InsITe Blog

Which Security Control Should You Fix First?

Written by Justin Platt | Oct 5, 2026, 12:30:00 PM

The Quick Answer

There's no single fixed order that fits every business. What matters is finding where the greatest risk or pain actually sits today, getting a fast, visible win there, and then using that momentum to build out toward a full roadmap, one that eventually covers identity, incident response, and a compliance framework matched to your actual requirements. A roadmap that ignores where you're starting from is just theory.

This is a pattern we hear constantly at events, expos, and in conversations with prospective clients: an ops leader walks out of a security workshop with a full page of notes. MFA. Passkeys. A written incident response plan. Employee training. A cyber insurance renewal with new requirements attached. A list of Secure Score recommendations from IT. The renewal deadline is three weeks out. Every item on the page reads as urgent. Nothing on it says what to do Monday morning.

A full checklist is not a secure business

It's easy to believe that checking off more items means getting more secure. More controls in place, less risk.

But security doesn't work like a list where every line carries equal weight. Some items close a door attackers use every day. Others close a door almost nobody uses.

And no single item closes a door all the way.

1. Why the list shows up flat

Every item on that page came from someone with a reason to put it there. Each one is right about their own piece. None of them is positioned to weigh it against the rest of your list.

  • The single-tool vendor tells you their piece is critical. They have no reason to tell you which piece comes first.
  • The all-in-one platform tells you it covers everything. It has no reason to tell you what it misses.
  • The insurance application tells you what to attest to. It doesn't check whether the control works on a bad day.
  • The framework tells you what a complete program looks like. It doesn't know where you're starting from.

That's how a business ends up with a long list, equal weight on every line, and no clear first move.

2. Every tool has a blind spot

Good tools are built to stop specific things. That same focus is what leaves them blind to everything else.

A few blind spots we see often:

  • MFA stops a stolen password. It doesn't stop an attacker who tricks an employee into signing in through a fake page and walks away with the live session.
  • Endpoint protection covers the laptops and servers it's installed on. It can't run on a lot of what sits outside the office: shop floor equipment, cameras, printers, older machines nobody wants to touch.
  • Email filtering catches bad links and attachments. It does nothing when the attack arrives as a phone call or through a trusted link that then lands you on a malicious site.
  • Secure Score measures how your Microsoft settings are configured. It can't tell you whether your team would follow the password verification callback procedure when someone sounds urgent.
  • Backups get your files back. They don't tell you what an attacker copied on the way out.

None of these tools are bad. Each one is doing its job. The gap is in expecting any one of them to do every job.

3. What one missing layer looks like

An employee gets an email that looks like a normal sign-in request. The login page is convincing. They enter their code.

MFA did exactly what it was built to do. The attacker holds a live session anyway.

If MFA was the only layer, nothing else notices. No alert fires on the unusual sign-in. Nobody sees the new inbox rule quietly forwarding invoices.

The first sign comes three weeks later, when a vendor calls asking why their payment went to a new bank account.

With one more layer, the same morning looks different. The sign-in gets flagged. The payment change triggers a callback to a number already on file.

Someone on the team knows the first three calls to make. The session is shut down before lunch.

Same attack. Same employee. Different outcome, because something else was there to catch the miss.

4. Layers catch what tools miss

Real protection comes from layers that overlap on purpose. Where one layer is weak, another is strong. That means more than tools.

  • Technology stops the common, automated attacks at scale. This is where MFA, endpoint protection, filtering, and backups live.
  • Process covers the moments when technology gets fooled. A callback rule for payment changes. An incident response plan the team has actually practiced. Regular reviews of who has access to what.
  • People notice what doesn't look right. They know what to question, who to call, and that raising a flag will never get them in trouble.

A tool with no process behind it gets bypassed. A process nobody has practiced falls apart under pressure. A trained team with no tools gets overwhelmed.

Build for the miss.

Every control will fail at something eventually. The question isn't whether a layer can be beaten. It's whether the next layer is there when it is.

5. Sequence still decides where you start

Building for the miss doesn't mean doing everything at once. It means asking a sharper question than "what's next on the list."

Work through it in this order:

  • Where is the risk or pain greatest right now? Start there, not at the top of a generic list.
  • Which layer is thinnest at that spot? Sometimes the gap is a tool. Often it's a missing process or a team that hasn't been shown what to watch for.
  • What's the fastest, most visible win you can take there? Take it. Momentum matters.
  • Back out from that win to the full roadmap. Identity, practiced incident response, and a framework matched to what your business is actually required to meet.
  • Use tools like Secure Score to check progress. Never as the plan itself.

A checklist tells you what exists. A roadmap tells you what to do first, and what backs it up when it fails.

How InsITe approaches it

We don't hand over another list or push every business through the same fixed order. We start by finding where each business's risk actually sits and which layers are thin there.

Then we build the roadmap outward across technology, process, and people, matched to the framework that fits its requirements. Every step is designed so no single control carries the load alone.

See InsITe's Security & Compliance Roadmap →

Build for the miss

The goal was never a perfect list. It's a business where one failed control is an inconvenience, not an incident.

If your most trusted security control failed tomorrow morning, what would catch it?

And could you defend the order of your last three security investments, or were they simply next on someone's list?