The current changes to the security industry forced by AI capabilities to find and exploit vulnerabilities aren’t a new problem. They are a continuation of a change that started years ago with the introduction of zero trust. Well, it probably started way before that, but stick with me here, I’m building to something.

The adoption of zero trust replaced the idea of an impervious network boundary with a defense-in-depth solution built on the principle that your system WOULD, not could, be compromised. Moving the focus from just preventive controls and making reactive controls equally if not more important.

In an era when compromise is all but assured, the most critical measure of potential vendors is how you will respond in a crisis, not what you are doing to prevent one. Preventing a crisis is impossible. Sure, we can mitigate and reduce risk, but one day something will happen, and it is on that day that I want to know my vendor is going to be able to handle the situation.

Yes, I still care about what you are doing to prevent an incident, but largely I am looking at that as an indication of your technical capacity and organizational commitment to cybersecurity. I’m less concerned about the details of your implementation and more interested in what it tells me about your organization, your leadership, and your values.

Keep this in mind when you are developing your Certification Packages. This isn’t just a checklist of controls, it is an explanation of why I can trust you to protect my data.