06/19/2026
Hardest sentence in cybersecurity:
"I thought I did the right thing."
We turned on MFA last year.
We bought the antivirus the bank recommended.
We trained the team every quarter.
We had backups.
And then a phishing email got past everything, an attacker proxied the MFA token, and a wire to a "vendor" left the account before anyone noticed.
This isn't a story about bad owners. It's a story about a moving target. The control list that was enough in 2022 isn't the same control list that's enough in 2026. AiTM phishing kits make standard MFA defeatable. 340+ Microsoft 365 tenants were hit by the EvilTokens device-code phishing kit between February and April this year (The Hacker News, March 2026). 67% of all 2026 incidents traced back to identity attacks (Sophos 2026), not vulnerabilities.
If "we did the right things" doesn't always equal "we're protected," then the most useful thing an owner can do is calibrate where their readiness actually sits today, not where it was when they last reviewed it.
That calibration is the entire purpose of the Cybersecurity Self Assessment. 15 minutes. Plain language. A real picture of where you are.
https://security.sohomsp.net/