Breakpoint Blog

Benjamin Mossé • 07 Oct 2025

The Basics Aren't So Basic

Let’s drop the slogans and face the facts.
For a decade, people have preached “focus on the basics” as if saying it makes it so.
They’ve likely never tried to bring even a mid-sized organization up to those basics.

Take multi-factor authentication.
You start by identifying every app in use, only to find a swarm of shadow IT. You must understand what each app does, what data it handles, and who owns it. Then comes enrolling them all into SSO with MFA.

In sectors like healthcare, you’ll hit legacy apps that simply cannot do MFA. So you isolate them behind Zero Trust controls if the vendor even cooperates.

Then there are shared accounts, old processes, contractual dependencies, systems that cannot be re-engineered overnight. Each requires negotiation, testing, coordination.

When you probe further, say, a social engineering test against your MSP or SaaS provider, you learn that MFA can be undone with one polite phone call. Another fire to put out.

And still, users will sign up for new AI tools tomorrow, uploading sensitive data without SSO.

Now multiply that across thousands of users, across every device, cloud, and app. That is what doing the basics really looks like.

“Focus on the basics”. The phrase sounds comforting. But comfort is not security.
It is time we stop preaching hygiene and start teaching how to manage credentials at scale, with realism, effort, and cost disclosed in full transparency.

Recent Blog Posts

Benjamin Mossé • 06 Oct 2025

Understand First, Then Do Security

When I look back, the biggest progress I’ve seen in cybersecurity hasn’t come from new tools or f...
Benjamin Mossé • 05 Oct 2025

Mike Burgess's Five Knows of Cyber Security

Back in 2015, Mike Burgess introduced his mental model called “The Five Knows”, a framework built...