
Reactive vs Proactive Cyber Security
Stop managing the bad day. Make it less likely.
I spent a large part of my career thinking like an attacker. When you have sat on the offensive side of cyber, you stop seeing security as a wall to climb over and start seeing it as a set of odds. Some targets are worth the effort. Most are not. That single shift in perspective is, I think, the most useful thing I can pass on to anyone trying to protect an organisation.
Let me put it in the plainest terms I can:

Risk is the product of the threat, the probability of that threat landing, and the impact if it does. Get your head round that one line and the whole subject starts to make sense. This is true for all risks, and certainly cyber risk.
The one factor you don't control
Threat is a tough one to manage. That's because the adversary owns the threat. They decide how they attack, what they want, how patient they are and how much they are willing to spend to get in. You do not get a vote.
But that doesn't mean we should ignore the threat. While we can't control threat, we absolutely can understand it, characterise it, and use it to inform the rest of the risk equation. That work matters, and we put real effort into it. But understanding the threat is not the same as reducing it. You can know a storm is coming and still get soaked.
We can't control threat, so that means if we want to have any chance of managing the cyber risk we are facing, the only two levers we get to control are probability and impact.
This is a game of pulling the levers of probability and impact. They are the only two you actually hold.
Reactive cyber is impact management
Most of what people picture when they think of cyber security is reactive. The breach happens, the alarms go off, the incident team scrambles, and if things are bad enough, the lawyers get a phone call. All of that is impact management. You are working to make a bad day less bad.
Impact management is genuinely important. It is a vital component of cyber risk management, and I am not knocking it. But it is only ever half the picture. And I'd argue that it is the expensive half, because by the time you are managing impact, something has already gone wrong. You are always on the back foot, reacting to an incident.
It is also more subtle than people give it credit for.

You cannot contain what you cannot see. The organisations that come through an incident in good shape are rarely the ones with the biggest response team. They are the ones who spotted it early, understood what they were looking at, and acted without flapping. Detection and a cool head beat brute force every time.
But, speaking as a cyber security expert, I'd rather prevent an attack from happening than respond to one that has landed.
Probability is the lever most people ignore
Here is where I plant my flag.

Every successful attack runs through a chain of small openings. A weak identity here, an unpatched box there, a misconfiguration nobody owned, a person who clicked because the email looked legit. Probability management is the unglamorous work of closing those openings before anyone tries the handle. Strong identity. Tight configuration. Patching that actually happens. Knowing what assets you have and who can access and utilise them.
Most cyber security companies don't like doing probability management because it's harder than "detection and response". It involves rolling up sleeves and getting stuck in. It requires close, deeply collaborative working relationships with clients as well as any external suppliers or stakeholders. Getting it right means understanding and fitting into how change management happens in the organisations being served. That's hard stuff that most companies don't really want to take on.
But we love it.

A good security posture is not something you buy once and stand back to admire. It is a habit. It is the steady, slightly boring discipline of staying hard to attack, day after day, when nothing is on fire. Acute care is the crash team. Chronic care is the diet and the daily walk that mean you never have to meet them. I would rather my clients lived the second life.
And here is the quiet bonus. Every bit of probability work you do also shrinks your impact. A tightly run environment is one where, on the bad day, the attacker has fewer places to hide and you have fewer things to untangle. The two levers are not really separate. Pull the probability one hard enough and the impact one gets lighter on its own.
Where this leaves us
We can't control threat. But we can lower the probability, and we can limit the impact. Doing both is the best chance you have of managing cyber risk.
It is also, for what it is worth, how we have built our own services. MIDAS is largely probability work made routine: proactive configuration and hardening across Microsoft 365, the daily hygiene that keeps you a hard target, with detection and response sitting underneath it. ATLAS is the impact side done properly: pulling signals from across your environment, correlating what no single tool would catch on its own, and acting the moment a threat is confirmed. One lowers the odds. The other limits the damage when the odds do not go your way. We built them as a pair because that is how risk actually works.
If you'd like to see my colleague Dave and I speak about this for our Blog, check out this video:
Understand the threat. Expertly manage the probability and impact variables. And spend most of your energy on the quiet, chronic work that means the call to the crash team never has to come.






