{"id":11774,"date":"2026-03-05T11:00:25","date_gmt":"2026-03-05T11:00:25","guid":{"rendered":"https:\/\/www.withsecure.com\/?p=11774"},"modified":"2026-06-04T06:40:59","modified_gmt":"2026-06-04T05:40:59","slug":"why-reactive-security-no-longer-works-and-what-to-do-about-it","status":"publish","type":"post","link":"https:\/\/www.withsecure.com\/en\/resources-hub\/blog\/why-reactive-security-no-longer-works-and-what-to-do-about-it\/","title":{"rendered":"Why reactive security no longer works \u2013 and what to do about it"},"content":{"rendered":"<section\n    class=\"wp-block-one-column-block edwp-block js-wp-block-one-column-block wp-block-one-column-block--content-1 layout--spacing-xxxl-top layout--spacing-xxxl-bottom\"\n    >\n    <div class=\"wp-block-one-column-block__container\">\n                                                                                                                            <div class=\"wp-component-content wp-component-content--default wp-block-one-column-block__content fade-in\">\n            <h1 class=\"wp-component-heading text--h2 wp-component-content__title\">\n    Why reactive security no longer works \u2013 <span class=\"blue-text\">and what to do about it<\/span><\/h1>                    <div class=\"wp-component-content__inner\">\n                                                    <div class=\"wp-component-content__meta\">\n                                                                            <span class=\"wp-component-content__meta-categories\">\n                                                                    <span class=\"wp-component-content__meta-category\">\n                                        AI                                    <\/span>\n                                                                    <span class=\"wp-component-content__meta-category\">\n                                        MSP                                    <\/span>\n                                                                    <span class=\"wp-component-content__meta-category\">\n                                        Proactive security                                    <\/span>\n                                                            <\/span>\n                                                                                                    <span class=\"wp-component-content__meta-date\">\n                                05 March, 2026                            <\/span>\n                                                                    <\/div>\n                                            <\/div>\n                <\/div>                                                                            <div class=\"wp-component-image__wrapper wp-block-one-column-block__image fade-in\">\n                    <figure class=\"wp-component-image__figure\">\n                                            <img loading=\"lazy\" decoding=\"async\" width=\"1920\" height=\"1080\" src=\"https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/06\/Co-security-services-ArcticMountains.webp\" class=\"wp-component-image\n                            wp-component-image--desktop\n                            wp-component-image--mobile\n                            wp-component-image--ratio-content-25-1 wp-component-image--fit-cover\" alt=\"\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/06\/Co-security-services-ArcticMountains.webp 1920w, https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/06\/Co-security-services-ArcticMountains-300x169.webp 300w, https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/06\/Co-security-services-ArcticMountains-1024x576.webp 1024w, https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/06\/Co-security-services-ArcticMountains-768x432.webp 768w, https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/06\/Co-security-services-ArcticMountains-1536x864.webp 1536w, https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/06\/Co-security-services-ArcticMountains-447x251.webp 447w, https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/06\/Co-security-services-ArcticMountains-700x394.webp 700w, https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/06\/Co-security-services-ArcticMountains-260x146.webp 260w\" sizes=\"auto, (max-width: 1920px) 100vw, 1920px\" \/>                                                    <\/figure>\n                    <\/div>\n                                                                                <\/div>\n<\/section>\n\n\n<section\n    class=\"wp-block-one-column-block edwp-block js-wp-block-one-column-block wp-block-one-column-block--content-5 layout--spacing-xl-bottom\"\n    >\n    <div class=\"wp-block-one-column-block__container\">\n                                                                                                                            <div class=\"wp-component-paragraph wp-block-one-column-block__paragraph fade-in\">\n    <p class=\"text--p-medium\">Our attack surface has never been larger. In the span of just a few years, organizations have moved from on-premises infrastructure to cloud, layered on dozens of SaaS services, and are now deploying AI on top of all of it \u2013 with AI agents talking to other AI agents, making decisions faster than any human reviewer can track. The perimeter, as a concept, is largely gone.<\/p>\n<p>And yet, according to a recent information security survey*, only 26% of organizations feel fully prepared for today&#8217;s cyber threats while 70% of ICT decision-makers say they are worried. Something does not compute.<\/p>\n<p>At our February 2026 Cyber Morning event, we dug into why so many organizations remain stuck in reactive mode \u2013 and what it actually takes to change that.<\/p>\n<h2 class=\"text--h6\">The Root Cause: Resources, Not Awareness<\/h2>\n<p>A common assumption is that organizations are reactive because they don&#8217;t understand the threats. However, for example in Finland, a significant amount of information about the changing threat landscape is being shared with Finnish organizations \u2013 yet breaches still happen. The more honest explanation, in most cases, is resources.<\/p>\n<p>Security budgets in small and medium-sized organizations are often fixed at a point in time and then left unchanged. A firewall gets deployed. It works. Nobody revisits it. The result is that the most common vulnerability pattern seen in breach investigations is the same year after year: an old edge device, unpatched, running an outdated firmware version sitting at the boundary of the organization with its own IP address, open to the internet, being probed automatically around the clock.<\/p>\n<p>A significant portion of organizations across Finland and the wider Nordics are still running basic EPP (endpoint protection) products. These tools offer some protection, but they were not designed for the threat landscape of 2026. Running basic EPP today is a bit like locking your front door but leaving the windows open.<\/p>\n<p>There is also a dangerous false assumption at play. Many mid-market companies believe they are not interesting targets \u2013 that attackers would not bother with them because they have nothing of particular value. This is simply wrong. Attackers think in economic terms. If a threat actor spends \u20ac1 million to execute an attack and collects \u20ac10 million in ransom, the gross margin is exceptional. Organizations do not need to be strategically important to be financially attractive.<\/p>\n<h2 class=\"text--h6\">Every Organization Will Be Attacked<\/h2>\n<p>Every organization will be attacked, one way or another. The question is not whether it will happen but how prepared you are when it does.<\/p>\n<p>This reframe matters enormously for how organizations budget, plan, and prioritize. Security is not a problem you solve once. It is a discipline you maintain continuously. The threat landscape evolves \u2013 AI is now being used by attackers to probe and exploit systems at a speed and scale no human attacker could match. A device that was reasonably safe two years ago may now be trivially compromised by an automated agent within hours of a new vulnerability becoming known.<\/p>\n<p>Finnish telecom company DNA has taken this seriously at the infrastructure level. It now includes three years of automated security patching as standard with every Wi-Fi router it sells to home customers \u2013 because a five-year-old home router with no firmware updates is not just an individual problem. As an operator, DNA sees itself as the first line of defense for Finnish society, since every cyber attack ultimately travels through their network. Whatever can be blocked at that level protects everyone downstream.<\/p>\n<p>This is the kind of thinking that separates reactive from proactive security: designing systems so that secure behavior becomes the default path, not something that depends entirely on individual vigilance.<\/p>\n<h2 class=\"text--h6\">What Proactive Security Actually Means in Practice<\/h2>\n<p>Here are concrete first steps for moving from reactive to proactive cybersecurity, drawn from our Cyber Morning panelists:<\/p>\n<p>Niko Isotalo, Regional VP North, WithSecure: Start by understanding your risks \u2013 specifically, what your most valuable assets are and what threatens them. Not risk in the abstract, but the concrete question of which parts of your business would cause the most damage if compromised. Do that assessment continuously, because the answer changes as your business changes and as the threat landscape shifts.<\/p>\n<p>Jussi Tolvanen, CEO, DNA: Build the capabilities and find the right partners. Mid-market organizations cannot afford to operate a full security operations center in-house. Nor should they need to. Managed security providers exist precisely to offer those capabilities as a shared resource. The hidden cost of reactive security is not just the breach itself \u2013 it is the absence of monitoring, detection, and response capability that would have caught the attack earlier, at lower cost.<\/p>\n<p>Anssi K\u00e4rkk\u00e4inen, Head of the National Cyber Security Centre, Traficom: Follow the changes in the threat landscape. Resources like Traficom&#8217;s Cyber Weather publish regular updates on what is actively being exploited. There is no excuse for being surprised by threat patterns that are publicly documented.<\/p>\n<p>Christine Bejerasco, CISO, WithSecure: Know your external exposures. An unpatched device inside your network perimeter is a risk. An unpatched edge device facing the open internet, in the age of AI-powered automated scanning, is an active liability.<\/p>\n<h2 class=\"text--h6\">The MSP Opportunity: From Reactive Vendor to Proactive Security Partner<\/h2>\n<p>For Managed Service Providers, this picture is both a challenge and a significant opportunity. Most mid-market organizations are not inadequately protected because they don&#8217;t care. They are inadequately protected because they don&#8217;t know what proactive security looks like in practice \u2013 and they lack the in-house resources to build it themselves.<\/p>\n<p>This is the gap MSPs are uniquely positioned to fill. WithSecure&#8217;s research shows that 82% of customers want a single security partner who can cover all solutions, expertise, and services. Providing continuous monitoring and threat detection that mid-market customers cannot staff internally, translating threat intelligence into actionable guidance, managing patching and exposure across the customer estate, and helping customers rehearse incident response before a crisis hits \u2013 done well, this is not a commodity service. It is a genuine security uplift, and increasingly, it is exactly what NIS2 compliance requires.<\/p>\n<p>The organizations that cannot yet answer &#8220;what are our crown jewels, and how exposed are they right now?&#8221; are the ones that need a proactive partner most urgently. And for MSPs building towards higher-value managed security services, those are exactly the customers worth having the conversation with.<\/p>\n<p>*Source: Telenor Nordic Digital Security Report 2025: <a href=\"https:\/\/www.telenor.com\/binaries\/who-we-are\/our-companies\/nordics\/digitalsecurity\/2025\/Telenor_security_report_2025_Nordic.pdf\" target=\"_blank\" rel=\"noopener\">telenor.com<\/a><\/p>\n<\/div>\n                                                                                <\/div>\n<\/section>\n\n\n<section\n    class=\"wp-block-sharing-icons edwp-block wp-block-sharing-icons--content-5 layout--spacing-xxxl-bottom\"\n    >\n    <div class=\"wp-block-sharing-icons__container\">\n        <div class=\"wp-block-sharing-icons__inner\">\n                            <p class=\"wp-block-sharing-icons__title fade-in\">\n                    Share this story                <\/p>\n                        <div class=\"wp-component-socials wp-component-socials--dark-mode\">\n    \n            <a href=\"https:\/\/www.linkedin.com\/shareArticle?mini=true&#038;url=https:\/\/www.withsecure.com\/en\/resources-hub\/blog\/why-reactive-security-no-longer-works-and-what-to-do-about-it\/&#038;title=Why%20reactive%20security%20no%20longer%20works%20\u2013%20and%20what%20to%20do%20about%20it\" target=\"_blank\" rel=\"noreferer noopener\" class=\"wp-component-socials__link\" title=\"Share on Linkedin\">\n            <svg class='edwp-icon edwp-icon--xlg js-icon ' aria-hidden='true'>\n                <use xlink:href='#linkedin'><\/use>\n            <\/svg>        <\/a>\n    \n            <a href=\"http:\/\/x.com\/share?text=Why reactive security no longer works \u2013 and what to do about it&#038;url=https:\/\/www.withsecure.com\/en\/resources-hub\/blog\/why-reactive-security-no-longer-works-and-what-to-do-about-it\/\" target=\"_blank\" rel=\"noreferer noopener\" class=\"wp-component-socials__link wp-component-socials__link--twitter\" title=\"Share on Twitter\">\n            <svg class='edwp-icon edwp-icon--xlg js-icon ' aria-hidden='true'>\n                <use xlink:href='#x'><\/use>\n            <\/svg>        <\/a>\n    \n    \n    <\/div>\n        <\/div>\n    <\/div>\n<\/section>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":15,"featured_media":11776,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[428,124,34],"tags":[],"content_type":[],"class_list":["post-11774","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai","category-msp","category-proactive-security"],"acf":[],"card":"<div class=\"wp-component-card-insight js-card-link wp-component-card-insight--highlighted\">\n    <div class=\"wp-component-card-insight__image-wrapper\">\n        <img width=\"1920\" height=\"1080\" src=\"https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/06\/Co-security-services-ArcticMountains.webp\" class=\"wp-component-card-insight__image\" alt=\"\" decoding=\"async\" loading=\"lazy\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/06\/Co-security-services-ArcticMountains.webp 1920w, https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/06\/Co-security-services-ArcticMountains-300x169.webp 300w, https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/06\/Co-security-services-ArcticMountains-1024x576.webp 1024w, https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/06\/Co-security-services-ArcticMountains-768x432.webp 768w, https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/06\/Co-security-services-ArcticMountains-1536x864.webp 1536w, https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/06\/Co-security-services-ArcticMountains-447x251.webp 447w, https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/06\/Co-security-services-ArcticMountains-700x394.webp 700w, https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/06\/Co-security-services-ArcticMountains-260x146.webp 260w\" sizes=\"auto, (max-width: 1920px) 100vw, 1920px\" \/>                    <p class=\"wp-component-card-insight__content-type\">Blog<\/p>\n            <\/div>\n    <div class=\"wp-component-card-insight__content\">\n                    <div class=\"wp-component-card-insight__meta\">\n                <div class=\"wp-component-card-insight__categories\">\n                                            <span class=\"wp-component-card-insight__category\">AI<\/span>\n                                            <span class=\"wp-component-card-insight__category\">MSP<\/span>\n                                            <span class=\"wp-component-card-insight__category\">Proactive security<\/span>\n                                    <\/div>\n            <\/div>\n                            <h3 class=\"wp-component-card-insight__title\">Why reactive security no longer works \u2013 and what to do about it<\/h3>\n                                                    <div class=\"wp-component-card-insight__button-wrapper\">\n                <a class=\"wp-component-button btn btn--primary btn--dark wp-component-card-insight__button btn--small\" href=\"https:\/\/www.withsecure.com\/en\/resources-hub\/blog\/why-reactive-security-no-longer-works-and-what-to-do-about-it\/\">Read more<\/a>            <\/div>\n            <\/div>\n<\/div>","_links":{"self":[{"href":"https:\/\/www.withsecure.com\/en\/wp-json\/wp\/v2\/posts\/11774","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.withsecure.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.withsecure.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.withsecure.com\/en\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/www.withsecure.com\/en\/wp-json\/wp\/v2\/comments?post=11774"}],"version-history":[{"count":4,"href":"https:\/\/www.withsecure.com\/en\/wp-json\/wp\/v2\/posts\/11774\/revisions"}],"predecessor-version":[{"id":11928,"href":"https:\/\/www.withsecure.com\/en\/wp-json\/wp\/v2\/posts\/11774\/revisions\/11928"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.withsecure.com\/en\/wp-json\/wp\/v2\/media\/11776"}],"wp:attachment":[{"href":"https:\/\/www.withsecure.com\/en\/wp-json\/wp\/v2\/media?parent=11774"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.withsecure.com\/en\/wp-json\/wp\/v2\/categories?post=11774"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.withsecure.com\/en\/wp-json\/wp\/v2\/tags?post=11774"},{"taxonomy":"content_type","embeddable":true,"href":"https:\/\/www.withsecure.com\/en\/wp-json\/wp\/v2\/content_type?post=11774"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}