Detection vs Prevention Balance
Zero Breaches. Three Near-Misses. Prevention Working. Breach Record Not Telling the Story.
5 min read · 21 July 2026 · Security
A pharmaceutical research company evaluated two vendors for a clinical trial data management contract , both with clean breach records over the past three years. The evaluation treated the clean breach records as equivalent positive indicators. The security assessments then diverged sharply. Vendor A had a mature prevention programme , email security that blocked ninety-four percent of phishing attempts, EDR that caught and quarantined three malware samples before execution, and a vulnerability management programme that had patched a critical vulnerability within forty-eight hours of publication. Their security operations team had documented three significant prevented attack attempts in the preceding eighteen months. They shared these near-miss records as evidence of security programme effectiveness. Vendor B had an equivalent clean breach record achieved through different means , a more conservative approach with lower threat exposure, fewer external-facing systems, and a smaller attack surface that had simply attracted less attacker attention. When the pharmaceutical company probed the two vendors' detection and prevention histories, the difference became apparent: Vendor A had been actively attacked and had successfully prevented the attacks. Vendor B had experienced less attack activity and had fewer data points to demonstrate prevention capability. The clean breach records were identical. The security programmes behind them were not.
What is the Detection vs Prevention Balance Problem, Really?
The detection versus prevention balance problem in vendor security assessment is the challenge of understanding whether a vendor's clean breach record reflects effective prevention capability or simply low attack exposure. Both produce the same breach record. Only prevention capability provides assurance that the vendor's security programme will perform effectively when attack pressure increases , which it will if the vendor's data or platform access makes them a higher-value target over time.
The near-miss visibility gap is the structural measurement problem. Prevention success is measured by events that did not happen , phishing emails that were blocked before reaching users, malware that was quarantined before execution, vulnerabilities that were patched before exploitation. These successes are recorded in security programme operational data , email security block rates, EDR quarantine logs, vulnerability remediation timelines , but they are not typically disclosed in vendor breach assessments because they are not breaches. The breach record reflects only the failures of the prevention programme. The near-miss record reflects its successes.
The attack pressure calibration problem is the supply chain dimension. Vendors who hold valuable data , intellectual property, regulated health or financial data, research data , attract higher attack pressure than vendors with less valuable holdings. A vendor whose security programme has been tested under significant attack pressure and has successfully prevented breaches provides a different quality of assurance than a vendor who has attracted minimal attack activity. The clean breach record is identical. The assurance quality is different.
- Clean breach record not distinguishing effective prevention from low attack exposure
- Near-miss data not disclosed or not requested in vendor assessments
- Prevention capability undemonstrated without attack exposure history
- Equivalence assumed between different clean breach record origins
- Attack pressure assessment absent , vendor's data value and attack attractiveness not evaluated
Why this matters
Detection versus prevention balance matters for TPRM because supply chain targets are specifically selected for their access to high-value data , and vendors who hold or process high-value data will face increasing attack pressure as their data value becomes known to threat actors. A vendor whose clean breach record is built on low attack exposure rather than effective prevention may not maintain that record as attack pressure increases. Understanding the origin of the clean breach record , prevention capability or low exposure , informs the forward-looking risk assessment that TPRM requires.
Where most teams get this wrong
The most consistent failure is treating breach records as the primary security effectiveness indicator without assessing the prevention activity that underlies them. The prevention programme is more informative than its record of failures.
- Breach record treated as primary effectiveness indicator
- Near-miss history not requested in security assessments
- Prevention programme operational data not assessed , block rates, quarantine rates, patch timelines
- Attack pressure not assessed , vendor's data value and attractiveness to threat actors
- Clean record equivalence assumed across different security programme origins
What good looks like
Mature detection and prevention assessment programmes request near-miss operational data alongside breach records , specifically email security block rates, malware prevention rates, vulnerability remediation timelines, and any documented significant prevented attack attempts , to assess prevention capability rather than only prevention record.
- Near-miss history requested , significant prevented attacks in last two years
- Prevention programme metrics , email block rates, EDR quarantine rates, patch timelines
- Attack pressure assessment , vendor's data value and historical attack targeting
- Prevention capability vs prevention record , distinguishing programme effectiveness from exposure history
- Forward-looking assessment , will the programme maintain its record under increasing attack pressure
Tooling
Email Security , Proofpoint, Mimecast with block rate reporting
Email security platforms provide block rate statistics that are a direct indicator of prevention programme effectiveness , the fraction of malicious emails detected and blocked before reaching users. For TPRM practitioners, asking vendors for their email security block rate and the volume of blocked phishing attempts in the last twelve months provides a specific prevention programme effectiveness metric.
Governance challenges
The governance challenge with near-miss disclosure is vendor sensitivity. Vendors are reluctant to disclose that they were attacked , even successfully prevented attacks , because disclosure creates the impression of being targeted. The governance resolution is framing near-miss requests as evidence of prevention capability rather than evidence of vulnerability , which requires educating both the assessment team and the vendor on why prevented attacks are positive indicators.
- Request near-miss history framed as prevention capability evidence
- Ask for prevention programme metrics , block rates, quarantine rates, patch timelines
- Assess attack pressure , vendor's data value and sector targeting history
- Distinguish clean record origins in risk assessment
- Weight prevention capability alongside breach record in security posture assessment
If you are a small team
For each vendor assessment, ask two questions alongside the breach history question. First: in the last two years, have you had significant security events that were detected and prevented before becoming breaches , and if so, what were the attack types and how were they stopped? Second: what is your email security block rate for malicious emails, and how many malware samples has your EDR quarantined before execution in the last twelve months? Those two questions reveal whether the clean breach record is built on prevention capability or low attack exposure.
- Ask for significant prevented attack history alongside breach history
- Ask for email security block rate and EDR quarantine statistics
- Assess attack pressure , vendor's data value and sector targeting
- Distinguish prevention capability from prevention record
What to require
Ask directly:
"Beyond breach history , can you share near-miss events where significant attacks were detected and prevented in the last two years, along with your email security block rate and EDR quarantine statistics? We view successful prevention as a positive capability indicator."
Expect as evidence
- Near-miss history , significant prevented attacks
- Email security block rate and volume
- EDR quarantine statistics
- Vulnerability patch timelines for critical vulnerabilities
A vendor who confirms a clean breach record should be asked for the prevention programme metrics that explain it. The breach record shows what was not stopped. The prevention metrics show what was.
How to evidence it
- Near-miss history assessment records
- Prevention programme metrics
- Attack pressure assessment
- Detection vs prevention balance evaluation
Key Takeaway
Zero breaches. Three prevented attacks. One hundred and forty-seven thousand phishing emails blocked. Three malware samples quarantined. One critical vulnerability patched in forty-eight hours. The clean breach record and the rich near-miss record are both present. The assessment that asks only about breaches sees the record of failures , which is empty , and misses the evidence of prevention capability. The prevention programme is demonstrated by what it stopped. The breach record only reflects what it did not. Ask for the near-miss history. Ask for the block rates. The clean breach record is the outcome. The prevention programme is the explanation.
Speak to It™
The term you nodded along to, explained in ninety seconds, so you can speak to it professionally. It is how most readers find these articles.
Join the Association