Nobody knows who gets the 3 am call.


Here is a test that takes ninety seconds and is more informative than most security assessments.
Ask three people in your organisation — one in IT, one in the executive team, one in the business — what happens if something serious is detected at three o'clock on a Sunday morning. Who is called first? What that person is authorised to do without waking anyone else. Whether they can take a production system off the network on their own judgement, or whether they need permission from somebody whose phone is on silent.
In my experience you get three different answers, and at least one of them is "I assume there's a
process".
That gap is not a tooling gap. You cannot buy your way out of it, and organisations that try end up
with a well-equipped estate that is still, in the way that matters, undefended.
Security spend is easy to justify and hard to evaluate
This is the structural problem with the whole category.
A business can hold a full stack of respectable products, a current certificate, a penetration test
from this year and a board paper showing spend rising in line with peers — and none of that answers whether an attacker who lands on a laptop in the finance team can reach anything that matters.
Every one of those artefacts is easy to evidence. The thing they are meant to be evidence of is
not. So the conversation drifts to what can be counted: tools deployed, findings closed, budget
committed. It is a rational response to a hard question, and it produces estates that look defended
on paper.
Two questions cut through most of it.
What are we actually protecting? Not the asset register. The three or four things whose loss or
exposure would genuinely damage the business — and where they actually live, which is very often not where policy says they live. Regulated data has a way of ending up in an export somebody built for a good reason in 2022.
Who acts when this alerts? Named, contactable, and clear on their authority.
If those two are unanswered, buying a detection platform is premature. It will generate signals that
arrive somewhere nobody is watching, about assets nobody has prioritised, for a response nobody is authorised to make.
Where does a compromise stop?
The most useful architecture question is not how someone gets in. Assume they get in — through a
phished credential, an unpatched edge device, a supplier's access, one of the ordinary routes.
The question is where they stop.
If the honest answer is "we're not sure", that is a segmentation and identity finding, and it is
worth more than another year of tooling. Most of the damage in the incidents that make the news came after the initial access, during the part where the intruder moved sideways through an estate that was flat because flat was convenient.
Identity is where this concentrates. Who can reach what. Whether privileged access is time-bound or permanent. Whether leavers actually lose access, or merely stop using it — those are different
things, and the second one is far more common than security policies suggest. Whether the certificate that expires next month has an owner, because an expired certificate has taken down more services than most of the threats in the risk register.
None of that is exotic. It is not the interesting part of security. It is the part that decides
outcomes.
Response is a rehearsal problem
An incident response plan that has never been exercised is a document, not a capability.
The exercise does not need to be elaborate. Put the people who would actually be on the call in a
room for two hours, give them a plausible scenario, and work through it in real time. What you learn
in the first forty minutes is usually not about attackers. It is that the out-of-hours contact list
is out of date, that nobody is clear who talks to the regulator or the insurer, that the person with
authority to disconnect a system is on leave with no delegate, and that the recovery procedure
depends on a system that would itself be affected.
Every one of those is cheap to fix, and none of them will be found by a tool.
What we do, and what we do not
I want to be direct about the boundary of this, because the security market is not always direct
about it.
Toga designs. We establish what is worth protecting, assess it honestly rather than accepting the
documented position, design the architecture, identity model, controls and detection, staff security
functions with our own specialists, and run the rehearsal with the people who would actually take
the call.
We do not operate a 24/7 managed security operations centre.
We are a boutique firm. Running round-the-clock monitoring properly requires a staffed rota at a scale we do not have, and I would rather say that plainly than bid for it and let a client find out during an incident. Where continuous monitoring is what an organisation needs, we will say so, help specify what good looks like, and help select or integrate a provider — which is a genuinely useful thing to do, because most organisations buy that service without a clear definition of what they are buying.
One further boundary, because it saves confusion in tenders. Certification and regulatory
preparation — ISO 27001, NIS2 readiness, obligation mapping, the policy set and the decision rights around it — is governance work, and we handle it under Global Governance. The technical controls those obligations imply are security work, and they sit here. They are usually bought by different budgets, and they are not the same exercise; however, often they appear on the same page.
⸻
Eight signals worth checking against your own organisation.
Nobody can say who would be called first at three in the morning. Tooling has been bought, and the
alerts are not reviewed. Leavers keep access. A certificate expiry has caused an outage. A customer or regulator questionnaire cannot be answered honestly. A penetration test report is eighteen months old with findings still open. A cyber insurance renewal is asking for evidence that does not exist. A new obligation is arriving, and nobody has mapped it to a system.
If several of those are true, the useful next step is not a purchase. It is two hours with the people
who would be on the call.
⸻
Oghenetega Gharoro-Akpojotor is the founder of Toga EMEA, a boutique technology management
consultancy working across Europe, the Middle East, Africa and APAC. Cyber Defence is Toga's security practice.



Comments