top of page

Nobody knows who gets the 3 am call.

Writer: Toga EMEA FZC LLC
Toga EMEA FZC LLC
Sep 6
5 min read

Here is a test that takes ninety seconds and is more informative than most security assessments.


Ask three people in your organisation — one in IT, one in the executive team, one in the business — what happens if something serious is detected at three o'clock on a Sunday morning. Who is called first? What that person is authorised to do without waking anyone else. Whether they can take a production system off the network on their own judgement, or whether they need permission from somebody whose phone is on silent.


In my experience you get three different answers, and at least one of them is "I assume there's a 

process".


That gap is not a tooling gap. You cannot buy your way out of it, and organisations that try end up 

with a well-equipped estate that is still, in the way that matters, undefended.


Security spend is easy to justify and hard to evaluate


This is the structural problem with the whole category.


A business can hold a full stack of respectable products, a current certificate, a penetration test 

from this year and a board paper showing spend rising in line with peers — and none of that answers whether an attacker who lands on a laptop in the finance team can reach anything that matters.


Every one of those artefacts is easy to evidence. The thing they are meant to be evidence of is 

not. So the conversation drifts to what can be counted: tools deployed, findings closed, budget 

committed. It is a rational response to a hard question, and it produces estates that look defended 

on paper.


Two questions cut through most of it.


What are we actually protecting? Not the asset register. The three or four things whose loss or 

exposure would genuinely damage the business — and where they actually live, which is very often not where policy says they live. Regulated data has a way of ending up in an export somebody built for a good reason in 2022.


Who acts when this alerts? Named, contactable, and clear on their authority.


If those two are unanswered, buying a detection platform is premature. It will generate signals that 

arrive somewhere nobody is watching, about assets nobody has prioritised, for a response nobody is authorised to make.


Where does a compromise stop?


The most useful architecture question is not how someone gets in. Assume they get in — through a 

phished credential, an unpatched edge device, a supplier's access, one of the ordinary routes.


The question is where they stop.


If the honest answer is "we're not sure", that is a segmentation and identity finding, and it is 

worth more than another year of tooling. Most of the damage in the incidents that make the news came after the initial access, during the part where the intruder moved sideways through an estate that was flat because flat was convenient.


Identity is where this concentrates. Who can reach what. Whether privileged access is time-bound or permanent. Whether leavers actually lose access, or merely stop using it — those are different 

things, and the second one is far more common than security policies suggest. Whether the certificate that expires next month has an owner, because an expired certificate has taken down more services than most of the threats in the risk register.


None of that is exotic. It is not the interesting part of security. It is the part that decides 

outcomes.


Response is a rehearsal problem


An incident response plan that has never been exercised is a document, not a capability.


The exercise does not need to be elaborate. Put the people who would actually be on the call in a 

room for two hours, give them a plausible scenario, and work through it in real time. What you learn 

in the first forty minutes is usually not about attackers. It is that the out-of-hours contact list 

is out of date, that nobody is clear who talks to the regulator or the insurer, that the person with 

authority to disconnect a system is on leave with no delegate, and that the recovery procedure 

depends on a system that would itself be affected.


Every one of those is cheap to fix, and none of them will be found by a tool.


What we do, and what we do not


I want to be direct about the boundary of this, because the security market is not always direct 

about it.


Toga designs. We establish what is worth protecting, assess it honestly rather than accepting the 

documented position, design the architecture, identity model, controls and detection, staff security 

functions with our own specialists, and run the rehearsal with the people who would actually take 

the call.


We do not operate a 24/7 managed security operations centre. 


We are a boutique firm. Running round-the-clock monitoring properly requires a staffed rota at a scale we do not have, and I would rather say that plainly than bid for it and let a client find out during an incident. Where continuous monitoring is what an organisation needs, we will say so, help specify what good looks like, and help select or integrate a provider — which is a genuinely useful thing to do, because most organisations buy that service without a clear definition of what they are buying.


One further boundary, because it saves confusion in tenders. Certification and regulatory 

preparation — ISO 27001, NIS2 readiness, obligation mapping, the policy set and the decision rights around it — is governance work, and we handle it under Global Governance. The technical controls those obligations imply are security work, and they sit here. They are usually bought by different budgets, and they are not the same exercise; however, often they appear on the same page.

Eight signals worth checking against your own organisation.


Nobody can say who would be called first at three in the morning. Tooling has been bought, and the 

alerts are not reviewed. Leavers keep access. A certificate expiry has caused an outage. A customer or regulator questionnaire cannot be answered honestly. A penetration test report is eighteen months old with findings still open. A cyber insurance renewal is asking for evidence that does not exist. A new obligation is arriving, and nobody has mapped it to a system.


If several of those are true, the useful next step is not a purchase. It is two hours with the people 

who would be on the call.

Oghenetega Gharoro-Akpojotor is the founder of Toga EMEA, a boutique technology management 

consultancy working across Europe, the Middle East, Africa and APAC. Cyber Defence is Toga's security practice.

 
 
 

Comments


bottom of page