From confidence to evidence: Building a security culture that tests its own assumptions
There’s a moment that comes up often enough in first meetings with a new client that our team half-expects it – a lot of nodding heads. Have you got a cyber resilience plan in place? Yes. A disaster recovery plan? Yes. An incident response plan? Yes.
Then comes the follow-up question – when was the last time you actually tested it?
And the room goes quiet.
Everyone says yes until you’re asked to prove it
The people answering yes genuinely believe it, and in a sense, they’re right – the plan exists, the policy is written, the backup solution is switched on. The follow-up question exposes the gap between having something and knowing it works, and many businesses have this gap whether they realise it or not.
That prompts a question. Why do you assume things are fine? Maybe you think “it’s always worked like this”, even though nobody’s actually checked since whoever originally set it up moved on. Or “we’d definitely notice if something was wrong.” That one assumes a level of visibility that, as we’ve covered before, most businesses simply don’t have.
You might even have everything documented – a network diagram, a signed-off policy, a process document – all useful, but they just capture a snapshot of a single moment, not a live account of what’s actually true today. A document that hasn’t been reviewed in a year isn’t evidence.
When this goes wrong for real
In 2023, KNP Logistics, a 158-year-old UK transport company, was hit by a ransomware gang after attackers guessed a single employee’s password on an account that wasn’t protected by multi-factor authentication. Unable to pay the ransom, KNP’s servers, backups and disaster recovery systems were encrypted or destroyed, and roughly 700 people lost their jobs when the company collapsed.
KNP held cyber insurance and reasonably believed its IT met the standard it was supposed to. Theoretically, they were covered. But the incident exposed that having controls and plans in place isn’t the same as knowing how they’ll perform when they’re actually needed. That’s a hard story, and a good reminder of the importance of replacing assumptions with evidence in cybersecurity.
This isn’t a one-time project
It’s easy to miss that replacing assumptions with evidence isn’t a one-and-done event. It’s an ongoing evolution. You don’t just do it once and then stop worrying about it until next year. New threats appear. Compliance requirements shift. The technology itself keeps changing, and every change quietly reopens questions that felt settled six months ago. Treating any of this as finished is a mistake that can take you back to assuming you’re covered.
The principle of a ‘Zero Trust’ mindset
There’s a name for the discipline that sits underneath everything above – Zero Trust. The National Cyber Security Centre defines it as “remove the assumption of trust from the network entirely”. Nothing gets access because it was inside the perimeter yesterday; everything gets verified, every time. The principle is “never trust, always verify.”
In practice, that shows up as a handful of familiar ideas.
- Giving people access to only what their role actually needs, rather than broad access.
- Verify identity continuously, not just once at login, checking where someone’s logging in from, what device they’re using, and whether anything about the request looks out of place.
- Assume breach – rather than focusing only on keeping attackers out, plan as if they’re already inside, and limit the damage they can do from there.
This isn’t a project with an end date, either. It’s a maturity journey, built over years, one verified assumption at a time.
Turning “how do we know?” into a habit
But Zero Trust is more than a collection of technical controls. It’s a way of thinking.
It means questioning whether the backup actually restores. Whether former employees really have been removed from every system. Whether the alert someone expects to see would actually be noticed. Whether the AI tools people are using are visible to the organisation.
The organisations that build this kind of resilience don’t necessarily have the biggest security budgets. They have built a habit of checking, challenging and re-checking what they believe to be true. Turning this principle into a habit comes down to a few practices:
- Verify on a rhythm, not just when someone remembers to. If you haven’t checked a control recently, test it.
- Know what you actually have, not what you think you have. You can’t test something nobody remembers exists. Check for the tools, accounts and access that have quietly accumulated over time, not just the ones you already know about.
- Keep documentation honest. If it doesn’t reflect what’s actually happening today, it isn’t evidence of anything.
- Make “has this actually been checked?” a normal question. Businesses that do this well have created a culture that questions the status quo before an incident, auditor, or customer prompts the question.
What this means for you
None of this requires a big security team or a bigger budget. It requires deciding, as a business, that “we think so” and “we know” aren’t the same.
That’s really the thread running through everything we’ve explored in this series – the confidence gap under the spend, blind spots a dashboard was never going to show, the complexity created by a security stack that grew one decision at a time, AI tools nobody signed off on. Different symptoms, same root cause.
You can’t eliminate every uncertainty. But it’s important to build a security culture where the important assumptions don’t go unchallenged for too long.
So if you want to see whether your business is running on assumptions or evidence today, take our Cyber Confidence Quiz. It’s a quick way to assess your security and see where you truly stand.
You don’t need to have all the answers before you start. You just need to be willing to test them.
Can you prove your cyber security?
Take five minutes to answer 10 questions to see how confident you should be in your current cybersecurity.




