Cyber, InfoSec, Ops Risk – Defending in the Wrong Tense

Why most of it, in 2026, is technically a form of historical research.

This is the first of three essays about a problem hiding in plain sight at every board meeting where the words cyber risk, information security, or operational risk appear on the agenda just before lunch. They are usually discussed as separate items, by different people, using different vocabularies, on different slides. They are, in fact, the same problem wearing three name badges.

The problem is not that the threat has evolved. The problem is that defence, in most institutions, has not. It is still organized — in 2026 — around assumptions the adversary, the regulator, and reality itself quietly retired five years ago. We continue to inspect what was, while the world we are meant to be defending works in what is. This is written from the vantage point of financial services, because that is where I have spent most of my working life. But nothing in what follows is specific to banks, or to cyber. Substitute transaction with shipment, policyholder, patient record, or production order, and the shape of the problem is identical. Substitute cyber risk with data risk, third-party risk, conduct risk, or operational resilience, and the shape is still identical. The tense is wrong in every domain that has digitised faster than it has rethought what it is defending.

They are, in fact, the same problem wearing three name badges.

These essays are not for the security team, or the risk team, or the compliance team. They already know. They are for the people who govern those teams, fund them, and sign off on their budgets on the basis of a slide deck that says, in essence, everything is fine, please approve.

This is the first essay. It explains why everything is not fine.

The dashboard is green

Somewhere in your bank, right now, an account with every legitimate credential is doing something no real human would. The login was clean. The password was correct. The two-factor authentication completed in 1.4 seconds. The dashboard, somewhere in your security operations centre, is a tasteful shade of green. The account, meanwhile, is moving money in a pattern that statistically resembles three people simultaneously, none of them in the country where the account holder lives.

By the time anyone looks at the dispute, it will be Tuesday.

The same essay could be written about a logistics company whose supplier portal has been quietly issuing duplicate purchase orders for six weeks, an insurer whose claims pipeline has been processing thirty perfectly-formed but synthetic policyholders a day, or a hospital whose electronic record system has been accessed at 3:00am by a vendor account that was supposed to have been deprovisioned last quarter. Different industries. Different incident reports. Same essay. Same tense problem.

By the time anyone looks at the dispute, it will be Tuesday.

The story we tell ourselves about cybersecurity — and about information security, and about operational risk, because we still pretend these are different conversations — is that the adversary is becoming more sophisticated. This is true, in the same way that it is true that the weather is becoming less predictable — accurate, mildly worrying, and useless as the basis for action. The more interesting truth, the one nobody seems quite ready to say out loud, is that our defences have stopped being a defence. They are now a recording mechanism. They notice things. They notice things very thoroughly. They simply notice them in the past tense.

Book-keeping with anxiety

Consider what an enterprise actually does to defend itself, in 2026. It conducts a quarterly access review, in which someone — usually a tired manager — looks at a spreadsheet of 4,000 entitlements and decides, with the rigour of a person choosing a sandwich, that they all look fine. It runs a vulnerability scanner, which produces a list of 47,000 findings, of which 12 are real, 4 are urgent, and the rest are a quiet ritual of corporate self-soothing. It commissions an annual penetration test, the results of which are presented to the board in a deck whose opening slide, without fail, contains the phrase overall posture is improving. It convenes a fraud review meeting six weeks after the fraud, where someone with a clipboard explains how it happened, in considerable detail, to people who can no longer do anything about it. It produces a quarterly operational risk report whose top five risks have been the same top five risks for nine consecutive quarters, because anything new would require explaining why it was missed.

This is not security. This is not risk management. This is bookkeeping with anxiety.

This is not security. This is not risk management. This is bookkeeping with anxiety.

The industry, sensing this, has responded with the only weapon it has ever truly mastered: the acronym. We now have CTEM and ITDR and ISPM and ZTNA and SASE and XDR and CNAPP on the security side, and ORM and ICAAP and KRI and RCSA and BCP and ORSA on the risk side, and a dozen more on each, each promising to solve, comprehensively, a problem we have yet to define. Magic Quadrants are produced. Forrester Waves crash decorously onto the procurement shore. Consultants arrive at board meetings with slides whose font sizes shrink in inverse proportion to the confidence of the speaker. Everyone agrees that something must be done. Nothing is done. The acronyms multiply.

The gap between two audits

The reason none of this works is not that the tools are bad. Most of them are quite good at what they do. The reason none of it works is that the entire architecture — security, risk, compliance, audit, the whole edifice — is organised around inspecting states. Was the user authorised. Was the patch applied. Was the transaction approved. Was the control tested. Was the policy signed. The adversary, meanwhile — and here adversary should be read broadly, to include external attackers, internal abusers, third-party drift, regulatory exposure, and the slow entropy of a digital estate that nobody has fully mapped in six years — stopped attacking states some years ago. They now operate on streams. They wait for the half-second between provisioning and use. They study the behavioural rhythm of a real user for three weeks and then impersonate it for four minutes. They walk a vulnerability path that no scanner has marked as urgent, because the path doesn’t exist in the scanner’s worldview — it exists only when three configurations align, which they will, at 2:14am on the third Tuesday of the month.

They are not, in other words, breaking your controls. They are slipping between them. And the gap they slip through is the gap between two audits.

They are not, in other words, breaking your controls. They are slipping between them. And the gap they slip through is the gap between two audits.

A change of tense

This is the part of the essay where I would, if I were a vendor, pivot smoothly into the solution. I am not a vendor. I am someone who has sat on enough boards to know that the solution is not a product. It is a change of tense.

Defence, to be defence again — whether you call it cyber, information security, operational risk, or simply the thing the regulator is going to ask about next — has to be continuous, not periodic. It has to read behaviour, not just credentials. It has to validate exposures by walking them, not by listing them. It has to operate at machine speed, because the attacker, the system, and the regulator certainly do. None of this is exotic. All of it exists. Some of it is being built — quietly, by people who have stopped attending the acronym conferences — in places you would not necessarily expect. The interesting work, as is usually the case, is not where the marketing budget is.

The question for any board, the next time the security update or the risk update or the compliance update appears on the agenda just before lunch, is not are we secure. Nobody is. The question is: what was true at 2:00am that wasn’t true at 9:00am? If your CISO, or CRO, or Head of Operational Risk can answer that, you have a programme. If they cannot, you have a reporting cadence in a nice colour palette.

“If your CISO, or CRO, or Head of Operational Risk can answer that, you have a programme. If they cannot, you have a reporting cadence in a nice colour palette.”

The shift required is not technological. The technology exists. It is being deployed, in pockets, by institutions that have stopped pretending the old model works. The shift required is philosophical. It is a willingness to say, out loud, in a room where people are paid to be reassured, that the way we have been doing this — across cyber, information security, and the broader risk estate — is no longer the way to do this.

This is harder than it sounds. The architecture of corporate security and risk is, in many institutions, indistinguishable from the architecture of corporate comfort. Quarterly reviews exist because they fit the calendar of the audit committee. Annual penetration tests exist because they fit the budget cycle. Operational risk reports exist because they fit the regulator’s template. The acronyms exist because they fit the slide. None of these things exist because the adversary respects them. The adversary, in fact, finds them quite useful — they tell him exactly when no one is looking.

The first step, before any technology is bought or any framework is adopted, is to ask a question the slide deck does not invite. Not are we compliant. Not are we covered. Not did we tick the box. But: are we still defending in a tense the attacker, the system, and the world have abandoned? If the honest answer is yes, no product and no framework will save you. If the honest answer is no, you already know which way to walk.

The next essay in this series picks up identity — specifically, the strange new world in which most of the identities inside an enterprise are not human, do not sleep, and are multiplying faster than anyone is governing them. The one after will look at the asymmetry between offensive automation and defensive automation, and what it means when both sides of an attack — and, increasingly, both sides of a risk assessment — are now run by machines.

If you’d like to read them when they’re published — and the longer working paper I’m writing for boards on how to ask better questions about cyber, information security, and operational risk — leave a note in the comments or write to me directly. I read everything. I reply to most of it. I do not, ever, add anyone to a mailing list. That is a promise of a kind.


Comments

2 responses to “Cyber, InfoSec, Ops Risk – Defending in the Wrong Tense”

  1. […] The first essay in this series argued that the tense of defence is wrong. The second argued that the subject of defence is wrong. This third and final essay argues something that follows from the first two but that nobody, in polite institutional company, wishes to say aloud: the speed of defence is wrong, and the human-in-the-loop — that comforting phrase deployed at every board meeting, every regulatory submission, every vendor demo — is increasingly a polite fiction. […]

  2. […] The first essay in this series argued that the tense of defence is wrong — that we inspect what was, while the adversary works in what is. This second essay argues something more uncomfortable: that the subject of defence is also wrong. We have spent thirty years building identity management programmes around the assumption that an identity is a person. It has not been true for some time. It is now spectacularly untrue. And nobody, in most institutions, has noticed. […]

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from Sumir Nagar

Subscribe now to keep reading and get access to the full archive.

Continue reading