The End of Reactive Security
Find Threat Talks on
The End of Reactive Security
You already had the threat intel. The IP was on your blocklist, the file hash was known bad. Your MDR saw it, matched it, and raised an alert. It did not stop the attack. That gap between what your SOC knows and what it acts on is the whole problem with reactive security.
In this episode, Lieuwe Jan Koning, Co-founder & CTO at ON2IT, sits down with colleague Nicholai Piagentini, Technical Enablement Engineer at ON2IT, at Venable HQ in San Francisco during RSA. Gartner now calls the alternative preemptive cybersecurity. Lieuwe Jan and Nicholai break down what that shift means for MDR, for the SOC, and for who controls your data.
What you’ll learn
-
The leaking tap. Detecting the same known threat over and over is mopping the floor while the tap keeps running.
-
Block first, alert second. The same intel that fires the MDR event can fire the block at the endpoint, network, or cloud.
-
Speed decides. Attacks now move in seconds, so detection and remediation have to collapse into one automated action.
-
Data freedom. Your logs and telemetry belong on storage you control, not embargoed inside a vendor cloud.
Your cybersecurity experts
Lieuwe Jan Koning
Co-Founder and CTO
ON2IT
Episode details
The core argument is simple and uncomfortable: traditional MDR is disaster recovery wearing a detection badge. You collect logs, you spot the leak, you clean up. You get very good at the cleanup and never touch the cause. Nicholai frames the fix as a block-first mentality. If a threat is already a known indicator of compromise, the alert and the block should be the same event, not two teams and two days apart.
That reframing forces an organizational change most security programs have avoided. The SOC that collects logs and the operations team that runs the firewalls and endpoints have to fuse. Detection with no path to enforcement is, as Nicholai puts it, the antithesis of Zero Trust: allow everything, then critique what you let through. Zero Trust flips that to deny by default, with log analysis kept for step five, validating that the protections you built are actually working.
Speed is where the stakes land hardest. Initial access to lateral movement used to be measured in days or months. Automated tooling now runs those steps in seconds, which is why the hosts invoke The Imitation Game: you need a machine to beat a machine, because humans cannot correct fast enough. A one-minute mean time to detect paired with a four-day mean time to remediate is not a win. In that window you were already part of the botnet.
The last thread is control. Nicholai calls it data freedom: your data is yours, not something to be locked and embargoed inside a vendor cloud. Vendors argue they cannot protect data they do not hold, but the honest translation is that reselling storage is where the margin lives. The takeaway for buyers is to bring that requirement to procurement, ask every vendor how the SOC can push controlled, validated changes back into enforcement, and refuse to copy the market just because everyone else does.
Get your Hacker T-shirt
Join the treasure hunt!
Find the code within this episode and receive your own hacker t-shirt for free.





