Rapid7: Why wait for an alert? It’s already too late

Why-wait-for-an-alert?-It's-already-too-late

ISJ hears exclusively from Thom Langford, CTO EMEA of Rapid7 about why security teams need to ditch detection and response.

For as long as I’ve been in security, the approach has always been to find bad things after they’ve entered the environment.

It was a familiar sequence of identifying exposures, monitoring for alerts, investigating suspicious activity, containing incidents and recovering after impact.

And it worked well for decades!

It helped organisations mature their security programmes and build essential detection and response capabilities.

However, as we all know, good things don’t last forever and the same is true of traditional detection and response capabilities.

Detection and response were great when infrastructure was more centralised and attack paths were easier to understand, but modern environments have outgrown that and are in a constant phase of flux.

It’s a bit like a horse and cart.

It was a brilliant mode of transport for centuries but, with combustion engines, it’s an outdated approach to getting around.

The same is happening with detection and response – we need to ditch the horse and start using the car.

The messy digital environment

When you look underneath an organisation’s bonnet, it’s usually a tangled mess.

There’s cloud infrastructure, SaaS applications, remote work environments, third-party ecosystems, human identities, machine identities and unmanaged or poorly understood assets.

All of this creates new connections that attackers can exploit.

Just to add to the challenge for security teams, every new tool and workflow is another that needs to be managed.

This complexity slows everything down, and analysts spend valuable time piecing together data from endpoints, cloud infrastructure, identities and applications.

By the time enough information has been gathered to investigate an alert properly, attackers may already have exploited a vulnerable asset, abused an identity, leveraged a cloud misconfiguration or moved laterally through the environment.

That leaves security teams in an uncomfortable position.

Either they wait for more evidence and risk giving attackers additional time, or they respond quickly with incomplete context under growing pressure from the business.

Neither is an attractive option.

More importantly, this creates a cycle of constant reactive activity without consistently reducing risk.

Teams become exceptionally good at responding to symptoms while still struggling to address the underlying conditions that attackers rely on, which means the organisation’s security is not improving.

We constantly hear that security teams are struggling with alert volume and don’t have time to focus on the risks most likely to create business impact.

Maybe it’s because the approach they’re using is creating the beast?

Attackers have figured out the holes

On top of the challenge of not understanding their environments, security teams are facing adversaries that are stronger and faster than ever before.

Initial access now happens earlier and more quietly. Identity abuse and cloud misconfigurations can accelerate attack paths, while third-party and supply chain risk can introduce exposure from outside the organisation’s direct control.

All these weaknesses can also be chained together by attackers, providing them with a straightforward path to data, systems or operational disruption.

Threat actors increasingly automate reconnaissance, identify exposed assets at scale, weaponise leaked credentials and exploit cloud configuration weaknesses within hours of exposure.

There is a vanishingly small window between exposure and exploitation.

You might have an exceptionally mature Security Operations Centre, world-class analysts and excellent incident response procedures, but with the tactics now used by attackers, the detection and response approach might already be too late.

It’s why security teams need a way to move earlier in the lifecycle, before exposures become incidents and before isolated signals turn into material impact.

Why preemptive security gets defenders back ahead

The goal of preemptive security is to identify likely breach paths, prioritise the exposures that matter most and move response earlier in the attack lifecycle.

Rather than waiting for alerts to indicate something has already gone wrong, organisations use exposure context, threat intelligence, business impact and clear prioritisation to identify the conditions that make successful attacks possible before attackers can exploit them.

This will shift security from reacting to incidents towards reducing the opportunities attackers have in the first place.

Think about airport security.

Success isn’t measured by how effectively crews respond to a threat once an aircraft is in the air.

Instead, enormous effort is invested before take-off, identifying risks, screening passengers and preventing dangerous conditions from ever reaching the aircraft.

Emergency procedures still exist, but they’re the final layer of defence, not the primary strategy.

Cybersecurity needs to adopt the same mindset.

Detection and response remain essential, but they work best when they’re supported by a proactive understanding of where attackers are most likely to succeed.

Exposure management becomes more actionable when connected to monitoring, investigation, validation and response. Together, these capabilities help teams focus their limited time and resources where they can have the greatest effect.

A recent campaign involving a backdoor delivered through a widely used application shows how this model works.

Threat intelligence identified attacker behaviour and tactics early, triggering proactive threat hunting across multiple environments.

Security teams identified impacted organisations and ran targeted scans before widespread damage occurred.

Detection capabilities were also updated and deployed broadly, ensuring all organisations benefited from the insight.

How preemptive security is implemented

To implement such a model, security teams need to begin by assessing their security posture and identifying exposed assets.

This will help map likely attack paths across an organisation’s different environments.

Fundamentally the purpose is to identify the risks that matter most, rather than creating a longer list of issues to fix.

With assets clearly mapped, data is then normalised, so signals are consistent, usable and ready for investigation.

Connected telemetry helps teams build context, spot anomalies earlier and understand when an exposure, behaviour, or signal deserves immediate attention.

This is also where AI becomes a useful tool by reducing noise and surfacing the activity most likely to matter. Analysts are then left to focus on validating findings, determining scope and guiding response.

Response actions may include isolating endpoints, securing accounts, updating detection, interrupting attacker activity or directing remediation teams towards exposures most likely to be used again.

Once the immediate issue is addressed, lessons learned feed back into the broader security programme so teams can strengthen controls, refine prioritisation, improve playbooks and reduce future risk.

The approach means leaders are able to see whether the organisation is closing the exposures most likely to be targeted and whether high-risk attack paths are being reduced over time, rather than investigating alert by alert.

A new definition for success

The industry celebrates detection and response metrics because they’re measurable.

However, attackers don’t care how quickly you detect them if they’ve already got what they came for.

The most effective security programmes are no longer those that respond fastest when an attack occurs, but those that reduce the opportunities for attackers to succeed before an incident ever begins.

Leaders must define success around outcomes rather than activity.

Reduced exposure before exploitation, faster containment, clearer accountability, improved visibility and stronger business confidence provide a more meaningful measure of security effectiveness.

Share this content

Latest Issue

Connect with us

Free digital subscription

Receive the latest breaking news straight to your inbox