Defender's Dilemma: Why IT Teams Must Move Beyond Antivirus

Protect your business from cyber attacks by adopting a proactive security posture.

As the digital world evolves at breakneck speed, cyber threats are keeping pace — and becoming more frequent. For example, in 2024, half of all UK businesses reported a cyber attack or security breach, a sharp rise from 39% in 2022. And unfortunately, the odds are stacked in the attackers’ favour – a perfect example of the defender’s dilemma.

The defender’s dilemma states that breaches are inevitable because defenders have to be right 100% of the time, while attackers only need to be right once.”

This imbalance is known as the defender’s dilemma, where attackers succeed once while defenders must stay vigilant. All it takes is one mistake for an attacker to access your system. This could be a clicked phishing link or an approved malicious prompt. This makes it less a question of if a breach will happen, and more a matter of when.

However, a lot of organisations still lean on traditional tools like antivirus software as their primary defence against cyber threats. The problem? When something does get through, there’s no visibility or warning until it’s too late and the damage is already done.

So, what’s the better approach to take?

There are many cyber security tools available, but building a strong defence strategy is still challenging. It means layering different elements together, preparing to respond when attacks happen, and much more. If you’re not sure what you need or where to start, it can get overwhelming quickly.

Fortunately, this is where the NIST Cyber Security Framework (CSF) comes into play.

NIST: a framework for cyber security

First introduced by the National Institute of Standards and Technology (NIST) in 2014, the NIST CSF offers practical guidelines and best practices to help organisations reduce cyber security risk.

The latest version, NIST CSF 2.0, was released in February 2024. It broadens the framework’s focus beyond Critical National Infrastructure, making it much more accessible to businesses of all sizes and industries. It does this by adding practical resources like profiles, example controls, and clearer guidance to help with implementation.

As a result, the updated NIST framework is trusted by organisations of all sizes because of its flexible and simple approach. (Including us here at Bistech!).

NIST CSF 2.0 introduces six core functions (up from five in version 1.0):

An illustration of the six core functions of NIST: govern, identify, protect, detect, respond, and recover.

We’ll break down each function in more detail below.

Govern

An image of a gavel representing the 'Govern' section of the NIST, surrounded by the following features: - Role assignment - Risk alignment - Policy development - Oversight mechanisms

A strong cyber security strategy extends beyond the IT department and must be part of the entire organisation.

The Govern function of the NIST CSF lays the foundation for how cyber security is managed at a strategic level. It shapes how your organisation sets its risk management strategy, defines expectations, and creates policies. In short, it sets the tone for everything else.

Here’s what the Govern function covers:

  • Understanding your mission, stakeholder needs, legal obligations, and operational environment.
  • Creating and maintaining policies and processes to identify, assess, and manage risk, as well as aligning them with your broader enterprise risk strategy.
  • Managing supply chain risks, including oversight of vendors and third parties.
  • Clearly defining cyber security roles and responsibilities at all levels, especially within leadership.
  • Enforcing, reviewing, and regularly updating governance structures.
  • Monitoring performance, conducting audits, and driving continuous improvement in your cyber security programme.

Identify

An image of a magnifying glass representing the 'Identify' section of the NIST, surrounded by the following features: - Asset inventory - Risk assessments - Risk strategy - Business context

Most businesses lack a full inventory of connected devices, from thermostats to entry systems and sensors. Full visibility is essential for a strong security posture and must come first.

The Identify layer focuses on laying the groundwork for effective risk management by helping an organisation understand itself: its assets, people, environment, risk tolerance, and vulnerabilities. If Govern is the strategy, Identify is the map. Strengthening the Identify function helps reduce the defender’s dilemma by giving you a clear view of what needs protection and where your biggest risks lie.

The core areas within Identify include:

  • Create an inventory of your physical and software assets. Map data flows and classify assets by importance.
  • Identify threats and vulnerabilities, then link them to your key business objectives.
  • Continuously evaluating internal and external risks, including the likelihood of events and their potential consequences.
  • Understanding the company’s mission, goals, stakeholders, and place in the supply chain, then aligning cyber security efforts with the broader business strategy.

Protect

This defender's dilemma image is of a shield representing the 'Protect' section of the NIST, surrounded by the following features: - Access control - Data protection - Security training - Protective technology

It’s often said that “prevention is better than cure,” and that’s exactly what the Protect layer is about — putting safeguards in place to help prevent cyber security incidents before they happen. This layer plays a key role in reducing the impact of defender’s dilemma by making it harder for attackers to find an initial foothold.

Some of the Protect layer’s core aspects include:

1. Antivirus

Next-generation antivirus (AV) vendors can leverage the cloud to spot unusual behaviour using AI and machine learning. This forms a sound basis, but as these tools still rely on known tactics, techniques, and procedures, you need to implement additional layers for full protection.

2. Firewall

Firewalling is the next logical layer. Typically protecting the environment from the network edge, firewall solutions have evolved from the straightforward block / allow list and now permit traffic based on identity, application, and job role, with some even analysing traffic as it flows through the firewall itself.

3. Email filtering

Email is the starting point for 94% of all breaches, and it’s not hard to see why — email addresses are often public or easy to guess, and they usually lead straight to the intended target. As such, email filtering is another key layer to include.

4. Multi-Factor Authentication

Multi-Factor Authentication (MFA) and Two-Factor Authentication (2FA) significantly increase the difficulty of hacking; in fact, it’s estimated that 80% of breaches could have been stopped with the use of MFA or 2FA. They offer impressive value for money and are often bundled with other licences.

5. Employee awareness

It’s easy to forget that employees can be one of your strongest lines of defence when it comes to cyber security. With regular awareness and training sessions, your team can act as a ‘human firewall’, spotting suspicious behaviour or subtle red flags that automated tools might miss, like emotional or out-of-character language designed to trick someone into clicking a link.

Detect and Respond: Overcoming the Defender’s Dilemma

This defender's dilemma image is of a target representing the 'Detect' and 'Respond' sections of the NIST, surrounded by the following features: - Anomaly detection - Stakeholder communication - Incident analysis - Continuous monitoring

The defender’s dilemma is clear here. Detect and Respond functions help shift this dynamic by identifying threats early. Identifying and stopping threats early helps organisations move from a reactive stance to a proactive one. This boosts security while saving you time, cutting costs, and safeguarding your reputation.

Here’s a look at some of the key options that help build this extra layer of defence:

1. Security Information and Event Management (SIEM)

Security Information and Event Management (SIEM) systems collect logs from various sources across a network, including:

  • Firewalls
  • Intrusion detection/prevention systems (IDS/IPS)
  • Servers
  • Applications
  • Endpoints (eg, user devices)

Many organisations use SIEM for data retention, but without reviewing the data, its value for detection is limited. However, if a breach does occur, having all the logs in one place can make a big difference. It gives the incident response team quicker access to the information they need, which can help contain the damage and reduce overall costs.

2. Security Orchestration, Automation, and Response (SOAR)

Next‑gen SIEM solutions paired with SOAR improve compliance and strengthen threat detection. These solutions can group alerts from different applications and devices into a single incident, with some even offering limited integration with a company’s existing security stack.

3. Endpoint Detection and Response (EDR)

The downside to SIEM and SOAR is their high cost. For companies where compliance isn’t the main priority, Endpoint Detection and Response (EDR) offers a more cost-effective alternative.

EDR works by leveraging the AV agent on the endpoint, adding just an extra layer to the existing license. The agent then streams data to a centralised database, where it’s stored and can be accessed for retrospective analysis.

4. Extended Detection and Response (XDR)

Extended Detection and Response (XDR) goes beyond traditional EDR by integrating cloud, network, and firewall protections. It’s similar to SIEM and SOAR but offers more flexibility, allowing dynamic firewall rule updates and the ability to isolate users as part of its response.

5. Security Operations Centre (SOC)

These tools can help detect threats earlier, but the data must be actively analysed to be effective. This process, known as ‘threat hunting,’ involves spotting unusual behaviour and searching for Indicators of Compromise (IOCs) within historical data — a key strategy for businesses to level the playing field against network attackers.

However, the reality is that most businesses don’t have an internal SOC, and the tools required can be costly, making this combination out of reach for many. That’s where Managed Detection and Response (MDR) steps in.

6. Managed Detection and Response (MDR)

MDR involves outsourcing the combined Detect and Respond functions to experts who handle alerts, investigate incidents, and help with remediation when needed. By leveraging automation and scaling their infrastructure, MDR providers can deliver the same results at a more affordable price.

Recover

An image of a circular arrow representing the 'Recover' section of the NIST, surrounded by the following features: - Recovery execution - Stakeholder coordination - Strategy updates -Continuity planning

Failing to prepare for a cyber attack can be catastrophic for a business. A 2024 report by Cybereason, which surveyed companies impacted by ransomware, made this clear:

  • 84% paid the ransom, but only 47% got their data back uncorrupted.
  • 46% estimate business losses of $1-10 million, and 16% estimate losses of over $10 million.
  • 78% of those who paid a ransom were targeted again, and 63% of these were asked to pay more the second time.
  • 87% increased their cyber security spend after a breach, but only 41% felt they had the right people and plan to manage the next attack.

These figures show how damaging poor recovery planning can be

In theory, it’s easy to say a business should never pay a ransom — after all, no one wants to fund cyber criminals. But when you’re actually in that situation, faced with the choice of paying up or losing critical data and starting from scratch, the decision suddenly becomes a lot more complicated.

The Recover layer helps your organisation avoid the difficult decision of paying a ransom during a ransomware attack (or losing data to an accident or natural disaster). It ensures you can quickly get back to business after a cyber security incident or disruption by:

  • Create and maintain Business Continuity and Disaster Recovery plans to restore systems after an incident. This includes having experts forensically examine affected systems to understand the incident’s details and timeline, giving your team the info needed to recover and address any necessary remediation.
  • Review your recovery processes often and use past incidents to improve resilience and response.
  • Keep teams, customers, and partners informed during recovery to maintain transparency and trust.

Getting serious about cyber security

Cyber security is hard to navigate, even with a CSF, and the lack of in‑house expertise makes it tougher. If you want to protect your brand reputation, prevent costly data and revenue loss, and avoid potential fines, working with a trusted cyber security specialist is the way to go.

At Bistech, we take a personalised, multi-layered approach to security, helping you protect, detect, and respond to evolving cyber threats so your business can effectively overcome the defender’s dilemma. If you are ready to proceed, book a call with us today.

 

Book a call today


Shaun Farrow, Practice Lead

Shaun Farrow works with customers to strengthen their cyber security posture, combining hands-on engineering expertise with a consulting approach. He leads the growth and direction of Bistech Managed Security, supporting solution design and translating complex challenges into clear, practical guidance. Shaun focuses on security, governance, risk and compliance, and how frameworks such as NIST CSF v2 support informed, senior-level cyber security decisions.