By Aaron Fansler, CEO, FrontLine Cyber Solutions
I’ve been working in cybersecurity for almost 25 years now.
Over that time, I’ve watched the industry evolve from protecting standalone networks and defending against relatively unsophisticated malware to combating nation-state adversaries, ransomware syndicates, AI-assisted attacks, supply chain compromises, and attacks against critical infrastructure.
- Technology has changed dramatically.
- The attackers have become more sophisticated.
- The tools have become more advanced.
- Budgets have grown.
- Entire industries have been built around cybersecurity.
Yet despite all of that…We’re still fighting many of the exact same problems we were fighting two decades ago.
The More Things Change
Every year, we hear the same predictions.
- “This year ransomware will explode.”
- “We’re seeing an increase in phishing.”
- “Organizations still aren’t patching.”
- “Passwords are weak.”
- “People are the weakest link.”
- “Critical infrastructure remains vulnerable.”
Sound familiar?
I’ve heard those same statements for almost a quarter of a century.
- The names of the malware families have changed.
- The attack techniques have become more refined.
- The technology has improved.
- But the underlying problems remain remarkably consistent.
- Organizations still struggle with visibility.
- Asset inventories are still incomplete.
- Networks still aren’t segmented.
- Security monitoring remains reactive rather than proactive.
- Incident response plans still sit on shelves until the day they’re desperately needed.
- Attackers continue to exploit systems with known vulnerabilities, and the funny part is that sometimes those vulnerabilities have been public for years.
Pondering on it all, technology changes, but human behavior changes much more slowly. Which leads me to my next question
Why Aren’t We Getting Better?
It’s a question I’ve been asking myself more frequently, and what I can’t wrap my head around is if:
- We’ve invested hundreds of billions of dollars globally into cybersecurity
- We’ve developed countless security products
- We’ve written thousands of security standards
- Organizations are more aware of cyber risk than ever before
Why don’t the outcomes reflect that investment? I refuse to believe it’s because we’re not trying. I think we’ve become incredibly good at reacting. I’m less convinced we’ve become equally good at fundamentally changing how we approach cybersecurity.
Too often, we solve yesterday’s attack with tomorrow’s product. Then we wait for attackers to adapt. Enviably, they always do.
Are We Living the Definition of Insanity?
There’s a quote often attributed to Albert Einstein: “The definition of insanity is doing the same thing over and over again while expecting different results.” Whether Einstein said it or not, isn’t the important part. The question is whether it applies to cybersecurity.
I’ve been a part of so many breach recoveries lately, every one of them has the same “recommendations”:
- Deploy MFA.
- Improve logging.
- Implement Zero Trust.
- Conduct more training.
- Segment networks.
- Patch faster.
- Increase visibility.
These are all good recommendations. But they’re also the same recommendations we’ve been making for years, if not decades. Yet organizations continue to experience the same categories of compromise by repeating the same poor decisions. It reminds me of drunk driving or smoking cigarettes. In both cases, people know the risks, yet some continue the behavior and ultimately face the consequences.
Back on point, perhaps the issue isn’t that the recommendations are wrong, but rather the issue is that we’re treating cybersecurity as a collection of products instead of a continuously evolving discipline.
A Mathematician’s Perspective
Before cybersecurity became my career, mathematics was my academic foundation. One of the things mathematics teaches you is that patterns matter. History matters, iteration matters. Eventually you begin asking a different question. Not “What happened?” But rather, “Why do things happen?”
That mindset has shaped how I think about cybersecurity. Rather than focusing only on individual incidents, I look for why they happened and examine the root causes across the systems that produced them: people, technology, and processes.
That always leads me back to why do organizations continue to lack visibility or why do they still gamble with cybersecurity. Why do they tend to always choose the cheapest route or always look for the easy button?
That leads to the next obvious question: why do attackers keep succeeding with the same techniques? If the same lure keeps catching fish, why would they change it?
The next question is why defenders so often respond instead of anticipate. There are several answers, and it can quickly become a deep rabbit hole. In one recent ransomware incident we handled, the organization did not have a dedicated cyber defender. They had an IT person who could talk about cybersecurity and install a low-cost antivirus product. That problem alone deserves its own discussion.
As I step back and think about it, none of the reasons for any breach are isolated failures. They’re characteristics of the “system” failing overall.
The Code Makers vs. The Code Breakers
History offers an interesting parallel. Long before cybersecurity existed as an industry, there was cryptography. Entire governments invested enormous resources into creating stronger encryption. At the same time, equally talented mathematicians worked just as hard to break it. Every advancement in code making produced a corresponding advancement in code breaking.
Neither side ever permanently “won.” The competition simply evolved. Cybersecurity feels remarkably similar. Every defensive innovation creates new offensive research. Every detection capability inspires new evasion techniques. Every security control motivates new attack methods.
Artificial intelligence is accelerating both sides simultaneously. Better defenders. Better attackers. Stronger encryption. More sophisticated exploitation. The race never stops.
Maybe cybersecurity isn’t separate from that centuries-old struggle. Maybe it’s simply the latest chapter in an ongoing mathematical competition between those who protect information and those who seek to obtain it.
Security Is an Adaptive System
One mistake we often make is thinking cybersecurity is a destination. It isn’t. It’s an adaptive system. Every participant learns. Attackers evolve, defenders evolve, technology evolves and compliance regulations evolve. The environment never reaches equilibrium.
That’s why organizations can’t treat cybersecurity as a project with an end date. It’s closer to biology than engineering. The strongest organizations aren’t necessarily those with the biggest budgets. They’re the ones capable of adapting faster than their adversaries.
We Need to Stop Chasing Alerts
One observation I’ve made over the years is that we’ve become exceptionally good at collecting alerts. Unfortunately, alerts aren’t intelligence. Most organizations are drowning in data while starving for understanding.
Security isn’t improved by producing another dashboard. It’s improved by understanding what the data means. That’s one of the reasons we’ve invested so heavily in building technologies and services focused on behavior, context, and operational understanding rather than simply generating more notifications.
Finding another alert isn’t difficult. Understanding why it matters is where real cybersecurity begins.
Maybe We’re Asking the Wrong Question
Perhaps the goal shouldn’t be asking how we eliminate cyber-attacks. History suggests that isn’t realistic. Maybe the better question is, “How do we become organizations that learn and adapt faster than our adversaries?” That’s a fundamentally different objective.
It changes how we think about security investments. It changes how we train people. It changes how we build technology. It changes how we measure success.
Looking Forward
After nearly 25 years in cybersecurity, I’m optimistic. Not because I think attackers are slowing down. They’re not. Not because regulations will solve the problem. They won’t.
I’m optimistic because our understanding of cybersecurity is beginning to mature. We’re starting to recognize that cybersecurity isn’t just about firewalls, endpoint protection, or compliance checklists.
It’s about understanding systems. Understanding behavior. Understanding people. Understanding the business decisions that lead to bad security decisions. As my best friend always says, “It’s about understanding that a customer shouldn’t spend thousands of dollars to protect a hundred-dollar asset”.
We must start understanding how technology, mathematics, engineering, psychology, and operations interact. Those are much harder problems to solve.
They’re also the problems worth solving. The race between the code makers and the code breakers will almost certainly continue for decades to come. The challenge for all of us isn’t finding a way to end the race.
It means thinking more strategically, challenging assumptions, and staying one step ahead without overthinking the problem which leads to hesitation or stagnation.
Because in cybersecurity, over thinking is just like standing still and that is the same as falling behind.