In a nutshell: Faster detection reduces financial damage from individual breaches, but does not prevent the underlying compromise — only prevention lowers structural risk.
The cybersecurity industry relies too heavily on detection and reaction instead of preventive controls. Experts call for a reversal: Over 70 percent of new cybersecurity startups develop detection tools, while prevention remains underfunded.
The cybersecurity industry primarily relies on detection and incident response, despite prevention being demonstrably more cost-effective. This is evident in the portfolio of new security solutions: at the RSAC Conference, the industry’s largest startup competition, detection tools accounted for more than 70 percent of entries over the last three years across more than 500 newly launched companies. Prevention tools — firewalls, antivirus systems, and access controls — by contrast are receding into the background.
The focus on detection has historical roots: early networks were fragile, and downtime was expensive. As a result, perimeter controls emerged first, blocking access and preventing exploits. With the Internet boom of the 1990s, prevention multiplied. But as attackers adapted and networks became more complex, the industry supplemented these with Intrusion Detection Systems and Security Information and Event Management. Detection was meant to complement prevention, not replace it — yet the focus increasingly shifted nonetheless.
The problem: detection reduces the financial impact of breaches, not the structural risk. IBM’s Cost of a Breach report does document that faster identification and containment lower follow-up costs. However, the global average cost of a data breach remains in the eight-figure range because detection does not prevent the initial compromise. The real cause lies in known vulnerabilities, stolen credentials, or misconfigurations — problems that only prevention addresses.
The detection-first approach has further limitations: as the number of security tools increases, so does alert generation, leading to alert fatigue among security teams and an inundation of false positives. Meanwhile, modern attackers operate at machine speed — vulnerabilities are exploited automatically, and phishing campaigns are scaled through AI. With the further proliferation of frontier AI models and future quantum cryptography, the attack surface will grow exponentially. Responding to this dynamic with even faster detection is structurally insufficient.
Prevention changes the economic equation: it reduces the attack surface problem at its root, rather than treating alarms after breaches have already succeeded. A reallocation of investment and innovation toward preventive controls could permanently lower risk, instead of merely accelerating the treatment of breaches.
Source: www.csoonline.com · Published July 15, 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.