security is a process, not a product
expressionsecurity
Bruce Schneier's reminder that security is a process, not a product - nothing you buy makes you done.
Products help, but threats move, configurations drift, and people change; what endures is the loop of assessing, patching, monitoring, and responding. Anyone selling total security in a box is selling the noun without the verb.
Bruce Schneier's formulation is that security is a process, not a product, and it is aimed at the assumption that a purchase can resolve a security problem. Products are components in a process; they are not the thing itself, and treating a deployment as a conclusion is how organizations end up well equipped and badly protected.
The reasoning is that the environment moves continuously. New vulnerabilities are disclosed, attackers change technique, the systems being defended change every sprint, staff join and leave, and business requirements alter what is acceptable. A configuration that was correct in March is a set of assumptions that have been decaying since. Nothing about that is fixable by buying a better version of the same appliance.
What the process actually consists of is unglamorous and continuous: knowing what you have, patching it, monitoring it, reviewing access, rehearsing incidents, and revisiting decisions when the conditions that justified them change. None of it produces a certificate to hang on a wall, which is precisely why it competes badly for budget against a product that does. The organizations that do it well tend to be the ones that stopped asking what to buy and started asking what to operate.