Photo Credit: Pexels
Five cybersecurity experts explain why prevention, verification, and early action matter more than waiting for an attack.
Cybersecurity has long operated around a familiar sequence: find a threat, respond to it, and repair the damage. That approach becomes harder to sustain when attackers can develop new tactics faster than businesses can recognize them. Artificial intelligence has made convincing phishing messages easier to create, while remote work, connected devices, and increasingly sophisticated fraud have given attackers more places to look for an opening.
Across industries, cybersecurity leaders are responding by putting more attention on what happens before an attack. Their methods vary, but they share a basic idea: preventing an attacker from getting through is far less complicated than dealing with what happens once they are inside.
Slow Down and Verify
Speed is one advantage attackers have learned to exploit. Fraud attempts often create a sense of urgency, giving a target little time to question a request before sending money or revealing information.
John Rowan, founder of Home Fraud Defense, sees that problem regularly in real estate. He says the fraud world can adapt to new information within weeks, particularly as AI gives criminals new ways to refine existing scams.
“The fraud world operates on a six-week timeframe,” Rowan said. “And the fraud world goes, ‘With AI, how can I do this and make it better?’”
His response is decidedly low-tech. Rowan’s “Pause Protocol” asks people who receive a suspicious request to wait 24 hours and verify it using a phone number they already know and trust.
“That is the one thing the fraud community can’t get past: that simple voice verification from a trusted, known number,” Rowan said. “There isn’t really a case that I’ve seen that that pause and phone call wouldn’t have stopped.”
The threat can also move beyond a fraudulent payment request and into emotional manipulation. Rowan described an 85-year-old doctor who was prepared to sell a $500,000 home for $100,000 while being manipulated by someone she trusted.
“She was willingly doing it. She was being manipulated,” Rowan said. “That’s another level we deal with in the real estate world, where people are just so starved for attention.”
Restrict Access Before Something Goes Wrong
While Rowan focuses on interrupting the decisions that allow fraud to succeed, Danny Jenkins, co-founder and CEO of ThreatLocker, applies a similar prevention-first idea to the technology itself.
“Every cyber attack that I’ve ever seen in my life could have been stopped by simple proactive cybersecurity controls,” Jenkins said. “What companies are doing is sitting there watching cameras for something bad to happen instead of locking the doors.”
His alternative is a zero-trust approach that blocks activity unless it has already been approved. Jenkins recommends closing unnecessary network ports, preventing untrusted software from running, and validating devices accessing software-as-a-service accounts. He argues those three controls can prevent nearly all common attacks.
“Shut down your network ports, stop software from running that isn’t trusted, and make sure you’re validating devices for all your SaaS accounts,” Jenkins explains. “If you do those three things, you will stop 99.9% of probable cyberattacks.”
AI adds another complication because attackers can use it to create more convincing campaigns without the same technical expertise once required.
“Anyone with a computer right now can create malware or phishing campaigns anywhere in the world; they don’t even have to be smart. We’re seeing attackers using AI to create perfect phishing campaigns to create malware that’s never been seen before.”
Prepare People as Well as Systems
Sanford Wilk, COO of DigiGuard, says many small and mid-sized businesses approach cybersecurity as an expense they can postpone until a problem forces their attention.
“The vast majority of clients that come to us are on fire,” Wilk said. “All of those entrepreneurs and board members look at it as, ‘Why do an expense now? Let’s just deal with it when the time comes.’ That’s until they’re dealing with the cleanup.”
DigiGuard combines employee training and phishing tests with managed endpoint protection.
“Your employees are your softest spot,” Wilk explained.
Waiting until something goes wrong can also shift control away from the business itself.
“The surest way to have the insurance company telling you what to do on a daily basis is to have a failure. And the surest way to have a failure is to have no evaluation beforehand.”
Nik Bakhshalian, director of strategy and growth at AET Solutions, also sees human behavior as a weak point, particularly when businesses assume the platforms they already use provide enough protection.
“They have a certain sense of confidence in the tools they’re using,” Bakhshalian said. “The problem, the biggest vulnerability that businesses face, is individuals. Individuals allowing people to get in.”
AI is making manipulation harder to recognize. A public interview can provide enough audio to imitate an executive’s voice, allowing a scam to arrive as a phone call rather than an obviously suspicious email.
“If your CEO is public-facing at all, has done a single interview anywhere, they have his voice,” Bakhshalian explained. “It’s not just emails anymore. It’s phone calls. It’s voice.”
For smaller businesses, he argues that basic protections do not necessarily require a huge investment. “You do need backups; that’s the main thing. And you need MDR, managed detection and response, which is the next level of antivirus. “It’s not an expensive thing to just get set up.”
Build Security In Early
In regulated industries, waiting can create a different kind of problem. Jose Bohorquez, PhD, president and founder of CyberMed, works with medical device companies navigating cybersecurity requirements during the FDA clearance process.
“You literally won’t be able to market your device if you don’t get through FDA, and FDA requires that your system be secure,” Bohorquez said. “It’s a total of about 14 different documents: threat modeling, security architecture views, security risk analysis, test results.”
Bohorquez says companies may need to prepare about 14 different cybersecurity documents as part of that process. Companies that address those requirements late can discover problems when a product is already approaching submission.
“Twenty percent come to us after FDA has rejected their submission: that’s the worst-case scenario,” Bohorquez added. “Twenty percent come to us early and end up spending the least overall.”
Hospitals are also asking manufacturers for security documentation and information about how vulnerabilities will be patched.
“If you’re a medical device company and your medical device gets hacked, somebody gets hurt; your reputation is in the tank. Security isn’t optional anymore. It’s a market access requirement.”
Prepare for the Attack That Hasn’t Happened Yet
No single control addresses every cybersecurity threat. A real estate transaction, a remote employee’s laptop, and a connected medical device do not carry identical risks.
What connects them is timing. Waiting for an alert, a stolen payment, or a failed regulatory submission leaves the attacker or the problem in control of the timeline.
Businesses cannot predict exactly what the next attack will look like. They can slow down suspicious requests, limit unnecessary access, prepare employees, and address security weaknesses before someone else finds them first.