Cyber Defense Advisors

Your Cybersecurity Program Looks Good on Paper. Would It Survive Tuesday Morning?

Your Cybersecurity Program Looks Good on Paper. Would It Survive Tuesday Morning?

Most companies can point to MFA, backups, security tools and an incident-response plan. Far fewer can prove those defenses will work when an attacker gets in and the clock starts running.

At 9:17 on a Tuesday morning, the difference between a cybersecurity program that looks good on paper and one that actually works can become painfully clear. An employee reports that Microsoft 365 keeps asking them to log in. Minutes later, someone notices an unfamiliar forwarding rule in the account. The security team checks the logs. Something is wrong.

Now the policies sitting in SharePoint matter a lot less than what happens next. Who can disable the account? Has anyone revoked the active sessions? Did the attacker reach SharePoint, Teams or another cloud application? Was sensitive data downloaded? Who calls legal counsel? Who contacts the cyber insurer? Who decides whether customers or regulators need to know? And perhaps most important: Does everyone already know the answers?

That is the difference between having a cybersecurity program and having one that actually works.

The Security Program Everyone Thinks They Have

On paper, many companies look reasonably secure. MFA is enabled. Endpoint protection is installed. Backups run every night. Employees complete annual security training. Vulnerability scans generate reports. An MSP or managed security provider watches alerts. There is probably an incident-response document somewhere.

Every one of those things is useful. None proves the organization can withstand an actual attack.

A backup system can report successful jobs for months without anyone knowing whether a critical server can actually be restored from it. An incident-response plan can satisfy an auditor while containing phone numbers for employees who left two years ago. Security software can be installed everywhere and still be configured incorrectly. Even MFA—the control organizations increasingly treat as table stakes—only protects the systems where it is actually turned on.

That distinction has had enormous consequences.

We Have Already Seen What One Missing Control Can Do

When Colonial Pipeline was hit with ransomware in May 2021, investigators traced the intrusion to a legacy VPN profile that was no longer intended to be used. Senate testimony later established that the account did not use multifactor authentication. The company shut down pipeline operations, contributing to fuel shortages and panic buying across parts of the Eastern United States.

Three years later, the lesson was repeated on an even larger scale. Attackers used compromised credentials to enter a Change Healthcare Citrix remote-access portal in February 2024. The portal did not have MFA. According to UnitedHealth CEO Andrew Witty’s congressional testimony, the attackers entered on February 12, moved laterally through the environment, exfiltrated data and deployed ransomware nine days later. The attack disrupted payment and claims systems across the U.S. health-care industry.

Then there was MGM Resorts. Its September 2023 cyberattack forced the company to shut down systems across its U.S. properties. Reservations and other guest-facing services were disrupted, customer information was stolen, and MGM later estimated the incident would reduce adjusted property earnings by approximately $100 million for the quarter.

Different companies. Different industries. Same uncomfortable lesson: cybersecurity tends to fail at the point where what an organization assumes is happening diverges from what is actually happening.

“We Have That” Is Not the Same as “We Tested That”

Ask almost any company whether it has backups and the answer will be yes. Ask when it last restored a critical production environment from those backups and watched the business operate from it, and the conversation often changes.

The same goes for almost every major security control.

“We have MFA.” Is it required for every privileged account, remote-access service and cloud application?

“Our MSP monitors us.” What happens when it detects something at 2:00 a.m.? Who gets called? How quickly? What authority does the provider have?

“We have an incident-response plan.” When was the last tabletop exercise? Did the CEO participate? Did legal? Finance? Communications? The outside security provider?

“We terminate access when employees leave.” Across Microsoft 365, VPN, Salesforce and every other SaaS application—or only the systems HR remembers?

The dangerous word underneath all of these answers is assume. A mature security program replaces assumptions with evidence.

The Controls Most Likely to Matter Are Often the Least Tested

Security teams spend enormous amounts of time proving that controls exist. What receives less attention is whether those controls will function correctly under pressure.

Can a compromised administrator account be detected quickly? Can someone restore the company’s most important application without rebuilding half the environment first? Are old VPN accounts really disabled? Can the organization identify every third party with privileged access? If the MDR provider sends a critical alert tonight, does someone have the authority to take a production server offline immediately—or will ten people spend an hour debating it?

These are not exotic attack scenarios. They are ordinary operational questions. That is precisely why they matter.

Attackers rarely need every security control to fail. They need one weakness, one forgotten account, one bad configuration or one delay—and enough time to exploit it.

Five Questions Every Executive Should Be Able to Answer

Executives do not need to become security engineers. They do need to know whether the security program beneath them has been tested in the real world.

Start with five questions:

  1. When did we last test our incident-response plan rather than simply review it?
  2. When did we last restore a critical system from backup and verify that the business could operate?
  3. How quickly would we know if a privileged account were compromised?
  4. Who has access to our most sensitive systems today—and does every one of those people still need it?
  5. If a serious security alert arrived tonight, who exactly would make the decisions?

If the answers involve long pauses, conflicting explanations or too many sentences beginning with “I think,” that is useful information.

You have found something to test.

Cybersecurity Is a Verb

Compliance matters. Policies matter. Security products matter. Documentation matters. But none of them is the finish line.

A functioning cybersecurity program continuously challenges itself. It tests controls. Exercises incident response. Reviews access. Validates backups. Examines configurations. Tracks vulnerabilities. Challenges third-party dependencies. And periodically tries to discover what everyone has missed.

The objective is not to accumulate more evidence that the organization is secure. It is to find evidence that it isn’t—while there is still time to fix it.

Because sooner or later, every cybersecurity program gets its Tuesday morning.

The time to find out whether yours works is Monday.

Put Your Cybersecurity Program to the Test

Cyber Defense Advisors helps organizations move beyond policies, dashboards and assumptions to determine whether their cybersecurity controls actually work. We assess security programs, test defenses, identify operational gaps and help organizations strengthen incident readiness before those weaknesses become real-world problems.

If you want to know how your cybersecurity program would perform on Tuesday morning, contact Cyber Defense Advisors today.

Leave feedback about this

  • Quality
  • Price
  • Service