The Pulse

The official blog of Sentinel Technologies

What Hundreds of Security Assessments Taught Me About the Hidden Cost of "It's Deployed"

Tue August 25, 2026

By Mark Combs, Sentinel’s National Director of Enterprise Architecture and Innovation

Organizations continue to invest millions of dollars in cybersecurity technologies. Firewalls, Endpoint Detection and Response (EDR), Identity and Access Management (IAM), Secure Email Gateways, Security Information and Event Management (SIEM), vulnerability scanners, cloud security tools, and countless other security controls are deployed with the expectation that they will stop attacks before they become business-impacting events.

But here's the bigger issue I now see with customers:

Organizations are facing a widening gap between attacker decision speed and defender decision speed.

AI-assisted attackers can move from reconnaissance to attack-path discovery to exploitation faster than most organizations can validate exposure, make a risk decision, contain an incident, or prove recovery. The problem is no longer just whether a tool is deployed. The problem is whether the organization can make the right security and business decision fast enough.

The real question isn't whether your firewall is working. The real question is whether an attacker could use a series of seemingly minor weaknesses to disrupt a critical business service: payroll, manufacturing, ERP, supply chain, clinical operations, or revenue systems.

How do you know those investments are protecting your business today—not when they were deployed, not after the implementation project was completed, and not when the vendor demonstrated the product in a lab?

Too often, the first indication that a security control has failed isn't a security alert—it's an employee staring at a ransomware message on their screen or calling the help desk. By then, the conversation has already shifted from prevention to incident response.

Forrester frames today’s cyber environment as a relentless, AI-fueled arms race, pushing leaders to ask not only “How secure are we?” but whether the organization is resilient enough to withstand the next wave.

The Hidden Cost of Security

When organizations think about cybersecurity risk, they often think about the financial impact of a breach. While that cost can be significant, there is another cost that is rarely discussed: the cost of not knowing whether your security controls are functioning as intended.

Failure doesn't always mean your firewall stops passing traffic or your EDR console suddenly goes offline. Sometimes failure is much quieter.

  • An endpoint agent silently stops reporting.
  • A rebuilt system is missing critical security software.
  • A firewall rule opened during a troubleshooting exercise is never removed.
  • An access control list remains more permissive than anyone realizes.
  • A security policy is modified to solve an immediate operational issue but is never restored to its intended state.

None of these issues trigger headlines on their own, but together they create the conditions attackers are looking for.

Most major incidents do not originate from a single vulnerability. They emerge from attack paths that connect identities, applications, cloud services, misconfigurations, trusted relationships, and operational exceptions that were never meant to become permanent.

What Hundreds of Security Assessments Have Taught Me

During my 17 years at Sentinel Technologies conducting hundreds of Zero Trust security assessments and penetration tests, I've noticed a consistent pattern. Most organizations don't fail because they purchased the wrong technology. They fail because the technology they invested in slowly drifts away from its intended state.

As environments evolve, security configurations drift, exceptions accumulate, and temporary workarounds become permanent.

  • New systems and applications that were never fully integrated into security monitoring, endpoint protection, or identity governance.
  • Legacy services unintentionally re-enabled after systems were reimaged.
  • Firewall or ACL rules temporarily opened for troubleshooting but never removed.
  • Endpoint security agents that are no longer installed, communicating, or properly configured.
  • Security controls operating in monitor-only mode after configuration changes or software upgrades.
  • Security controls that exist on paper but are no longer protecting the environment as intended.
  • Security policies intentionally bypassed to support business operations but never restored.

Just as concerning is what we often don't find:

  • An up-to-date Business Continuity Plan (BCP).
  • A recent Business Impact Analysis (BIA).
  • Defined and tested Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).
  • A known and validated Mean Time to Recovery (MTTR).
  • Evidence that backups are immutable and recoverable following a ransomware event.

Business continuity and cyber resilience are no longer separate conversations from cybersecurity. They are fundamental components of exposure management.

Attackers don't just exploit vulnerabilities—they exploit an organization's inability to recover. Recovery is now a competitive advantage. Organizations that can rapidly validate identity recovery, data integrity, and business process restoration reduce both operational disruption and financial impact. The organizations that recover the fastest are often not those with the fewest vulnerabilities, but those that continuously validate both their security controls and their ability to restore critical business operations.

Forrester’s Zero Trust threat detection and response research emphasizes swift, informed action and operational resilience as core requirements for security leaders, not secondary outcomes after an incident occurs.

What This Means Going Forward

The pattern above, technology quietly drifting out of its intended state while the org still believes it's protected, is what makes the next problem so urgent. AI is now closing the gap between when a weakness appears and when an attacker finds it. That's the subject of the next post in this series: how AI has changed the equation, and what it means to move from counting vulnerabilities to continuously validating exposure.


The problem is not that your organization lacks the proper security tools, but rather a way to continuously verify those tools are still doing what they were deployed to do. That's exactly the gap a PenGuardian assessment is built to close: not a point-in-time scan, but ongoing, autonomous validation that proves your defenses are working today, not just the day they were installed.

GET A PENGUARDIAN ASSESSMENT