A few months ago, I was in a call with a company that had just been hit by a ransomware incident. They were not small. They were not careless. They had a security team, modern tools, and a Managed Detection and Response service watching their environment around the clock.
Managed Detection and Response, or MDR, is meant to do exactly what it sounds like. A specialist provider monitors your systems for suspicious activity and helps investigate and respond to threats. In many cases, they can isolate an infected machine, stop malicious processes, and then inform the organisation about what they have done and what needs to happen next. It is one of the most sensible ways for organisations that cannot staff a full security operations centre to get serious protection.
And yet, in this case, when the attack started, nothing important happened for almost two hours.
No critical system was isolated. No high-risk accounts were shut down. People were still debating whether the activity was “really an incident” or just a false alarm. By the time action was taken, the attackers had already moved through the environment and encrypted far more than they should have been able to.
After the call, someone said something I hear a lot. “We need to improve our security maturity.”
That was not the real problem. The problem was that, in spite of all the tooling and services in place, the organisation was not actually defensible.
Most organisations think about security in terms of what they have bought and what framework they follow. They talk about maturity levels, roadmaps, and coverage. But none of that answers a simpler question.
If something goes wrong tonight, can you stop it from turning into a business crisis?
Very often, the honest answer is no.
This is why I think we need a different way to think about security. Not in terms of how advanced it looks, but in terms of whether it clears a basic survival threshold. I call this threshold the security poverty line.
It is not a moral judgement. It is a practical one. In economics, being below the poverty line does not mean you have nothing. It means you do not have enough of the right things to absorb shocks. One unexpected expense can push you into crisis. In security, one ordinary attack can do the same.
Above the line, incidents still happen. Systems still get compromised. But the organisation has a chance to contain the damage and keep operating. Below the line, every serious incident becomes a gamble.
This problem shows up everywhere, but it is especially visible in Africa and other emerging markets.
Many organisations there are growing fast, adopting cloud services quickly, and digitising core processes under real economic pressure. They do not have the luxury of large in-house security teams. So they do what makes sense. They buy tools. They buy MDR. They buy insurance. They try to borrow “global best practice” and make it work locally.
And still, they get hit. Sometimes badly.
The easy explanation is to say the attackers are getting better. The more honest explanation is that many organisations are still structurally fragile. They are operating below a minimum level of security that makes real defence possible.
In the current geopolitical climate, this fragility is becoming harder to ignore. Modern conflicts are no longer fought only on physical battlefields. They increasingly extend into digital infrastructure. The ongoing tensions and conflicts in the Middle East have been accompanied by waves of cyber activity targeting energy companies, financial systems, government networks, and logistics platforms.
These incidents rarely begin with sophisticated zero-day exploits. More often they begin with the same weaknesses organisations struggle with everywhere else: exposed identities, poorly monitored systems, and slow decision-making when an incident begins to unfold.
In other words, geopolitical cyber operations frequently succeed not because the attackers are extraordinary, but because the target organisations are operating below their own security poverty line.
When nation-state aligned groups begin probing infrastructure, the difference between a minor incident and a systemic disruption often comes down to the same basic question: how quickly can the organisation detect what is happening, make decisions, and contain the damage before it spreads.
What does “defensible” actually mean?
It does not mean being hard to break into. That is a comforting idea, but it is not realistic. It means something more practical. It means you can spot trouble early enough, that someone can make a decision quickly, that someone can act without waiting for a committee, and that the business can find its way back to a stable state without weeks of chaos.
When any of those are missing, security turns into a form of organised hope. This is where the conversation about MDR often becomes confused.
Most modern MDR services can and do take action. They will isolate a compromised device. They will kill malicious processes. They will raise the alarm and explain what they have done. But in most environments, response is still a shared responsibility. The provider can contain part of the problem, but the customer still needs to reset accounts, check for lateral movement, decide whether systems should be taken offline, and deal with the business consequences.
This is exactly where many incidents go wrong.
If identity systems are weak, attackers can simply come back using another account. If nobody is quite sure who is allowed to shut down a critical server, action gets delayed. If logs are scattered and incomplete, nobody can see the full picture. If recovery has not been tested, restoring systems takes far longer than expected.
In other words, you can have good detection and even some level of response, and still be below the security poverty line.
I see this pattern in the UK and Europe. I see it even more often in African and other emerging markets, where environments are usually more mixed, budgets are tighter, and systems have grown in less tidy ways. Old servers sit next to new cloud services. Shared admin accounts exist because “that’s how it’s always been.” Internet links are less stable. Support contracts are more complicated. All of this makes fast, clean response harder.
And attackers do not need perfection. They just need enough friction in your response to buy themselves time.
The uncomfortable truth is that many organisations are not failing because they lack tools. They are failing because they lack coherent control over their own environments.
They cannot reliably say what they own. They cannot reliably say who can do what. And they cannot reliably act fast when something starts to burn.
This is what it means to be below the security poverty line.
It also explains why so much security spending feels disappointing. Money goes into things that sit above the line, while the foundations remain weak. More alerts. More dashboards. More reports. But when something serious happens, the same delays and confusions appear.
The shift in thinking is simple, but not easy.
Instead of asking, “How mature are we?” organisations should ask, “Can we actually survive the most likely incidents?”
For many, the fastest improvement will not come from buying something new. It will come from fixing identity properly. From reducing the number of powerful accounts. From making it clear who can isolate systems and disable access. From practicing recovery in conditions that feel uncomfortable. From deciding in advance who is in charge when things happen at the worst possible time.
These are not glamorous projects. But they move you from below the line to above it.
And once you are above the line, services like MDR start to deliver far more value. Detection becomes meaningful because response can follow. Containment sticks because attackers cannot simply walk back in. Recovery becomes a business process, not a crisis experiment.
The final, slightly uncomfortable conclusion is this.
A lot of organisations are not being defeated by brilliant attackers. They are being defeated by their own fragility.
The idea of a security poverty line gives leaders a more honest way to look at their situation. Not through the lens of how modern their stack looks, but through the lens of whether they can take a hit and stay standing.
In fast-growing markets, in emerging economies, and in fact everywhere, that question is starting to matter more than any maturity score.
Because in the end, security that only looks good on paper is not really security at all.
By Emmanuel Adjah
