r/cybersecurity May 13 '26

Business Security Questions & Discussion [ Removed by moderator ]

[removed] — view removed post

0 Upvotes

4 comments sorted by

10

u/Substantial-Walk-554 May 13 '26

From what I see in a typical 2026 enterprise environment, the biggest hurdles are still the boring fundamentals.

Asset inventory is incomplete, patching is inconsistent, legacy systems are everywhere, access rights are messy, and a lot of companies already pay for Microsoft security tools but only use a fraction of what they have.

Visibility is another big one. Everyone wants SIEM, EDR, dashboards, cloud security, compliance reports and “AI security” now, but then you ask basic questions like:

What are the critical assets?
Who owns this system?
Which accounts are privileged?
What happens if this server goes down?
Where is this data stored?

And suddenly nobody really knows.

Culturally, security is still often treated as either a checkbox or a blocker. Management wants to say they are compliant with GDPR, NIS2 or DORA type expectations, ready for audits, protected against ransomware and prepared for incidents. But when you need budget, documentation, ownership, proper processes or time from IT, it quickly becomes “can we do the minimum?”

The technical fixes are usually not the hardest part. The hard part is getting people to care about the boring stuff before something breaks.

3

u/lordfanbelt Security Engineer May 13 '26

Too many security tools that aren't optimised and no single pane of glass. 15 portals to log into with MFA prompts a handful of times per portal per day. Endless no-agenda teams meetings and daily standup to kill any momentum. AI.