"You can't defend. You can't prevent. The only thing you can do is detect and respond"
About this Quote
The subtext is pragmatic, almost unsentimental: stop buying miracles. In cybersecurity, "prevent" often translates to procurement theater - the expensive box, the bold promise, the dashboard that performs competence. Schneier reframes security as an ongoing operational discipline: detection and response. That’s not surrender; it’s a shift from posture to practice. You assume breach not because you’re pessimistic, but because you’re serious about consequences.
Context matters: Schneier comes out of decades of watching cryptography, networks, and organizations collide. Even when the math is solid, people misconfigure, reuse passwords, ignore patches, click the link. Attack surfaces sprawl faster than policies can keep up. So the actionable center of gravity becomes resilience: instrument the system, notice anomalies, contain damage, recover quickly, learn.
The intent is to mature the conversation. Security isn’t a finish line; it’s incident management with better tools and clearer eyes. Detect and respond is the grown-up promise: not safety, but survivability.
Quote Details
| Topic | Privacy & Cybersecurity |
|---|---|
| Source | Help us find the source |
| Cite |
Citation Formats
APA Style (7th ed.)
Schneier, Bruce. (2026, January 14). You can't defend. You can't prevent. The only thing you can do is detect and respond. FixQuotes. https://fixquotes.com/quotes/you-cant-defend-you-cant-prevent-the-only-thing-161973/
Chicago Style
Schneier, Bruce. "You can't defend. You can't prevent. The only thing you can do is detect and respond." FixQuotes. January 14, 2026. https://fixquotes.com/quotes/you-cant-defend-you-cant-prevent-the-only-thing-161973/.
MLA Style (9th ed.)
"You can't defend. You can't prevent. The only thing you can do is detect and respond." FixQuotes, 14 Jan. 2026, https://fixquotes.com/quotes/you-cant-defend-you-cant-prevent-the-only-thing-161973/. Accessed 7 Feb. 2026.






