For decades, cybersecurity strategy was built around a single objective: keep attackers out. But times have changed and Andrew Rubin – Founder, CEO and Board Member of Illumio – believes the first mistake leaders make is refusing to acknowledge that breaches are now an operational reality.
True preparation begins with a change in mindset, he advises.
“It’s about recognizing and admitting that going forward, what we’ve done in the past alone is necessary, but it’s no longer sufficient,” Rubin says.
That shift requires leaders to stop judging cybersecurity as a binary contest between total safety and catastrophic failure.
Speaking on CEO: Behind the Scenes, Rubin compares breach preparation with protecting personal health: perfection is unrealistic, but limiting the severity and duration of an incident is achievable.
“You’d much rather have a small cold that lasts for a few days than have a very bad flu that lasts for weeks or months,” he says. “That narrative in the real world is the same in the cyber world.”
In practice, that means preparing to contain an attacker before an incident occurs. A compromised device should remain an isolated problem, rather than becoming the entry point to an organization-wide crisis.
But greater spending does not automatically create greater security. Rubin argues that organizations continue to add vendors and tools while overlooking whether those investments materially improve outcomes.

“The threat landscape has changed.”
“What it means is that we’re over investing in certain things that aren’t helping enough, and we’re under investing in things that we probably need to invest in today,” he points out.
“The threat landscape has changed. If we just keep buying more of the same, we’re probably going to get outcomes that don’t work any longer.”
Visibility is one of those neglected areas. Organizations can’t contain threats they can’t see, yet many lack a real-time understanding of how systems communicate, where information is moving or when unusual behavior begins. By the time leaders become aware of the breach, an intruder may already understand the environment well enough to cause extensive damage.
“If you want to protect something, the first step is to be able to see it and understand it in real time,” Rubin says.
The lesson for leaders is not to accept defeat, but to redefine preparedness so that a breach remains an incident rather than becoming a disaster.
Listen to the latest episode of our CEO: Behind the Scenes podcast with Andrew Rubin on Amazon, Apple or Spotify.
