We Bought the Security Tools. We Hired the People. So Why Are We Still Vulnerable?

Think you’re protected? Here’s why companies get breached anyway: the real gaps security tools and compliance checklists miss.

This Article at a Glance:

  • Tools that are installed but not configured correctly are functionally the same as no tool at all.
  • Gaps in access control and offboarding processes are among the most common and most overlooked entry points.
  • Even a strong, dedicated internal hire has blind spots simply because they’re inside the environment every day.
  • For some smaller, lower-risk organizations, well-configured tools plus one disciplined person genuinely can be enough.
  • The combination of properly deployed tools, human expertise, and periodic outside validation is what actually closes the gap.

Introduction

You did what you were supposed to do. You invested in an EDR platform, put a firewall in place, maybe even a vulnerability scanner. You hired someone to take charge of security or handed it to your IT director as part of their portfolio. On paper, you’re covered.

Then something shakes that confidence: a near-miss incident, a vendor questionnaire that surfaced a gap you didn’t know existed, or a board member asking ‘are we actually secure?’, and nobody having a confident answer. The tools are in place. A person is responsible. So why do you still feel exposed?

The answer, almost always, isn’t what you bought or who you hired. It’s how the tools are deployed, whether they’re actually configured and running correctly, and whether anyone with an outside perspective has ever checked. That frustration you’re carrying isn’t a sign you made the wrong investments. It’s a sign the gap is somewhere you haven’t looked yet.

The dynamic of having a human over the top of the technology is really important. It’s my true belief that that’s what enables companies to move their programs forward in an effective and efficient manner. Relying independently on technology is a mistake, and relying independently on humans is a mistake.” — Paige Goss, Founder & CEO, Point Solutions Security

The question was never tools or people. It was always both, and the relationship between them.

Why the Tools You Bought Aren’t Covering You

Here’s what gets uncovered in a lot of engagements: a tool is installed, but it isn’t actually doing anything. Not because someone made a bad purchase decision, but because overengineering and overcomplication are extremely common patterns in security deployments.

A lot of times we’re sort of undoing things that were not built the appropriate way, or companies will have lots of tool sets deployed, but they’re not actually in production, or they’re not configured correctly. We find a lot of times that there’s a tool set there. It’s just not actually doing what they want it to be doing.” — Paige Goss

Tool deployment and tool configuration are two completely different things. A scanner that runs weekly but has never had its alert thresholds set, an EDR that was stood up during a previous engagement and never tuned to your environment, a firewall with default rules still in place. These are not edge cases. They’re the norm.

Beyond the tools themselves, the access control baseline is where some of the most common and most quietly damaging gaps live. Privileged access management (meaning who can escalate their permissions and under what conditions) is frequently underdefined. Termination processes are a consistent culprit: former employees keeping access they should have lost on their last day. These aren’t exotic attack vectors. They’re routine. And they accumulate over time into something an attacker can chain together.

Most of the time they think that it’s a technology process. They think what they need to do to become audit-ready is buy tools or set up software to solve their problems.” — Craig Schuemann, CISO & CIO, Point Solutions Security

Craig works with clients through audit readiness regularly, and the pattern holds: the assumption going in is that the problem is a technology gap. The reality is almost always governance, documentation, and process. Buying something new doesn’t fix what was never set up correctly in the first place.

Why the Person You Hired Isn’t Enough Either

The problem isn’t only the tools. Even a strong, experienced, genuinely capable security hire has a fundamental limitation that has nothing to do with their ability: they’re inside the environment every single day, making it hard to see the gaps.

This isn’t a knock on internal security talent. It’s a structural reality. Proximity to an environment creates blind spots that no amount of competence can fully compensate for. Your security person knows your systems well, but that same familiarity means they stop questioning things that have always looked the same way.

An outside reviewer sees the environment with fresh eyes and new angles. That difference in perspective is where gaps get found. There’s also the human element that no hire fully eliminates. Security still relies on humans making decisions, catching things, and acting on what they notice. People miss things. That’s not a failure of diligence, it’s simply a feature of human attention.

A separate and related problem shows how security responsibility gets assigned in the first place. Many mid-sized organizations don’t have a dedicated security hire at all; they have an IT director who owns security on top of everything else they’re managing. Why your IT director wearing the security hat is setting you both up to fail is a problem worth understanding on its own terms.

Even with a dedicated security person in place, the question of whether they have the right seniority and specialization to lead the program matters. Security leadership and execution are different jobs. If the real gap is strategic direction rather than headcount, it’s worth asking whether a vCISO is actually as good as a full time CISO.

The argument for a security hire isn’t invalidated by this; it’s complicated by it. One person, embedded in one environment, even a very good one, needs outside review to catch what their proximity prevents them from seeing.

The Honest Complication: When Tools Plus One Good Hire Really Is Enough

For some organizations, the answer to this article’s headline question is that you’re actually fine. If you’re a smaller company in a lower-risk industry, with no significant regulatory compliance obligations, modest data exposure, and a security-minded person who has genuinely taken the time to configure your tools correctly and maintain your access controls, then well-deployed tools plus one disciplined person can be sufficient.

The answer to ‘why are we still vulnerable?’ sometimes is ‘you’re not, or at least not in any way that justifies a larger investment right now.’ The point of this article is not to push every company toward buying more or hiring more. For some of you reading this, the gap isn’t a new investment. It’s a configuration audit of what you already have. That’s a very different problem with a very different scope.

What Actually Closes the Gap

For the companies where the gap is real (and in most of the 100-to-500-person organizations where these conversations happen, it is), the answer is the combination: tools deployed and configured correctly, human expertise applied over the top, and periodic outside validation.

On the tools side, the temptation to buy the next platform that promises to solve everything is strong and consistently counterproductive. Don’t get caught chasing the next shiny security tool. A tool will help, but only paired with the right deployment and an overall strategy, not as a stand-in for one.

Building a security program correctly from the start makes the maintenance dramatically more manageable. The cost isn’t in the tools. It’s in getting the tools to actually do what they’re supposed to do.

On the human side, PSS’s own practice is an honest illustration of how this works in the real world. When conducting penetration tests, AI tools are used for first sweeps and efficiency. They can catch things humans miss and help prioritize where to focus in a constrained timeframe. But as Angelina House, security analyst at PSS, describes it from our own internal pen testing workflow:

It’s great. It can catch things that we can’t catch. It can give us more detail about things. But it’s also important that we go in there and we physically look for ourselves because AI is just not as thorough as we are. Not yet, at least.” — Angelina House, Security Analyst, Point Solutions Security

PSS insists on the human physical review for our internal processes. The same principle applies to how your security posture gets validated: automated tools and platforms capture a lot, but they’re not a substitute for someone physically looking.

An annual third-party assessment, a pen test, or a security maturity review from someone who hasn’t been inside your environment every day is how you see what your own team can’t. Not because your team is bad at their jobs, but because seeing clearly requires distance.

When gaps are found, the goal is options and prioritization. Some things need to be fixed immediately. Others are worth knowing about but aren’t urgent. Understanding which is which is part of the value of the outside review.

Frequently Asked Questions

Why do we still get breached if we have security tools in place?

Usually because the tools are installed but not configured or actively managed. A scanner with default settings, an EDR that was never tuned to your environment, or access controls that were set up once and never reviewed; these are deployed in name only. A tool that isn’t doing what you need it to do is functionally the same as no tool at all. The gap isn’t typically in what you bought; it’s in whether it’s actually working.

Do I need to hire a security person if I already use security software?

Yes, but not for the reason most people expect. Software doesn’t make decisions, catch context, or notice when something looks subtly wrong in a way that doesn’t trigger an alert. A security hire adds judgment and human oversight over the top of the tools. The catch is that even a strong internal person has blind spots from being inside the environment every day — which is why periodic outside review matters regardless of how good your hire is.

How do I know if our security tools are actually working?

The most reliable way is a third-party review. Ask for evidence that your tools are configured correctly, that alerts are being monitored and acted on, and that your access control and offboarding processes are being enforced. A tool being installed isn’t the same as a tool being in production. If you can’t get a clear answer on that distinction from your own team, that’s the answer.

Is a well-configured tool plus one good security hire ever enough on its own?

For some organizations, yes. If you’re smaller, lower-risk with limited regulatory obligations and a genuinely disciplined security person who has taken the time to configure and maintain your tools correctly, that combination can be sufficient. If you do have a gap, the combination of correct deployment, human expertise, and outside review is what closes it. If not, save your budget.

The Question Was Never Tools or People

You came into this asking why you still felt exposed after doing what you were supposed to do. The answer is almost never that you bought the wrong thing or hired the wrong person. It’s that neither tools nor people fully close the gap when they’re operating in isolation.

Tools that aren’t configured correctly don’t protect you. A person embedded in the same environment every day develops blind spots no amount of competence can compensate for. And a program built around buying the next platform that promises to fix everything will keep spending money without ever actually feeling secure.

The combination of tools deployed correctly, human expertise applied over the top, and periodic outside validation to see what proximity prevents you from seeing, is the architecture that works.

Relying independently on technology is a mistake, as is relying only on humans. That’s the answer to why you still feel exposed. The question was never which one to choose.

Book a Security Strategy Session

Not sure if the gap is your tools, your team, or something in between? A strategy session gives you an outside, honest look at what’s actually covering you and what isn’t — no pitch, just clarity.

[Book My Strategy Session: What’s your biggest security headache right now?]

About the Author

Founder

Dark Web Monitoring: Tracks stolen data and threats on the dark web for proactive mitigation.

3rd Party Risk Review: Assesses security risks posed by vendors and partners.

PCI DSS Scan: Evaluates compliance with Payment Card Industry Data Security Standards.

Vulnerability Scan: Automated scan identifying weaknesses in systems, software, and configurations.

Phishing Simulations: Mock phishing attacks to assess employee susceptibility and improve detection of malicious emails.

Penetration Testing: Simulated attacks to identify and exploit vulnerabilities in systems before malicious actors can.

Security Awareness Training: Educates employees on recognizing and avoiding cyber threats through interactive lessons and real-world scenarios.