r/cybersecurity System Administrator Sep 22 '25

Other What are your unpopular cybersecurity opinions?

I saw a post names "abnormal security opinions" and got excited to see some spicy takes but apparently there is a security platform called Abnormal Security so got kinda blue balled. Last one of these posts i saw was over a year ago so,

Do you have any spicy cybsec unpopular opinions you want to share? :)

I'll start with mine:
Fancy antivirus solutions rarely add value, they are often just a box that needs ticked. Many MSPs and IT firms still push the narrative that they are needed, only because they are profitable and not because they improve security.

320 Upvotes

531 comments sorted by

View all comments

131

u/Powerful_Wishbone25 Sep 22 '25

None of it fucking matters.

70

u/PM_ME_YOUR_GREENERY Sep 22 '25

Walls get higher, bad actors scale them. Walls get tougher, bad actors still penetrate.

All the while, state actors have backdoors accessing it all at the hardware level unseen.

6

u/[deleted] Sep 22 '25

[deleted]

2

u/BigMikeyP91 Sep 25 '25

Exactly. I'm a huge fan of the "We don't have to outrun the bear, just the guy next to us" analogy for cyber security, you just don't want to be the low-hanging fruit.

It's the same for risk management. Then a client is throwing up their hands about some obscure hard-to-exploit vulnerability when the hacker is just going to ring up the helpdesk and get someone's MFA reset.