Govern gets investment because it drives governance program development. Identify gets investment because asset inventory and risk assessment are foundational. Protect gets significant investment because preventive controls are tangible and procurable. Recover gets attention after incidents. Detect — the capability to identify cybersecurity events as they occur — is chronically under-resourced, inadequately tested, and systematically overestimated in maturity assessments. The consequence is that most organizations discover significant incidents significantly later than their detection investments should produce.
Why Detection Is Under-Invested
Detection investment is difficult to justify before an incident because it is hard to demonstrate value: the detection capability that never fires because no incident occurs looks indistinguishable from a detection capability that is inadequate. Prevention investments have clearer value narratives — the firewall blocks attacks, the patch closes the vulnerability. Detection investments produce alerts, some of which lead to confirmed incidents and many of which are false positives. The ROI narrative for detection is harder to tell.
Detection also requires continuous operational investment that prevention does not. A preventive control, once implemented, operates without ongoing attention. Detection requires analysts who triage alerts, detection engineers who tune rules, threat intelligence that keeps detection signatures current, and regular adversarial testing that validates detection capability against actual attack techniques. This operational cost is ongoing and hard to reduce without degrading the capability.
The maturity assessment dynamic compounds the under-investment. NIST CSF maturity assessments for Detect typically assess whether monitoring is deployed, whether logs are collected, and whether an alert process exists. These are existence indicators. They do not assess whether the detection capability would detect the attacks most likely to be used against the specific organization. A SIEM deployed with vendor default rules, generating hundreds of alerts per day with low actionability, scores similarly to a well-tuned detection program calibrated against relevant threat intelligence.
Detection maturity scores measure whether detection infrastructure exists. They do not measure whether the infrastructure would detect the attacks that matter. The score can be adequate while the capability is not.
What Under-Investment in Detect Produces
Extended Dwell Time Before Detection
The median dwell time — the time an attacker spends in an environment before detection — has been declining globally as detection capabilities improve, but remains measured in weeks in many documented incidents. Organizations with inadequate detection capabilities contribute to the upper end of that distribution. An attacker who understands how to operate within the baseline of a detection program's existing rules can persist indefinitely until they make a mistake or until detection capability improves. The organizations that discover incidents quickly have invested in Detect. The organizations where attackers operate for weeks or months have not.
Detection That Identifies Symptoms, Not Causes
Detection programs that identify indicators of compromise after significant damage has occurred are detecting the late stages of an attack rather than the early stages. An alert that fires when ransomware begins encrypting files is detecting the attack at its most damaging phase. Detection of the initial access, the credential theft, the lateral movement, and the persistence establishment that preceded the ransomware deployment would have enabled earlier intervention. Detecting the symptom while missing the progression is a detection program that fires at the wrong point in the attack chain.
Gaps That Attackers Map and Exploit
Sophisticated attackers probe detection capabilities as part of their reconnaissance. They test which actions trigger alerts and which do not, and route their attack through the unmonitored paths. A detection program with consistent gaps — the systems that are not in the SIEM scope, the identity system whose logs are not ingested, the cloud environment that is not connected to the central monitoring — provides an attack path that sophisticated actors will discover and use.
Investing in Detect Effectively
Effective investment in Detect requires connecting the detection program to the specific threat landscape facing the organization rather than to generic monitoring best practices. Three investments that produce the most value per dollar in Detect:
Threat-intelligence-driven detection tuning. Detection rules calibrated against the attack techniques most actively used against the organization's industry sector, using current threat intelligence, produce detection that addresses the actual threats rather than the generic threat landscape. This requires a threat intelligence program that feeds into detection engineering.
Coverage assessment against the full environment. A systematic assessment of which systems produce logs that are ingested into the detection program, identifying the gaps, and prioritizing gap closure based on the risk significance of unmonitored systems. The highest-risk systems not in the detection scope are the priority.
Adversarial validation of detection capability. Red team and purple team exercises that specifically test whether the detection program would detect the attack techniques identified as most relevant, and that report not only on whether the attacks succeeded but on whether the detection fired. Detection that does not fire on adversarial simulations is not providing the capability the maturity score suggests.
Invest in Detect at the level the function's importance warrants. The incident you discover in week one is a different incident than the incident you discover in week seven.
Test the detection capability against adversarial techniques, not against the maturity criteria. The capability that matters is the capability that detects what will actually be used against you.
Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.
