You probably don’t need to be more secure. You need to be able to prove it.
By Colin Riddle, Chief Product Officer, Ekco Cloud & Security
Most security conversations get framed around a single question: are we secure enough. It’s a reasonable question, but it tends to obscure a more useful one: could we prove it, specifically and quickly, to whoever just asked.
The gap that’s easy to miss
There’s a distinction that gets lost in most security conversations: the gap between having reasonable controls and being able to produce specific, current, documented evidence of them. Most mid-market organisations we talk to have the former. Fewer have the latter ready to hand when it’s actually asked for.
That distinction used to matter less. A board could be reassured by a confident description, “we’ve got MFA, we review access periodically, we take this seriously” and move on.
Why this matters more than it used
That’s changing, from several directions at once.
Insurers are pricing premiums against evidence of specific controls, not general assurances. Regulators across sectors have shifted from issuing guidance to actively enforcing it.
Funders and grant-makers are asking for cyber attestations alongside financial reporting. Boards and trustees are being told, increasingly explicitly, that awareness of a risk isn’t the same as demonstrating that it’s managed.
It’s an evidence problem, not a security problem
The organisations caught out by this shift aren’t usually the ones with bad security. They’re the ones who can describe their posture accurately but can’t produce it, a documented, specific, current answer, quickly enough when someone finally asks.
That’s an evidence problem more than a security problem, and it’s a solvable one.
What closes the gap
Two things typically do it. The first is a baseline review of identity and device security against a recognised standard – where are the gaps in multi-factor authentication, conditional access, and security policy, mapped specifically rather than described generally.
The second is a compliance-side review: a clear strategy for how sensitive data is labelled, how data-loss-prevention policies are applied, and how retention schedules align with data protection obligations.
Together, these produce something a description never can: a paper trail.
None of this requires assuming your controls are inadequate
Instead it requires assuming that, at some point soon, someone is going to ask you to prove them, and building the evidence before that conversation happens rather than during it. Ekco’s M365 Security Baseline Assessment and Purview Compliance Assessment are built to do exactly that, typically within a week combined.
The goal isn’t to become more secure than you already are. It’s to be able to prove, specifically and quickly, what’s already true.
And why not sign up for our short webinar series on how to get AI-Ready?
Four short webinars available to watch live or on demand after each session.
Question?
Our specialists have the answer
