Skip to main content

Science Quote by Bruce Schneier

"You can't defend. You can't prevent. The only thing you can do is detect and respond"

About this Quote

Security culture loves the fantasy of perfect walls. Schneier torches that fantasy in three clipped punches: "You can't defend. You can't prevent". The repetition isn’t just emphasis; it’s a controlled demolition of the language executives and policymakers reach for when they want certainty. Defense and prevention sound reassuring because they imply permanence. Schneier’s line insists permanence is a lie in complex systems, especially in digital ones where the attacker needs one overlooked pathway and the defender has to cover all of them, all the time.

The subtext is pragmatic, almost unsentimental: stop buying miracles. In cybersecurity, "prevent" often translates to procurement theater - the expensive box, the bold promise, the dashboard that performs competence. Schneier reframes security as an ongoing operational discipline: detection and response. That’s not surrender; it’s a shift from posture to practice. You assume breach not because you’re pessimistic, but because you’re serious about consequences.

Context matters: Schneier comes out of decades of watching cryptography, networks, and organizations collide. Even when the math is solid, people misconfigure, reuse passwords, ignore patches, click the link. Attack surfaces sprawl faster than policies can keep up. So the actionable center of gravity becomes resilience: instrument the system, notice anomalies, contain damage, recover quickly, learn.

The intent is to mature the conversation. Security isn’t a finish line; it’s incident management with better tools and clearer eyes. Detect and respond is the grown-up promise: not safety, but survivability.

Quote Details

TopicPrivacy & Cybersecurity
Source
Later attribution: Financial Services Sector Protection and Homeland Security (Frank R. Spellman, 2019) modern compilationISBN: 9781641433419 · ID: XxWbDwAAQBAJ
Text match: 95.00%   Provider: Google Books
Evidence:
... Bruce Schneier's (2000) view of security: “You can't defend. You can't prevent. The only thing you can do is detect and respond.” Simply, when it comes to making “anything” absolutely secure from intrusion or attack, there is no silver ...
Other candidates (1)
Managed Security Monitoring (Bruce Schneier, 2001)50.0%
Real-world security includes prevention, detection, and response. If the prevention mechanisms were perfect, you woul...
Cite

Citation Formats

APA Style (7th ed.)
Schneier, Bruce. (2026, March 7). You can't defend. You can't prevent. The only thing you can do is detect and respond. FixQuotes. https://fixquotes.com/quotes/you-cant-defend-you-cant-prevent-the-only-thing-161973/

Chicago Style
Schneier, Bruce. "You can't defend. You can't prevent. The only thing you can do is detect and respond." FixQuotes. March 7, 2026. https://fixquotes.com/quotes/you-cant-defend-you-cant-prevent-the-only-thing-161973/.

MLA Style (9th ed.)
"You can't defend. You can't prevent. The only thing you can do is detect and respond." FixQuotes, 7 Mar. 2026, https://fixquotes.com/quotes/you-cant-defend-you-cant-prevent-the-only-thing-161973/. Accessed 21 Mar. 2026.

More Quotes by Bruce Add to List
You cant defend You cant prevent Only detect and respond
Click to enlarge Portrait | Landscape

About the Author

USA Flag

Bruce Schneier (born January 15, 1963) is a Scientist from USA.

5 more quotes available

View Profile

Similar Quotes

Mel Brooks, Comedian
Mel Brooks

We use cookies and local storage to personalize content, analyze traffic, and provide social media features. We also share information about your use of our site with our social media and analytics partners. By continuing to use our site, you consent to our Privacy Policy.