Before You Scale AI, Secure the Basics

August 12, 2026

In the first blog of this series, we talked about how many organizations are still struggling with the same fundamental security challenges they faced a decade ago, despite investing heavily in advanced security capabilities.

 

If teams do not know what assets they have, cannot keep configurations consistent or lose track of who has access to what, even the most advanced tools will struggle to deliver real value. Before security teams chase what is next, they have to get serious about what has always mattered.

 

This means moving the spotlight to conversations around segmentation, deception, recovery and complexity.

 

 

The Forgotten Value of Segmentation

For years, network segmentation has been one of the least glamorous topics in cybersecurity. People don’t rush to build their conferences, companies or marketing campaigns around it. Yet segmentation remains one of the most effective controls available.

 

Modern security leaders recognize that preventing every intrusion is unrealistic. Threat actors will eventually gain access through stolen credentials, compromised vendors, external partners, cloud services or other trusted relationships. Supply-chain attacks and trusted-access compromises continue to reinforce this reality. The critical question is no longer whether attackers can enter an environment, it is, “What can they do after they get in?”

 

Well-designed segmentation limits movement and allows monitoring tools to alert while slowing down the attackers. It protects identity infrastructure, isolates critical workloads, separates administrative functions and reduces the blast radius of a successful compromise. The goal is not perfection. The goal is containment.

 

 

Deception May Be Ready for a Comeback

Another area that deserves more attention is deception technology. For years, deception platforms were often viewed as niche capabilities reserved for highly mature security organizations. Honeypots, honeytokens, decoy credentials and fake systems were frequently treated as interesting experiments rather than core security controls. 

 

That perception is starting to change. As attackers increasingly rely on automation, credential theft and identity abuse, deception offers something many security tools struggle to provide: high-confidence detection. If an attacker interacts with a decoy account, accesses a fake database, attempts to authenticate with planted credentials or probes a system that should never be used by legitimate employees, the signal is immediately meaningful. 

 

Unlike traditional security monitoring, which can generate thousands of alerts requiring triage, deception alerts often indicate malicious activity by definition. This becomes particularly valuable for security teams drowning in telemetry. Organizations continue to add endpoint tools, cloud logging platforms, identity monitoring systems and detection capabilities, yet many SOC analysts still spend much of their day separating false positives from legitimate threats.

 

 

Deception Changes the Equation 

Deception creates assets that have no business value other than detecting unauthorized activity. The concept is deceptively simple. Instead of trying to detect every possible attack, organizations create traps throughout the environment and watch for adversaries that spring them. A mature deception strategy can include planted credentials in administrative systems, fake cloud assets, decoy service accounts, mock databases containing synthetic records and even complete decoy environments that mimic production systems. When attackers move laterally, harvest credentials, perform reconnaissance or attempt privilege escalation, they are far more likely to reveal themselves before reaching critical assets. This capability aligns particularly well with a growing reality in cybersecurity: preventing every intrusion is becoming increasingly difficult. 

 

Deception technologies also complement security fundamentals rather than replace them. They serve as an additional layer that helps security teams identify control failures before an incident becomes a breach. 

 

As enterprises continue to invest in AI-powered detection and autonomous security operations, deception may become even more valuable. High-confidence alerts generated from deception assets can provide exactly the type of signal that automated SOC workflows and AI security agents need to prioritize investigations, reduce analyst workload and accelerate response. In a future defined by machine-speed attacks, deception offers a surprisingly old-fashioned advantage, making attackers reveal themselves.

 

 

Resilience Is More Important Than Prevention

Perhaps the most overlooked security capability today is recovery. Organizations invest heavily in prevention, detection, and response capabilities. Those investments are necessary. However, ransomware, extortion groups, supply chain and identity-focused attacks continue to demonstrate that some level of compromise remains inevitable. The organizations that recover more quickly often experience less long-term damage. 

 

This is why backups, disaster recovery testing, tabletop exercises and crisis communications planning deserve more executive attention. A backup strategy that has never been tested is not a recovery capability. An incident response plan that exists only on paper is not operational resilience.

 

Cybersecurity programs frequently measure prevention. Mature cybersecurity programs measure recovery.

 

 

Complexity May Be the Industry's Biggest Security Problem

The most important lesson emerging from today's cybersecurity landscape is not about AI, ransomware, cloud security or identity. It is about complexity. As organizations operate countless applications, security products, cloud platforms, identities and integrations, complexity grows and visibility declines. 

 

The industry's natural response has often been to purchase another tool. The highest-performing security programs are rarely the ones with the most technology. They are the ones with the clearest architecture, the strongest operational discipline and the most consistent execution of security fundamentals. AI, cloud-native application protection platform (CNAPP), exposure management, agentic SOCs and advanced analytics are all valuable force multipliers. But force multipliers only work when there is already a force to multiply. 

 

The future of cybersecurity will undoubtedly be shaped by AI. Yet the organizations most likely to succeed will be those that remember a simple truth: security has always been, and will remain, a fundamentals-driven discipline. The enterprises that master visibility, identity, configuration management, deception technologies, segmentation and resilience will ultimately outperform those that simply acquire more tools.

 

 

Now What: Turning Fundamentals Into a Security Roadmap

For cybersecurity leaders, the lesson is not that AI is overhyped or that innovation should slow down. The lesson is that advanced security capabilities only deliver meaningful value when they are built on a strong operational foundation. 

 

Organizations are trying to modernize quickly by evaluating a growing range of AI, cloud, identity and detection technologies. Meanwhile, many are still working through foundational questions such as: Do we know what assets we have?

  • Do we know who has access to what?
  • Can we identify our critical business systems?
  • Can we recover from a ransomware event?
  • Can we detect unauthorized activity quickly?

 

Before investing in another platform, organizations should ask what outcome they are trying to achieve and what foundational capabilities must exist for that outcome to be realistic. 

 

The next wave of cybersecurity maturity will belong to organizations that bridge the gap between innovation and execution. Want to see how you stack up? Schedule a no cost, no obligation security program landscape review.

Marty McDonald
Sr. Demand & Delivery Manager, CDAS | Optiv
Marty is a subject matter expert in the design and implementation of security incident and event management (SIEM) systems and is well versed in creating detection mechanisms that enhance security operation centers and compliance effectiveness. He has 20 years of deep cyber security industry experience gained from a variety of value-added resellers and solutions integrators. Prior roles include Senior Consultant in Security Intelligence for Datalink and Senior Consultant in the Technology Solutions Delivery organization at Accenture.

About Optiv Security: Secure greatness.® 
Optiv is the world’s largest pure-play cybersecurity company. With unmatched technology partnerships and deep technical expertise, Optiv securely enables the AI era for more than 6,000 clients. From financial services and health care, to government, energy and retail, organizations trust Optiv to advise, deploy and operate cybersecurity programs that reduce risk and deliver real results. Learn why Optiv is the most trusted brand in cyber at optiv.com.