26 August 2026 | By James Thomas
Four challenges every organisation must solve to adopt AI safely
Discover four key challenges affecting AI adoption and how organisations can build confidence in their approach.
Read moreAs the digital world evolves at breakneck speed, cyber threats are keeping pace — and becoming more frequent. For example, in 2024, half of all UK businesses reported a cyber attack or security breach, a sharp rise from 39% in 2022. And unfortunately, the odds are stacked in the attackers’ favour – a perfect example of the defender’s dilemma.
“The defender’s dilemma states that breaches are inevitable because defenders have to be right 100% of the time, while attackers only need to be right once.”
This imbalance is known as the defender’s dilemma, where attackers succeed once while defenders must stay vigilant. All it takes is one mistake for an attacker to access your system. This could be a clicked phishing link or an approved malicious prompt. This makes it less a question of if a breach will happen, and more a matter of when.
However, a lot of organisations still lean on traditional tools like antivirus software as their primary defence against cyber threats. The problem? When something does get through, there’s no visibility or warning until it’s too late and the damage is already done.
So, what’s the better approach to take?
There are many cyber security tools available, but building a strong defence strategy is still challenging. It means layering different elements together, preparing to respond when attacks happen, and much more. If you’re not sure what you need or where to start, it can get overwhelming quickly.
Fortunately, this is where the NIST Cyber Security Framework (CSF) comes into play.
First introduced by the National Institute of Standards and Technology (NIST) in 2014, the NIST CSF offers practical guidelines and best practices to help organisations reduce cyber security risk.
The latest version, NIST CSF 2.0, was released in February 2024. It broadens the framework’s focus beyond Critical National Infrastructure, making it much more accessible to businesses of all sizes and industries. It does this by adding practical resources like profiles, example controls, and clearer guidance to help with implementation.
As a result, the updated NIST framework is trusted by organisations of all sizes because of its flexible and simple approach. (Including us here at Bistech!).
NIST CSF 2.0 introduces six core functions (up from five in version 1.0):

We’ll break down each function in more detail below.

A strong cyber security strategy extends beyond the IT department and must be part of the entire organisation.
The Govern function of the NIST CSF lays the foundation for how cyber security is managed at a strategic level. It shapes how your organisation sets its risk management strategy, defines expectations, and creates policies. In short, it sets the tone for everything else.
Here’s what the Govern function covers:

Most businesses lack a full inventory of connected devices, from thermostats to entry systems and sensors. Full visibility is essential for a strong security posture and must come first.
The Identify layer focuses on laying the groundwork for effective risk management by helping an organisation understand itself: its assets, people, environment, risk tolerance, and vulnerabilities. If Govern is the strategy, Identify is the map. Strengthening the Identify function helps reduce the defender’s dilemma by giving you a clear view of what needs protection and where your biggest risks lie.
The core areas within Identify include:

It’s often said that “prevention is better than cure,” and that’s exactly what the Protect layer is about — putting safeguards in place to help prevent cyber security incidents before they happen. This layer plays a key role in reducing the impact of defender’s dilemma by making it harder for attackers to find an initial foothold.
Some of the Protect layer’s core aspects include:
Next-generation antivirus (AV) vendors can leverage the cloud to spot unusual behaviour using AI and machine learning. This forms a sound basis, but as these tools still rely on known tactics, techniques, and procedures, you need to implement additional layers for full protection.
Firewalling is the next logical layer. Typically protecting the environment from the network edge, firewall solutions have evolved from the straightforward block / allow list and now permit traffic based on identity, application, and job role, with some even analysing traffic as it flows through the firewall itself.
Email is the starting point for 94% of all breaches, and it’s not hard to see why — email addresses are often public or easy to guess, and they usually lead straight to the intended target. As such, email filtering is another key layer to include.
Multi-Factor Authentication (MFA) and Two-Factor Authentication (2FA) significantly increase the difficulty of hacking; in fact, it’s estimated that 80% of breaches could have been stopped with the use of MFA or 2FA. They offer impressive value for money and are often bundled with other licences.
It’s easy to forget that employees can be one of your strongest lines of defence when it comes to cyber security. With regular awareness and training sessions, your team can act as a ‘human firewall’, spotting suspicious behaviour or subtle red flags that automated tools might miss, like emotional or out-of-character language designed to trick someone into clicking a link.

The defender’s dilemma is clear here. Detect and Respond functions help shift this dynamic by identifying threats early. Identifying and stopping threats early helps organisations move from a reactive stance to a proactive one. This boosts security while saving you time, cutting costs, and safeguarding your reputation.
Here’s a look at some of the key options that help build this extra layer of defence:
Security Information and Event Management (SIEM) systems collect logs from various sources across a network, including:
Many organisations use SIEM for data retention, but without reviewing the data, its value for detection is limited. However, if a breach does occur, having all the logs in one place can make a big difference. It gives the incident response team quicker access to the information they need, which can help contain the damage and reduce overall costs.
Next‑gen SIEM solutions paired with SOAR improve compliance and strengthen threat detection. These solutions can group alerts from different applications and devices into a single incident, with some even offering limited integration with a company’s existing security stack.
The downside to SIEM and SOAR is their high cost. For companies where compliance isn’t the main priority, Endpoint Detection and Response (EDR) offers a more cost-effective alternative.
EDR works by leveraging the AV agent on the endpoint, adding just an extra layer to the existing license. The agent then streams data to a centralised database, where it’s stored and can be accessed for retrospective analysis.
Extended Detection and Response (XDR) goes beyond traditional EDR by integrating cloud, network, and firewall protections. It’s similar to SIEM and SOAR but offers more flexibility, allowing dynamic firewall rule updates and the ability to isolate users as part of its response.
These tools can help detect threats earlier, but the data must be actively analysed to be effective. This process, known as ‘threat hunting,’ involves spotting unusual behaviour and searching for Indicators of Compromise (IOCs) within historical data — a key strategy for businesses to level the playing field against network attackers.
However, the reality is that most businesses don’t have an internal SOC, and the tools required can be costly, making this combination out of reach for many. That’s where Managed Detection and Response (MDR) steps in.
MDR involves outsourcing the combined Detect and Respond functions to experts who handle alerts, investigate incidents, and help with remediation when needed. By leveraging automation and scaling their infrastructure, MDR providers can deliver the same results at a more affordable price.

Failing to prepare for a cyber attack can be catastrophic for a business. A 2024 report by Cybereason, which surveyed companies impacted by ransomware, made this clear:
In theory, it’s easy to say a business should never pay a ransom — after all, no one wants to fund cyber criminals. But when you’re actually in that situation, faced with the choice of paying up or losing critical data and starting from scratch, the decision suddenly becomes a lot more complicated.
The Recover layer helps your organisation avoid the difficult decision of paying a ransom during a ransomware attack (or losing data to an accident or natural disaster). It ensures you can quickly get back to business after a cyber security incident or disruption by:
Cyber security is hard to navigate, even with a CSF, and the lack of in‑house expertise makes it tougher. If you want to protect your brand reputation, prevent costly data and revenue loss, and avoid potential fines, working with a trusted cyber security specialist is the way to go.
At Bistech, we take a personalised, multi-layered approach to security, helping you protect, detect, and respond to evolving cyber threats so your business can effectively overcome the defender’s dilemma. If you are ready to proceed, book a call with us today.