---
title: On Bad Solutions and Negative Returns
description: If only there were some top-secret method of cybersecurity that hardened your network, protected your servers and applications, and was not too expensive.
image: https://reflare.com/hubfs/Blog%20image%20in%20post/On%20Bad%20Solutions%20and%20Negative%20Returns.png
---

[![Reflare home](https://reflare.com/hs-fs/hubfs/Reflare%20website%20images/Reflare%20Logos/reflare%20logo.png?width=421&height=150&name=reflare%20logo.png "Reflare home")](https://reflare.com)

[![logo](https://reflare.com/hs-fs/hubfs/Reflare%20website%20images/Reflare%20Logos/logo.png?width=262&height=82&name=logo.png "logo")](https://reflare.com/act3)

[![reflare logo](https://reflare.com/hs-fs/hubfs/Reflare%20website%20images/Reflare%20Logos/reflare%20logo.png?width=168&height=60&name=reflare%20logo.png "reflare logo")](https://reflare.com/act3)

- [Galena](https://reflare.com/galena) 
    - [Galena Overview](https://reflare.com/galena)
    - [Galena for Tech Teams](https://reflare.com/technical-teams)
    - [Galena for L&D Teams](https://reflare.com/learning-development)
    - [Galena Security and Deployment](https://reflare.com/security-deployment)
- Training 
    - [Capture the Flag](https://reflare.com/rctf-reflare-capture-the-flag)
    - [Developers](https://reflare.com/rcsd)
    - [Administrators](https://reflare.com/rcsa)
    - [PCI DSS](https://reflare.com/rcsd)
- Audit 
    - [PCI DSS](https://reflare.com/pcidss)
    - [PCI 3DS](https://reflare.com/pci3ds)
    - [PCI PIN](https://reflare.com/pcipin)
    - [PCI DSS ASV](https://reflare.com/pcidssasv)
    - [Penetration Testing](https://reflare.com/penetration)
    - [Vulnerability Scanning](https://reflare.com/vulnerability)
    - [Advisory and Management](https://reflare.com/advisory)
- [Research](https://reflare.com/research) 
    - [Anatomy of a Breach](https://reflare.com/research/tag/anatomy-of-a-breach)
    - [High Tech](https://reflare.com/research/tag/high-tech)
    - [Infosec Culture](https://reflare.com/research/tag/infosec-culture)
    - [Infrastructure](https://reflare.com/research/tag/infrastructure)
    - [Normal People and Infosec](https://reflare.com/research/tag/normal-people-and-infosec)
    - [WTFWIB](https://whythefuckwasibreached.com/)
- [About](https://reflare.com/about) 
    - [Contact](https://reflare.com/contact)
    - [Company](https://reflare.com/about)
    - [Careers](https://reflare.com/careers)
    - [Service Status](https://statuspage.reflare.com/)
- [日本語](https://jp.reflare.com/)

[Login](https://reflare.com/login)

[Buy Now](https://www.hubspot.com/)

[Login](https://www.hubspot.com/)Login to your Reflare account

- [Galena](https://reflare.com/galena)
  
  
  
  
  
  
  
  
  
    - [Galena Overview](https://reflare.com/galena)
    - [Galena for Tech Teams](https://reflare.com/technical-teams)
    - [Galena for L&D Teams](https://reflare.com/learning-development)
    - [Galena Security and Deployment](https://reflare.com/security-deployment)
- Training
  
  
  
  
  
  
  
  
  
    - [Capture the Flag](https://reflare.com/rctf-reflare-capture-the-flag)
    - [Developers](https://reflare.com/rcsd)
    - [Administrators](https://reflare.com/rcsa)
    - [PCI DSS](https://reflare.com/rcsd)
- Audit
  
  
  
  
  
  
  
  
  
    - [PCI DSS](https://reflare.com/pcidss)
    - [PCI 3DS](https://reflare.com/pci3ds)
    - [PCI PIN](https://reflare.com/pcipin)
    - [PCI DSS ASV](https://reflare.com/pcidssasv)
    - [Penetration Testing](https://reflare.com/penetration)
    - [Vulnerability Scanning](https://reflare.com/vulnerability)
    - [Advisory and Management](https://reflare.com/advisory)
- [Research](https://reflare.com/research)
  
  
  
  
  
  
  
  
  
    - [Anatomy of a Breach](https://reflare.com/research/tag/anatomy-of-a-breach)
    - [High Tech](https://reflare.com/research/tag/high-tech)
    - [Infosec Culture](https://reflare.com/research/tag/infosec-culture)
    - [Infrastructure](https://reflare.com/research/tag/infrastructure)
    - [Normal People and Infosec](https://reflare.com/research/tag/normal-people-and-infosec)
    - [WTFWIB](https://whythefuckwasibreached.com/)
- [About](https://reflare.com/about)
  
  
  
  
  
  
  
  
  
    - [Contact](https://reflare.com/contact)
    - [Company](https://reflare.com/about)
    - [Careers](https://reflare.com/careers)
    - [Service Status](https://statuspage.reflare.com/)
- [日本語](https://jp.reflare.com/)

[Buy Now](https://www.hubspot.com/)

<https://reflare.com/research> Research

#### Share this

[Share on Twitter](https://twitter.com/share?url=https://reflare.com/research/on-bad-solutions-and-negative-returns&text=On%20Bad%20Solutions%20and%20Negative%20Returns) [Share on Facebook](https://www.facebook.com/sharer/sharer.php?u=https://reflare.com/research/on-bad-solutions-and-negative-returns&t=On%20Bad%20Solutions%20and%20Negative%20Returns) [Share on LinkedIn](https://www.linkedin.com/shareArticle?mini=true&url=https://reflare.com/research/on-bad-solutions-and-negative-returns&t=On%20Bad%20Solutions%20and%20Negative%20Returns)

# On Bad Solutions and Negative Returns

 by [**Reflare Research Team**](https://reflare.com/research/author/reflare-research-team) on Oct 16, 2019 6:04:00 PM

"If only. If only there were some sort of top-secret method of cyber security that hardened your network, protected your servers and applications, and did so in a way that was seamless, invisible, reliable, and not too terribly expensive." \*cough\*

First Published 16th October 2019

![On Bad Solutions and Negative Returns](https://reflare.com/hs-fs/hubfs/Blog%20image%20in%20post/On%20Bad%20Solutions%20and%20Negative%20Returns.png?width=672&height=448&name=On%20Bad%20Solutions%20and%20Negative%20Returns.png)

*Hygiene matters, but it can be taken too far.*

5 min read  |  Reflare Research Team

Germans have an ironic idiom called “viel hilft viel.” This is directly translated into “lots helps lots”, and is often used to ridicule the notion that by just doing enough random actions, you will eventually fix the problem. Mostly, we all know intuitively that this approach won’t work. If you have over-salted a stew, no random addition of more salt and spices will fix the taste. Unfortunately, when it comes to information security, individuals and the industry as a whole still haven’t come to realize that the same is true.

In this briefing, we will take a look at when actions meant to increase security preparedness and awareness can be counter-productive.

## There are no magical solutions

The sentence “it’s alright, we have an [IDS](https://en.wikipedia.org/wiki/Intrusion_detection_system)” is the dead canary in the coal mine of corporate information security. In just six words it manages to convey a horribly simplistic view of cyber attacks, a naive trust in solutions vendors, and a culture of buzzwords over fundamentals. It is also a sentence that has become emblematic of the mismatch between actual information security needs and the supposedly easy fixes up for sale on the marketplace.

To understand why let’s look at two important concepts: Complexity and integration.

## On Complexity

Imagine you run a museum with lots of valuable artefacts that need protection. Naturally, leaving the halls fully unsupervised at night after you close the doors is a bad idea. If a burglar broke in, it might take hours for anyone to notice. So you hire guards to patrol the building at night. But what happens to security if you add more and more guards?

This is a tricky question (and for the purpose of this example we will assume that you don’t have the budget to put three guards with rotating shifts who are watching each other in each room). Let’s say you start with 5 guards and they manage to patrol each room once every hour between them. If you now hire 5 more guards, they will be able to visit each room once every 30 minutes. That’s an improvement to be sure, but in the real world, you cannot be sure that all guards are trustworthy. One of the guards may be a thief trying to slip in. Or one might be under financial duress and open to looking the other way for a fee. With each guard you hire, you increase the risk of one of them being a bad actor.

The same issue exists with information security solutions. No doubt, three layers of firewalls, an IDS on the network and a few more on each machine, remote sensing, remote log collection, antivirus and endpoint protection on all work machines etc will make the job of attacking your system tougher. But all of these tools themselves are systems. They have code and hardware designed by regular, fallible, developers. At what point is the risk, that one of the security solutions contains a critical vulnerability, larger than the additional protection it offers? At what point will you run into a vendor that is controlled by a state actor and includes backdoors into their products?

The answer is complicated, fuzzy and very much not good for a clear sales pitch to C-suite executives. “Buy our product and you will be secure” is a good marketing pitch. “Your security is an impossible problem that we’d be happy to solve as best as possible” is not.

## On Integration

But let’s assume that all of your solutions themselves are secure, don’t have any bugs and actually do what they claim to do on the box. There is another, equally important and equally ignored problem: Integration.

Let’s equate information security solutions to locks for a moment. Imagine a salesman sold you an unbreakable lock. Not even heavy equipment can cut through its bolts. Not even the best lock pickers can open it without a key. You invest heavily to acquire it, hand it off to your staff and they promptly and vigorously proceed to install it on the staff kitchen cupboard door while leaving the front door secured with the standard lock and the backdoor open altogether.

As absurd as it sounds, this is the situation - at least partially - in almost all major networks from corporate to government. As solutions and infrastructure grow more and more complex, fewer and fewer people have a full overview of what is going on and where the important doors are. Of course, most serious organizations have diagrams and charts to map just these important paths, but those charts are notoriously out of date in most places.

All of this leads us to the one key idea that you should take away from this briefing: You usually don’t need more or better locks. You need people who know what doors to put the locks on.

## The issue with human talent

But where can you find those people? Since the specialists are horribly expensive, your best bet is usually to increase the information security skills of your own IT staff and the awareness of your non-IT staff. The tool to do so is training.

But unfortunately, training solutions themselves suffer from the same issues of complexity and integration. “Lots helps lots” is just as inadequate when dealing with training as it is when dealing with solutions. Humans have a limited attention span and employees also have a job to do. If training is too long and too unrelated to their everyday job, it quickly becomes useless as they either tune out, avoid it or find creative ways to circumvent the training requirement. Worse yet, just like security solutions, the wrong training can end up having a negative impact on your staff’s level of readiness. After three hours of redundant multiple-choice questions on - for example - phishing attacks, most people are less likely to take phishing seriously than before.

## Summary and Further Reading

When looking for information security solutions, find the doors that need locking and then find the locks that match them. Buying more locks won’t fix the problem and anyone who promises you a lock that will make your house burglar-proof is lying to you.

When looking for information security training, look for a solution that conveys the subject matter you need in a concise and impactful manner that is applicable to the workflow of your staff. The solution with most content may look good on paper but is unlikely to yield the best results.

On a personal note, Reflare has recently partnered with information security vendor [New Light Technologies](https://newlighttechnologies.com) to release a comprehensive [whitepaper](https://reflare.com/materials/Whitepaper%20-%20Security%20Awareness%20Training%20As%20A%20Service.pdf) covering the need for and pitfalls of information security training solutions. If this briefing was valuable to you, we heartily recommend that you give it a look for more detailed information.

Topics: [Infrastructure](https://reflare.com/research/tag/infrastructure)

#### Share this

[Share on Twitter](https://twitter.com/share?url=https://reflare.com/research/on-bad-solutions-and-negative-returns&text=On%20Bad%20Solutions%20and%20Negative%20Returns) [Share on Facebook](https://www.facebook.com/sharer/sharer.php?u=https://reflare.com/research/on-bad-solutions-and-negative-returns&t=On%20Bad%20Solutions%20and%20Negative%20Returns) [Share on LinkedIn](https://www.linkedin.com/shareArticle?mini=true&url=https://reflare.com/research/on-bad-solutions-and-negative-returns&t=On%20Bad%20Solutions%20and%20Negative%20Returns)

- Recent
- Topics
- Archive

Recent

Topics

- [Infosec Culture (113)](https://reflare.com/research/tag/infosec-culture)
- [Anatomy of a Breach (60)](https://reflare.com/research/tag/anatomy-of-a-breach)
- [Normal People and Infosec (42)](https://reflare.com/research/tag/normal-people-and-infosec)
- [High Tech (31)](https://reflare.com/research/tag/high-tech)
- [Infrastructure (21)](https://reflare.com/research/tag/infrastructure)
- [Capture the Flag (8)](https://reflare.com/research/tag/capture-the-flag)

See all

Archive

- [June 2026 (1)](https://reflare.com/research/archive/2026/06)
- [May 2026 (1)](https://reflare.com/research/archive/2026/05)
- [April 2026 (1)](https://reflare.com/research/archive/2026/04)
- [March 2026 (1)](https://reflare.com/research/archive/2026/03)
- [February 2026 (1)](https://reflare.com/research/archive/2026/02)
- [January 2026 (1)](https://reflare.com/research/archive/2026/01)
- [December 2025 (1)](https://reflare.com/research/archive/2025/12)
- [November 2025 (1)](https://reflare.com/research/archive/2025/11)
- [October 2025 (1)](https://reflare.com/research/archive/2025/10)
- [September 2025 (1)](https://reflare.com/research/archive/2025/09)
- [August 2025 (1)](https://reflare.com/research/archive/2025/08)
- [July 2025 (1)](https://reflare.com/research/archive/2025/07)
- [June 2025 (1)](https://reflare.com/research/archive/2025/06)
- [May 2025 (1)](https://reflare.com/research/archive/2025/05)
- [April 2025 (1)](https://reflare.com/research/archive/2025/04)
- [March 2025 (1)](https://reflare.com/research/archive/2025/03)
- [February 2025 (1)](https://reflare.com/research/archive/2025/02)
- [January 2025 (1)](https://reflare.com/research/archive/2025/01)
- [December 2024 (1)](https://reflare.com/research/archive/2024/12)
- [November 2024 (1)](https://reflare.com/research/archive/2024/11)
- [October 2024 (1)](https://reflare.com/research/archive/2024/10)
- [September 2024 (1)](https://reflare.com/research/archive/2024/09)
- [August 2024 (1)](https://reflare.com/research/archive/2024/08)
- [July 2024 (1)](https://reflare.com/research/archive/2024/07)
- [June 2024 (1)](https://reflare.com/research/archive/2024/06)
- [April 2024 (2)](https://reflare.com/research/archive/2024/04)
- [February 2024 (1)](https://reflare.com/research/archive/2024/02)
- [January 2024 (1)](https://reflare.com/research/archive/2024/01)
- [December 2023 (1)](https://reflare.com/research/archive/2023/12)
- [November 2023 (1)](https://reflare.com/research/archive/2023/11)
- [October 2023 (1)](https://reflare.com/research/archive/2023/10)
- [September 2023 (1)](https://reflare.com/research/archive/2023/09)
- [August 2023 (1)](https://reflare.com/research/archive/2023/08)
- [July 2023 (1)](https://reflare.com/research/archive/2023/07)
- [June 2023 (2)](https://reflare.com/research/archive/2023/06)
- [May 2023 (2)](https://reflare.com/research/archive/2023/05)
- [April 2023 (3)](https://reflare.com/research/archive/2023/04)
- [March 2023 (4)](https://reflare.com/research/archive/2023/03)
- [February 2023 (3)](https://reflare.com/research/archive/2023/02)
- [January 2023 (5)](https://reflare.com/research/archive/2023/01)
- [December 2022 (1)](https://reflare.com/research/archive/2022/12)
- [November 2022 (2)](https://reflare.com/research/archive/2022/11)
- [October 2022 (1)](https://reflare.com/research/archive/2022/10)
- [September 2022 (11)](https://reflare.com/research/archive/2022/09)
- [August 2022 (5)](https://reflare.com/research/archive/2022/08)
- [July 2022 (1)](https://reflare.com/research/archive/2022/07)
- [May 2022 (3)](https://reflare.com/research/archive/2022/05)
- [April 2022 (1)](https://reflare.com/research/archive/2022/04)
- [February 2022 (4)](https://reflare.com/research/archive/2022/02)
- [January 2022 (3)](https://reflare.com/research/archive/2022/01)
- [December 2021 (2)](https://reflare.com/research/archive/2021/12)
- [November 2021 (3)](https://reflare.com/research/archive/2021/11)
- [October 2021 (2)](https://reflare.com/research/archive/2021/10)
- [September 2021 (1)](https://reflare.com/research/archive/2021/09)
- [August 2021 (1)](https://reflare.com/research/archive/2021/08)
- [June 2021 (1)](https://reflare.com/research/archive/2021/06)
- [May 2021 (14)](https://reflare.com/research/archive/2021/05)
- [February 2021 (1)](https://reflare.com/research/archive/2021/02)
- [October 2020 (1)](https://reflare.com/research/archive/2020/10)
- [September 2020 (1)](https://reflare.com/research/archive/2020/09)
- [July 2020 (1)](https://reflare.com/research/archive/2020/07)
- [June 2020 (1)](https://reflare.com/research/archive/2020/06)
- [May 2020 (1)](https://reflare.com/research/archive/2020/05)
- [April 2020 (2)](https://reflare.com/research/archive/2020/04)
- [March 2020 (1)](https://reflare.com/research/archive/2020/03)
- [February 2020 (1)](https://reflare.com/research/archive/2020/02)
- [January 2020 (3)](https://reflare.com/research/archive/2020/01)
- [December 2019 (1)](https://reflare.com/research/archive/2019/12)
- [November 2019 (2)](https://reflare.com/research/archive/2019/11)
- [October 2019 (3)](https://reflare.com/research/archive/2019/10)
- [September 2019 (5)](https://reflare.com/research/archive/2019/09)
- [August 2019 (2)](https://reflare.com/research/archive/2019/08)
- [July 2019 (3)](https://reflare.com/research/archive/2019/07)
- [June 2019 (3)](https://reflare.com/research/archive/2019/06)
- [May 2019 (2)](https://reflare.com/research/archive/2019/05)
- [April 2019 (3)](https://reflare.com/research/archive/2019/04)
- [March 2019 (2)](https://reflare.com/research/archive/2019/03)
- [February 2019 (3)](https://reflare.com/research/archive/2019/02)
- [January 2019 (1)](https://reflare.com/research/archive/2019/01)
- [December 2018 (3)](https://reflare.com/research/archive/2018/12)
- [November 2018 (5)](https://reflare.com/research/archive/2018/11)
- [October 2018 (4)](https://reflare.com/research/archive/2018/10)
- [September 2018 (3)](https://reflare.com/research/archive/2018/09)
- [August 2018 (3)](https://reflare.com/research/archive/2018/08)
- [July 2018 (4)](https://reflare.com/research/archive/2018/07)
- [June 2018 (4)](https://reflare.com/research/archive/2018/06)
- [May 2018 (2)](https://reflare.com/research/archive/2018/05)
- [April 2018 (4)](https://reflare.com/research/archive/2018/04)
- [March 2018 (5)](https://reflare.com/research/archive/2018/03)
- [February 2018 (3)](https://reflare.com/research/archive/2018/02)
- [January 2018 (3)](https://reflare.com/research/archive/2018/01)
- [December 2017 (2)](https://reflare.com/research/archive/2017/12)
- [November 2017 (4)](https://reflare.com/research/archive/2017/11)
- [October 2017 (3)](https://reflare.com/research/archive/2017/10)
- [September 2017 (5)](https://reflare.com/research/archive/2017/09)
- [August 2017 (3)](https://reflare.com/research/archive/2017/08)
- [July 2017 (3)](https://reflare.com/research/archive/2017/07)
- [June 2017 (4)](https://reflare.com/research/archive/2017/06)
- [May 2017 (4)](https://reflare.com/research/archive/2017/05)
- [April 2017 (2)](https://reflare.com/research/archive/2017/04)
- [March 2017 (4)](https://reflare.com/research/archive/2017/03)
- [February 2017 (2)](https://reflare.com/research/archive/2017/02)
- [January 2017 (1)](https://reflare.com/research/archive/2017/01)
- [December 2016 (1)](https://reflare.com/research/archive/2016/12)
- [November 2016 (4)](https://reflare.com/research/archive/2016/11)
- [October 2016 (2)](https://reflare.com/research/archive/2016/10)
- [September 2016 (4)](https://reflare.com/research/archive/2016/09)
- [August 2016 (5)](https://reflare.com/research/archive/2016/08)
- [July 2016 (3)](https://reflare.com/research/archive/2016/07)
- [June 2016 (5)](https://reflare.com/research/archive/2016/06)
- [May 2016 (3)](https://reflare.com/research/archive/2016/05)
- [April 2016 (4)](https://reflare.com/research/archive/2016/04)
- [March 2016 (5)](https://reflare.com/research/archive/2016/03)
- [February 2016 (4)](https://reflare.com/research/archive/2016/02)

See all

### Subscribe by email

#### About Reflare

We help customers increase cyber resilience with the #1 hands-on IT security training platform.

Our developer, administrator, and non-technical user training programs enhance user skills, fulfil your compliance needs, and contribute to developing more secure technologies.

<https://x.com/reflarehq><https://www.linkedin.com/company/reflare-ltd.>

Legal

- [Terms of Service](https://reflare.com/terms)
- [Privacy Statement](https://reflare.com/privacy)
- [Cookie Info](https://reflare.com/cookies)
- [Copyright and Citation Enquiries](https://reflare.com/citation)
- [Contact](https://reflare.com/contact)

 © 2026 Reflare Ltd, and/or its affiliates.   /   In business since 2009.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Reflare Research Team",
    "url" : "https://reflare.com/research/author/reflare-research-team"
  },
  "dateModified" : "2023-11-21T12:43:20.110Z",
  "datePublished" : "2019-10-16T17:04:00.000Z",
  "headline" : "On Bad Solutions and Negative Returns",
  "image" : [ "https://reflare.com/hubfs/Blog%20image%20in%20post/On%20Bad%20Solutions%20and%20Negative%20Returns.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://reflare.com/research/on-bad-solutions-and-negative-returns",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://reflare.com/hubfs/Reflare%20website%20images/Reflare%20Logos/logo.png"
    },
    "name" : "Reflare"
  }
}
```