Editorial

No Security Control is Absolute

Detection is still the last line of defence

Sunday, June 07, 2026 | 5 MINS

For the past decade, cybersecurity has steadily shifted towards prevention. Zero Trust, identity-centric security, secure access service edge, cloud-native platforms and AI-driven protection have all encouraged organisations to stop attacks before they become incidents. 

It is a logical direction of travel, but one that has led some to question whether Intrusion Detection and Prevention Systems (IDPS) are becoming less relevant.  That conclusion feels premature.

Attack techniques have evolved considerably, but the need to understand what is actually happening across networks and workloads has not diminished. If anything, the expansion of hybrid infrastructure, east-west traffic and cloud-native applications has made visibility more valuable than ever. Security teams still need to identify malicious activity, validate suspicious behaviour and understand how attackers are moving through an environment once prevention controls have been bypassed.

No prevention technology delivers perfect coverage.


Misconfigurations occur, credentials are stolen, trusted applications are compromised, and new vulnerabilities emerge long before signatures or patches are available. Every mature security strategy therefore, assumes that some threats will evade preventative controls. Detection remains the mechanism that allows organisations to identify those failures before they develop into significant business incidents.

Modern IDPS has also moved well beyond its traditional reputation


Early deployments were often associated with noisy signatures, high false-positive rates and lengthy tuning exercises. Many security teams spent as much time managing exceptions as they did investigating genuine threats. Today's platforms benefit from richer telemetry, threat intelligence integration, behavioural analytics and machine learning, allowing them to correlate multiple indicators rather than relying solely on static signatures.

This evolution has changed the role IDPS plays within security operations.

Rather than operating as an isolated appliance at the network perimeter, detection capabilities are increasingly distributed across endpoints, cloud workloads, containers, virtual networks and SaaS environments. The distinction between network detection, endpoint detection, cloud detection and behavioural analytics is becoming less important than the quality of the overall detection strategy and the ability to correlate events across the estate.

That broader view is essential because modern attacks rarely remain confined to one technology domain.

An attacker may compromise a cloud identity, move through SaaS applications, establish persistence on an endpoint, communicate through encrypted channels and laterally traverse internal networks, all within the same campaign. Identifying that sequence depends on bringing together multiple sources of telemetry rather than expecting any individual control to detect every stage independently.

Artificial intelligence is adding another dimension.


Security teams are beginning to use AI to reduce alert fatigue, improve correlation and surface the small number of detections that genuinely warrant investigation. Attackers, meanwhile, are also becoming more adept at avoiding traditional signatures and blending into legitimate business activity. This increases the importance of combining network intelligence with identity, behavioural and contextual analysis rather than relying on a single detection technique.

For security operations teams, the objective has become much clearer.  The value of IDPS no longer lies in counting blocked attacks or generating large volumes of alerts. Its contribution is measured by how effectively it helps analysts understand risk, prioritise investigations and identify malicious activity early enough for the organisation to respond before significant business impact occurs.

Detection has never been about replacing prevention, and prevention has never removed the need for detection. Both exist to support the same outcome: reducing the opportunity for attackers to achieve their objectives while giving defenders the visibility needed to respond when controls inevitably fail.

As enterprise environments continue to become more distributed, dynamic and encrypted, organisations still need technologies capable of answering one fundamental operational question with confidence: what is happening inside the environment right now?

Community Note


Detection technologies continue to evolve alongside AI, cloud infrastructure and modern SOC operations. If you have hands-on experience with IDPS, network detection, threat detection engineering or security monitoring and would like to share your expertise with the MYREDFORT community, we'd love to hear from you.

Please contact our Community Editor, Sam Redwood, at sam.redwood@myredfort.com.

Other topics