Skip to content
Saturday 15 August 2026London --:--Frankfurt --:--Zurich --:--
NewslettersSearchEN · DE
MorningWire

European business, markets and politics

FTSE 100
10,750.11
-0.21%
DAX
26,440.31
+0.53%
CAC 40
8,636.80
-0.16%
STOXX 50
6,539.59
-0.09%
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
More
GermanyFranceBankingAIEnergyFintechPropertyCapital Markets
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
  • DE
Thursday 16 May 2019 11:32 am  |  Updated:  Wednesday 05 June 2019 8:46 am

Cyber security solutions that are only 95 per cent effective are just not good enough anymore

The cyber security industry is failing businesses. Cyber criminals are constantly evolving and evading the market’s most sophisticated detection-based security solutions, with government figures showing that 32 per cent of UK businesses have faced a cyber attack or data breach in the past year.

Most security solutions take a “best endeavour” approach to defending against threats – offering little more than 95 per cent protection at best.

We wouldn’t satisfy ourselves with a seatbelt that worked 95 per cent of the time, nor a front-door lock that could be opened five times in 100. Yet in a world where data is the new currency and consumers vote with their feet, the cyber security industry appears to expect its customers to introduce that level of risk into their organisation.

Read more: Face off: iProov's facial verification system lets you prove who you are

I know the issue first-hand. In a previous role, I had to explain to a US Fortune 30 brand why it had suffered multiple breaches over a three-month period, despite being told that it had the best detection capability that money could buy.

In response, one board member simply said, “Dan, this best endeavour approach to detection gives us unquantifiable business risk – that’s unacceptable to our shareholders”.

He was right – it is unacceptable. Yet most companies seem resigned to accepting this risk for their own business and customers.

As it stands, there is very little incentive for the industry to do better. The cyber security market is expected to reach $300bn by 2024, with providers making a lot of money from selling fallible, sub-par solutions.

That’s not because 100 per cent secure solutions are not possible – indeed, we’ve proven that they are. By moving away from the traditional detection-based approach, new and wholly effective attack-prevention systems can and are being created.

Read more: Bank of England director calls for 'collective solution' to cyber threats

But we will only reach the tipping point where businesses reject the mantra that “95 per cent secure is good enough” when they start to feel the repercussions beyond an initial breach. Insurers and government watchdogs must step away from the culture of “best endeavours” and hold businesses accountable when they are breached due to the use of fallible solutions.

There are plenty of examples of this, going back as far as 2015, when a complaint was filed against California healthcare provider, Cottage Health System, by its cyber insurer, after it was discovered that it hadn’t met the “minimum required practices” when it had been breached.

Insurers and watchdogs must go further and make it clear that they will not pay out when companies have knowingly introduced the unquantifiable risk of sub-par security into their business.

Indeed, only when businesses understand that they are being failed by their security providers, and are being penalised as a result, will there be enough uproar to force the cyber security industry to shift away from improving fallible technology and towards finding novel solutions that truly prevent attacks.

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News
  • Opinion

Categories

  • Business
  • Opinion
  • Tech

Related Topics

  • Bank of England

Trending Articles

  • Revolut takes flight with launch of new airport lounges

  • Grandparents fund university degrees to avoid inheritance tax net

  • Revolut chatbot goes rogue by charging users to cancel subscription

  • Brompton Bicycle sues former adviser for ‘professional negligence’

  • As It Happened: Stocks dip as oil’s ‘slowing demand’ in focus; Iran threatens to extend war

More from Morning Wire

  • AI gold rush leaves accountancy firms exposed to costly cyberattacks

    AI
    Two tablets displaying code and a cyber warning symbol, with blurry blue and pink background numbers
  • UK government probes OpenAI breach after ‘unprecedented’ hack

    Tech
    Sam Altman discussing OpenAIs ChatGPT advancements at a press conference, emphasizing AI innovation and future developments
  • Accertify and Liminal Release First Empirical Study Proving Fraud-Cyber Convergence Works – and Defining How to Do It Right

    Business Wire
  • U.K. Firms Make Cyber Resilience Measurable

    Business Wire
  • Wasabi and Megaport Partner to Advance the Next Generation of AI and Cloud Infrastructure

    Business Wire
  • AI, drones and data: Defence giants splash record $4.1bn on tech start-ups

    Tech
    Defence
  • UK’s AI watchdog flags new OpenAI and Anthropic cyber alarms

    AI
    Smartphone displaying the Claude by Anthropic AI assistant app, showing the app icon and interface.
  • M&S to face shareholder grilling over cyber attack recovery

    Retail
    Marks and Spencer was one of three UK retailers to be targeted
MorningWire

Independent European business, markets and political news for decision-makers.

Morning Briefing

Europe

  • Germany
  • France
  • Europe
  • UK & Ireland

Business

  • Markets
  • Banking
  • Technology
  • Energy
  • Property
  • Fintech

Editorial

  • Opinion
  • Editorial Policy
  • Corrections
  • Contact

Company

  • About Morning Wire
  • Privacy Policy
  • Terms of Use
  • Cookie Policy
© 2026 Morning Wire Ltd · Published by Morning Wire Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
Privacy · Terms · Cookies · Facebook