August 6, 2026
Security by Design: The Practical Alternative to Tool Overload
The Simple Security Shift That Beats Every Expensive Tool

By Maikel Mardjan
2 min read
No business is too small to be a target for cybercriminals. Small and medium-sized businesses (SMBs) are attractive prospects for ransomware. They often have limited resources for security management and have outsourced every aspect of IT. It makes little difference whether that outsourcing is very expensive or the cheapest option available. SMBs also hold valuable customer data, and people remain the weakest link.
Within SMBs a typical question is: "Do we need these expensive cyber security measures?" And the core question is always: "What would actually stop us from being breached, and how much does it cost?" The truth is that high spending on cyber security measures does not reduce the likelihood of a breach. It only increases the frustration when one occurs.
The crucial question should instead be: "How do we strengthen our security foundation without slowing the business down or spending too much on tooling that still offers no absolute guarantee?"
A stubborn misperception persists that expensive security tools and costly consultancy firms automatically make an organisation more secure. This is far from reality.
The right security tools do make a difference. However, popular modern AI-driven solutions are not the most secure option. Be conservative when selecting vital tools to protect against cyber threats. Prefer proven open-source tools that meet minimum quality requirements.
A common blind spot is the assumption that security is "implicitly" perfect in modern tools or cloud platforms such as Microsoft 365, Google Workspace or AWS. In reality, most breaches stem from misconfiguration, weak identity controls, poor access hygiene and a lack of monitoring — not from exotic hacking techniques.
It is far harder to predict and prevent sophisticated attacks than it is to build strong identity management and monitoring practices derived from a security-by-design approach.
A well-maintained security architecture mitigates:
- Human errors: Human errors pose a serious threat and affect every business activity.
- Flaws in tools, software and hardware: Every piece of software has weaknesses, and hardware is an easy attack vector. A sound security architecture, founded on proven principles, builds resilience against the majority of common attack vectors.
Security fundamentals matter more than tools. The good news is that implementing security fundamentals is far less expensive than deploying costly security tools, which also have high implementation costs. Most commercial cybersecurity solutions are not future-proof and are hard to maintain in the long term.
The best security solutions are seldom expensive tools. Effective cybersecurity begins with creating an open, transparent security architecture based on key security-by-design principles. You simply cannot afford to have no architecture, so it is better to make it explicit. But do not make it overly complex. A good security architecture grounded in a security-by-design approach simply follows a few simple, proven steps.