Associated KonsultantsCybersecurity & Risk Consulting Better Business Bureau Accredited Business (opens in a new tab)

Insights · September 2026

The Noise Got Louder. The Question Didn’t Change.

A client called me after the money had already gone.

They had received an email from a vendor they really used, about an invoice they really owed. It said the banking details had changed. The details were updated and the payment went out on time, to an account that did not belong to their vendor. Their bank is working on it and so is law enforcement, and in the meantime the original invoice has not gone anywhere, because the vendor still has not been paid.

Nobody did anything stupid. That is worth saying plainly, because it is the part people skip. Somebody paid a real invoice to a real supplier on the day it was due, using the information in front of them. That is not a lapse. That is the job.

Afterward they asked me the right question: how could we have spotted this, or stopped it?

The answer had nothing to do with buying a product or service

Three things were missing, and any one of them, on its own, would have stopped this.

The first was training — not an annual video, but enough familiarity that a change of banking details on an existing account reads as an event rather than just another action. The second was a process: a rule that payment details for an existing vendor are never changed on the strength of the message that requests it, and that somebody calls the number already on file. Not the number in the email. The third was separation of duties: the person who can change where money goes is not also the person who sends it.

None of those three is a product or service. None of them appears in anyone’s advertising. All three are essentially free, and all three are boring. Which is exactly why a business overloaded by security noise can have none of them.

What eight years of noise has actually done

I made an argument some years ago that the security industry mostly sells noise, and that the noise was getting in the way of the work. I would like to report that it improved.

Unfortunately, the volume has gone up instead. There is a breach in the headlines most weeks, a product launch most days, and now there is AI on both ends of every pitch — the threats are AI-powered and so, conveniently, is the defense. A small business owner reading all of this is not being informed. They are being worn down.

Worn-down people do one of two things. Some buy something, because a purchase is the only available way to make the feeling stop. Others stop listening entirely; on the reasonable grounds that if everything is urgent then nothing is. Opposite reactions, same outcome: a company no better protected than it was.

And the email that cost my client did not need any of it. It did not need AI. It needed a real vendor, a real invoice, and a company with no rule about changing bank details.

Three signs the noise has gotten to you

Worth an honest minute:

You can name the security products you pay for, but not what each one actually protects. You can trace most of what you bought in the last two years back to a headline or a scare. And nobody in the building can say which system, down for a day, or which missing process, would genuinely hurt.

The test the noise cannot pass

Any real risk is made of three parts, and all three must be present at once.

A threat — someone with the means and the motive. A vulnerability — the opening they would use. An impact — what it actually costs when they get through. Remove any one and there is no risk, just an expense.

Run the vendor email through it. The threat was real and completely ordinary. The vulnerability was not a technology at all; it was a process that did not exist. The impact was money leaving the building and an invoice that still has to be paid. Three for three, which is why it worked.

Now run the last thing somebody tried to sell you through the same test. Ask which of the three it addresses. Then ask whether the other two are actually present in your business. A good vendor can answer both questions. Some will realize, partway through answering, that they have been selling you a very good lock for a door you do not have.

That is the whole filter. It does not require you to keep up with anything.

Why we score instead of scaring

Associated Konsultants assesses against a published standard — all eighteen CIS Critical Security Controls, scored for maturity, alongside four corporate and physical categories that most assessments never look at. Everything that comes back is sorted into short, mid and long term.

That sort order is the impact question doing its work. It is the difference between a list of everything wrong with a company and an answer to what to do first, which is the only thing anyone actually wants.

I will tell you when something you already own covers a risk, and I will tell you when a finding is real but not worth what fixing it would cost. That judgment is worth more when the person making it does not sell the remedy.

If the noise has gotten loud enough that you have stopped listening, that is exactly what the twenty-minute call is for.

Twenty minutes.

No cost, no presentation. We work out whether there’s a fit — and if there isn’t, I’ll say so and point you somewhere better.

Book a 20-minute call