Skip to main content
More Breach Detections Won't Save YouIncident Management
4 min readFor Risk Officers

More Breach Detections Won't Save You

The Conventional Wisdom

Security teams have spent years focusing on detection speed. The belief is that if you spot breaches faster, you'll reduce their impact. Conference keynotes echo this: shrink your mean time to detect (MTTD), deploy more monitoring tools, and hunt threats continuously. The Identity Theft Resource Center reports 1,803 data compromises in the first half of 2026 alone. The industry's response? Double down on detection capabilities.

Risk officers are advised to invest in SIEM platforms, endpoint detection and response tools, and user behavior analytics. The assumption is that better visibility equals better security. When insider wrongdoing breaches increased sevenfold since 2025, the immediate reaction was predictable: "We need better monitoring of our people."

Why Detection Alone Isn't Enough

Detection is a lagging indicator. It measures how quickly you notice a compromise, which is useful for incident response but doesn't address why breaches occur in the first place.

Consider the data: only 24% of breach notices in 2026 included attack vector details, the lowest rate ever recorded. This isn't just a transparency issue. It shows organizations don't understand how they're being compromised because they're focused on detecting breaches, not preventing them.

The rise in insider wrongdoing isn't just a monitoring gap. It's a design gap. If your controls rely on perfect detection, they're not controls. They're merely audit trails of failures.

Detection can tell you about a supply chain attack that exposes millions of victim notices, but it doesn't prevent the attack or reduce the victim count. It just tells you when to start apologizing.

The Evidence

Look at what ISO/IEC 27001:2022 Annex A prioritizes. Control 5.19 (information security in supplier relationships) and Control 5.15 (access control) focus on prevention before detection. Control 8.8 (management of technical vulnerabilities) requires systematic patching to prevent zero-day exploits.

The SOC 2 Trust Services Criteria follow the same logic. CC6.1 requires logical and physical access controls to prevent unauthorized access, not just detect it.

Publicly traded organizations represent 10.3% of breach events but 83.4% of victim notices. This isn't a detection problem. It's a failure to architect systems that limit damage. The Instructure breach, with approximately 275 million victim notices, wasn't a failure to detect. It was a failure to design systems that limit the blast radius.

AI-driven zero-day attacks compound this issue. You can't detect what you've never seen. A zero-day exploits an unknown vulnerability. Prevention through secure architecture, least privilege access, and network segmentation doesn't depend on whether the attack is novel.

What to Do Instead

Start with ISO/IEC 27001 Clause 6.1.3: risk treatment. Your risk treatment plan should prioritize controls that reduce likelihood and impact before investing in detection.

Implement Control 8.32 (change management) to prevent unauthorized modifications to systems. This addresses insider threats more effectively than monitoring by requiring approval and segregation of duties before changes occur.

Design for Control 8.9 (configuration management) with immutable infrastructure. If your baseline configurations can't be altered without rebuilding from source, you've eliminated entire classes of insider manipulation.

Apply Control 5.23 (information security for use of cloud services) by architecting multi-tenant isolation and data segmentation. When a breach occurs, it should affect thousands of records, not millions. The difference between the Instructure breach and a well-architected system isn't detection speed. It's containment by design.

For supply chain risks, implement Control 5.19 with contractual requirements for your suppliers' control environments. Require SOC 2 Type II reports or ISO/IEC 27001 certification. Verify their access management, change control, and vulnerability management before integrating their systems with yours. You can't detect your way out of a compromised supplier if they have direct access to your data.

Address the increase in insider wrongdoing with Control 6.4 (disciplinary process) and Control 5.7 (threat intelligence). More importantly, implement Control 8.2 (privileged access rights) to ensure no single insider can exfiltrate data without triggering controls that require secondary authorization.

When Detection Matters

Detection is crucial in three scenarios:

When prevention fails. Despite your controls, breaches will occur. ISO/IEC 27001 Control 5.24 (incident management planning) and Control 5.25 (assessment of security events) require detection capabilities. You need to know when you're compromised to contain and recover.

For compliance evidence. SOC 2 Type II examinations require evidence that your monitoring controls operated effectively throughout the audit period. You can't demonstrate that without detection logs and alert response records.

When managing residual risk. After implementing preventive controls, detection provides defense in depth. Control 8.16 (monitoring activities) gives you visibility into whether your preventive controls are being bypassed or failing.

But detection is the third layer, not the first. If you're spending more on detection tools than on access control architecture, you're optimizing the wrong part of the problem. The 3,600 projected breaches by year-end won't be stopped by better monitoring. They'll be reduced by better design.

You Might Also Like