Ask This Question First
I get this question from clients more than almost any other one: “Are we doing enough on security, or are we doing too much?” It usually comes up right after we recommend a new tool or a new layer, and I can see the client doing the math in their head. Where does this end?
It doesn’t end at a number. It ends at a fit.
The Home Security Comparison
Think about home security for a minute. I know families who have cameras on every corner, a monitored alarm, bars on the windows, and a dog that takes the job seriously. I know others who have one good lock on the front door and sleep just fine. Neither household is wrong. What’s right depends on the house, the neighborhood, what’s inside, and how much risk that family is comfortable carrying.
Business cybersecurity works the same way. The right amount of protection isn’t a fixed number. It depends on what you’re protecting, what would happen if it were compromised, and how much risk your business can carry.
Why “More Security” Isn’t Automatically the Right Answer
This is the part that surprises people: piling on every tool we sell isn’t always the right call, and it’s not what I recommend by default either. If a layer of security doesn’t match your real risk, all it does is add cost and complexity. It doesn’t make you safer.
My goal for every client isn’t maximum security. It’s right-sized security, matched to the business in front of me.
The Real Questions I Walk Clients Through
When a client asks whether they need more protection, I don’t answer that directly. I ask a few questions of my own instead:
- What data would really hurt you if it were stolen or exposed? Customer records, financial data, and proprietary designs don’t carry the same weight.
- What would a day of downtime cost you? A manufacturer with a stalled production line is in a very different spot than a consulting firm that can work from their phones for a day.
- What does your industry require? Healthcare, financial services, and a few other regulated spaces come with a baseline you don’t get to opt out of.
- How much risk can your business genuinely absorb if something goes wrong, financially and reputationally?
Answer those honestly, and you’ll land somewhere between “one good lock” and “cameras, alarm, and a dog.” Most businesses do, and that’s completely normal.
What This Looks Like in the Real World
I worked with a 20-person professional services firm recently with no regulated data and low downtime risk. Solid endpoint protection, MFA everywhere, email security, and backups that actually get tested. That was a strong baseline for them, full stop.
Compare that to a 50-person healthcare practice I work with that handles patient records. Totally different risk profile. The baseline has to shift, because a breach there is expensive in ways that go beyond the immediate cost, there’s regulatory exposure on top of it. And here’s a stat that changes how a lot of business owners think about this: smaller businesses face fewer attacks overall, but a notably higher breach success rate when they’re actually targeted. Getting hit less often doesn’t mean getting hit less hard.
Neither business I mentioned is doing it wrong. They’re protecting different things.
How to Push Back on Your IT Provider
If your IT provider brings up a new tool, ask why. Not to be difficult, just as a real question: what risk does this address, and how does it apply to us specifically? A provider who can answer that clearly is helping you build the right protection. One who can’t is just selling you tools.
That’s how every security conversation starts on my end: understanding what you’re protecting and what it’s worth before we ever talk about what goes on top of it. Learn more about how Nevtec approaches this.
Find Your Right-Sized Baseline
If you’ve been wondering whether you’re overspending, underprotected, or somewhere in the middle, the only way to know for certain is to look at your specific risk picture.
Talk to Nevtec about a right-sized security assessment and get an honest answer, not an upsell.
Frequently Asked Questions
- Is it possible to have too much cybersecurity?
Yes, in the sense that layers which don’t match your real risk add cost and complexity without meaningfully reducing exposure. The goal is matching protection to risk, not maximizing every category.
- How do we know what our “baseline” should be?
Start with the type of data you hold, what downtime would cost you, any industry compliance requirements, and how much risk your business can absorb. Those four factors shape your baseline more than any single tool recommendation.
- Does company size determine how much security we need?
Size is a factor, but not the only one. A smaller business handling sensitive data or operating in a regulated industry may need more protection than a larger business with lower-risk operations.
- What if our IT provider keeps recommending more tools?
Ask what specific risk each recommendation addresses and how it applies to your business. A provider focused on your real risk profile should be able to answer clearly.
- How often should our security baseline be reviewed?
At least annually, or any time your business changes significantly, such as adding new locations, handling new types of data, or entering a regulated industry.