Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

The cybersec industry is solving the wrong problem. Here's why I think so.

0
Medium
Published: 08/10/2026 (08/10/2026, 13:52:03 UTC)
Source: Reddit Cybersecurity

Description

This content is an opinion piece discussing the cybersecurity industry's focus and challenges. It argues that the industry is not facing a detection problem but rather a decision-making problem due to the complexity and context-dependence of modern data. The author highlights that despite increasing cybersecurity spending, organizations continue to suffer significant losses from cyberattacks. The article emphasizes the need for contextual evidence to aid analysts in making informed decisions rather than relying solely on automated detection verdicts.

Reddit Discussion

r/cybersecurity·posted by u/johnymalko
00

A few years ago I "somehow" (ask me in the comments if you're curious) ended up in cybersec. I used to be just a "generic" software dev, so honestly I never thought Id be working with people who actually helped shape this industry in its very early days.

One of them is Tomasz Kojm, founder of Contextal and the guy who decades ago originally created ClamAV being still... at university. No funding, no experience, no company behind it, absolutely no support even from university itself. Just another project for him. Working with people like Tomek is a great experience. Not because you work with a cybersec veteran, but because you learn something you can't learn anywhere else. You start to notice more than you did before. You just become smarter within time - whatever that means.

Decades ago when Internet was becoming mainstream, organizations were floooooded with malware. However... nothing was as obvious back then as it may seem today. The biggest challenge wasn't understanding data. It was scale. Imagine processing massive volumes of files and emails manually. Therefore automation became the top priority, and the whole system design had to stay fairly simply: is this email / file malicious? Give me a quick verdict. Yes or No. That's basically it.

Now, according to Gartner, worldwide cybersecurity spending in 2026 is expected to reach almost $240B. And let's be honest.. next year it will probably be $260B, then $280B, then $300B etc. We don't need a crystal ball to predict where this is going. But let's stop here.

We spend hundreds of billions every year on cybersecurity and still lose billions because of cyberatacks. You read about another ransomware attack, stolen credentials and businesses paralyzed or shut down for months.

2026 - Hasbro - $25M in lost revenue

2026 - Marks & Spencer - £300M reduction in operating profit

2025 - Co-op Group - £206M in lost revenue

These are the companies we all know, and which mainstream media like because they convert. But there are thousands of them every year - just different scale and popularity.

So here's the question. If organizations spend more money than ever before, why do we still keep loosing? Companies are literally ARMED: endpoint protection, email security, sandboxes, malware scanners, AI... they seem to have everything. And that's the biggest paradox.

I don't think cybersecurity nowadays has a detection problem anymore. It has a decision problem!

Nowadays, modern data is no longer SIMPLE. Imagine a "simple" PDF can contain embedded objects, scripts, external references, QR codes, even encrypted parts. A single black box verdict often tells you almost nothing. Something that looks malicious doesn't really have to be. Something that looks clean doesn't have to be either. This is where context becomes everything.

Automation isn't the problem. Actually I think it's one of the biggest achievements in this industry. Catching generic threats on the fly is priceless but nowadays... security rarely operates in such ideal conditions. I guess most of you have seen VirusTotal showing 1 engine saying "malicious" while another 60+ classify exactly the same sample as clean. So... who's right? You probably won't open Reddit and ask people to make the decision for you ❌ Ive even had samples where every engine completely missed the malicious content.

When the verdict isn't obvious, and expect it to happen often. You don't need another detection engine in your stack. You don't need another black box verdict. You need evidence. You need context. Imagine, modern data carries metadata, relationships, execution paths, embedded objects and bahavior signals. None of them invididually proces malicious intent, but together they build context. And context is what helps analysts actually make good decisions.

I don't think organizations lose millions because they lacked one more malware verdict. I think they lose millions because they lacked the context needed to make the right decision. We live in a world where nothing is black and white anymore. You need a full picture of your data to understand what's going on and make a good decision.

I published my 1st 🥳 article on my blog. If you would like to dive deeper, feel free. I would be grateful. Btw, I will keep writing more stories in the future. I can't promise when because of work and other stuff, but it's something I really enjoy doing. I'm happy to answer any questions or discuss it in the comments.

https://magicsays.com/the-cybersecurity-industry-is-solving-the-wrong-problem

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/10/2026, 17:56:19 UTC

Technical Analysis

The article presents a viewpoint that the cybersecurity industry has evolved from primarily addressing detection challenges to now facing difficulties in decision-making because modern data is complex and ambiguous. It points out that automated detection tools provide black-box verdicts that often conflict or lack sufficient context, making it hard for analysts to determine true malicious intent. The author suggests that the key to improving cybersecurity outcomes lies in providing richer contextual information and evidence to support analyst decisions, rather than adding more detection engines.

Potential Impact

The impact described is conceptual rather than a direct technical vulnerability or exploit. It highlights ongoing financial losses by organizations despite heavy investment in cybersecurity technologies, suggesting that current approaches may not effectively reduce risk due to insufficient decision support. No specific technical exploit or vulnerability is identified.

Defensive Guidance

No technical mitigation or patch is applicable as this is an opinion and analysis piece rather than a software vulnerability. Organizations should consider enhancing their security processes to incorporate richer contextual analysis and decision support for analysts, as recommended by the author.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Domain
null
Newsworthiness Assessment
{"score":35,"reasons":["external_link","established_author","recent_news"],"isNewsworthy":true,"foundNewsworthy":[],"foundNonNewsworthy":[]}
Has External Source
true
Trusted Domain
false

Threat ID: 6a7a10b5bf8831d539459731

Added to database: 08/10/2026, 17:56:05 UTC

Last enriched: 08/10/2026, 17:56:19 UTC

Last updated: 08/11/2026, 03:11:03 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses