside a business. Imagine discovering that a threat actor may have been inside your network for weeks or months. Systems are down. Data may have been accessed. Employees cannot work. Customers are asking questions. Leadership wants answers. Attorneys, insurers, and regulators may all need details.

Now imagine trying to answer those questions without Managed Detection and Response (MDR), without a Security Information and Event Management (SIEM) platform, and without reliable historical logs.

  • How did the attacker get in?
  • When did the activity begin?
  • Which accounts were used?
  • Which systems were touched?
  • Was data accessed or exfiltrated?
  • Has the threat been fully removed?

Without visibility, the organization isn’t investigating with evidence, which recalls our collective frustration with COVID’s origins.

That’s where recovery gets much harder. You can’t confidently recover from an incident you don’t understand. MDR and SIEM do more than detect threats. They supply the context that makes good decisions possible during and after an incident.

It’s worth being precise about what recovery means here. Restoring a server from backup is one step in it. True recovery means knowing what happened, what was affected, whether the attacker is gone, and what has to change before operations resume.

AI Has Changed the Assumption

Artificial intelligence is accelerating cybercrime. Attackers can move faster, write cleaner phishing messages, automate research, generate convincing social engineering content, analyze stolen information, and scale attacks against more organizations at once.

The effect shows up in the data. In its 2026 Data Breach Investigations Report, Verizon found that exploiting unpatched vulnerabilities has overtaken stolen credentials as the most common way attackers gain initial access. It’s the first time in the report’s 19-year history that credentials have been knocked off the top spot. Verizon attributes part of that shift to attackers’ use of AI, which has compressed the window between a vulnerability becoming public and being exploited from months down to hours.

That speed changes the assumption businesses have to make. For years, many organizations believed that with enough preventive technology, they could push the odds of a successful breach close to zero. That assumption no longer holds.

AI doesn’t make every attacker sophisticated, but it does make many attackers faster and more efficient. It lowers the effort required to build a convincing attack and raises the volume of attempts an organization has to absorb.

In that environment, prevention remains necessary and can’t carry the whole load. Even mature organizations get caught by identity compromise, third-party exposure, software vulnerabilities, cloud misconfigurations, and social engineering.

The organizations best positioned for the AI era are the ones that can detect quickly, respond intelligently, and recover without panic.

Why Insurance Carriers Are Talking More About Recovery

Cyber insurance carriers still care about prevention. Multi-factor authentication, endpoint protection, vulnerability management, email security, and security awareness training remain important. Most carriers still require those controls before issuing coverage or offering favorable terms.

But carriers have learned something from claims history: organizations with nearly identical preventive controls can end up with wildly different financial outcomes. For example, one goes offline for weeks, struggles to determine what happened, negotiates under pressure, and absorbs major business interruption. The other contains the incident quickly, restores from tested backups, works from a documented response plan, and brings critical operations back in a controlled sequence.

From an underwriting perspective, those are two very different risks.

Which is why underwriting conversations have quietly become technical audits, increasingly built around resilience-oriented questions such as:

  • Do you have immutable or otherwise protected backups?
  • Have you tested disaster recovery?
  • Do you have a documented incident response plan?
  • Do you run tabletop exercises?
  • Can you produce logs and evidence during an investigation?
  • Do you have MDR or another form of 24/7 monitoring?
  • How quickly can you restore critical business functions?

The message from carriers keeps getting clearer. Cybersecurity is measured by how much it reduces the likelihood of an event and(!) by how much it reduces the severity when one happens.

Recovery Has Become a Business Strategy

This is the heart of the prevention-versus-recovery conversation, and the framing itself deserves a correction. Prevention and recovery aren’t competing line items. They’re two halves of the same program.

Preventive controls reduce the number of successful attacks. Recovery controls reduce the impact of the attacks that get through. A mature program needs both.

So organizations should keep investing in MFA, EDR, patching, secure configuration, awareness training, and vulnerability management. They should also invest in the capabilities that create confidence during a crisis:

  • MDR for continuous monitoring and expert response
  • SIEM to centralize logs and support investigation
  • Backup and disaster recovery testing to validate that restores actually work
  • Incident response planning to define roles before the pressure hits
  • Tabletop exercises to expose gaps before a real event does
  • Business continuity planning to protect operations, revenue, and reputation

There’s evidence this works. Verizon’s latest breach research found that most ransomware victims now decline to pay, and the median ransom has been falling, with stronger recovery capability among the reasons. When an organization can restore on its own, the attacker loses their leverage. On the mechanics, CISA’s #StopRansomware guidance is refreshingly concrete: keep backups offline, encrypted, and immutable, and test the restore on a regular schedule.

One Limit Worth Naming

Resilience deserves an honest caveat. A clean restore brings your systems back, and it does nothing to recall data that already left the building. Most ransomware crews now steal information before they encrypt anything, then threaten to publish it. That’s exactly why detection and prevention still carry real weight alongside recovery. Getting operations running again is the goal on the availability side. Keeping sensitive data from walking out the door in the first place is a separate job, and both belong in the same program.

The New Cybersecurity Equation

The future of cybersecurity comes down to being open-eyed about risk.

No organization can guarantee that every attack will be prevented. The speed of AI, the complexity of modern technology, and the reality of human behavior make that impossible. What organizations can do, however, is prepare to spot threats sooner, limit damage faster, and recover with far less uncertainty.

Because in today’s environment, resilience is not a backup plan. Resilience is the plan.

Scroll to Top