Stop. Check. Protect. Why Continuous Validation Matters

Written by
Nick Cross
Published on
August 23, 2026

When we think about a ‘bad actor’, it’s easy to picture someone sitting on the other side of the world, launching a sophisticated cyberattack against an unsuspecting organisation.

But the reality can be much closer to home.

A bad actor could be sitting in the same city as you. They could be using the identity of someone inside your organisation. They could be operating through a legitimate account that has been compromised and quietly behaving like a normal user.

That’s what makes modern cyber threats so difficult to detect. The initial scam might be a simple phishing email and the real attack starts when someone gains access.

This is why the message behind Scam Awareness Week – Stop. Check. Protect. – matters. But for businesses, we need to take that message one step further.

It’s not enough to ask whether someone will actually click on the link.

What happens when they do?

The scam is often just the starting point

Most organisations have invested in protecting their users.

• Email security

• Multi-factor authentication

• Endpoint protection

• Firewalls

• Security awareness training.

All of these are important.

But attackers don't necessarily need to break through every defence. Sometimes they simply need to convince a legitimate user to hand over their credentials.

Once an account is compromised, the attacker may have access to the same applications, data and services as the legitimate user.

They don't necessarily look like an attacker.

They can look like Jane from Finance.

They can access Microsoft 365, open files, send emails, access collaboration platforms. They may be able to move between systems.

The challenge is knowing the difference between legitimate behaviour and compromised behaviour.

From ‘Is this user authorised?’ to ‘Should they be trusted right now?’

This is where continuous validation comes in.

Traditional security often asks: Is this user authorised?

Zero Trust asks a different question: Should this user be trusted to do this, right now, under these circumstances?

That requires context.

• Where is the user logging in from?

• What device are they using?

• Is this consistent with their normal behaviour?

• What applications are they accessing?

• Are they suddenly downloading large volumes of data?

• Are they accessing information they don't normally use?

• Has their behaviour changed?

• Is the session itself showing signs of compromise?

Having access doesn't mean someone should automatically be trusted. The technology needs to keep checking that the activity makes sense.

Understanding normal behaviour

This is where account behaviour analysis can help.

By establishing what normal user activity looks like, organisations can identify activity that doesn't fit the usual pattern – such as an unusual login location, device, IP address or change in activity.

It can also provide useful evidence when investigating what happened before and after an account compromise. This becomes particularly important because a compromised identity can be much harder to spot than a traditional attack.

Imagine an employee normally logs into Microsoft 365 from Sydney during business hours. Suddenly, their credentials are being used from an unfamiliar location, on an unknown device, followed by access to applications and files they don't normally use.

One signal alone might not prove anything. Multiple signals together can tell a very different story.

Why cross-surface detection matters

Modern intrusions don't necessarily stay within one part of the technology environment.

Activity can span:

• Endpoints

• Networks

• Cloud services

• SaaS applications

• Identity.

The organisations that can connect those signals have a much better chance of seeing what is really happening.

This is increasingly important in environments built around Microsoft 365 or Google Workspace, where email, documents, collaboration, identity and business applications are interconnected. The security of one shouldn't be considered independently from the others.

Where Com-X stands apart

At Com-X, we don't look at cybersecurity as a collection of individual products.

We look at the environment as a whole:

• Your Microsoft 365 environment needs to work securely with your identity platform

• Your identity controls need to work with your digital workspace

• Your endpoint security needs to provide signals to your wider security environment

• Your data needs to be protected wherever users access it

• And your security team needs visibility across those surfaces.

This broader view allows us to look for the gaps between technologies – not just whether each individual product is switched on. Because sometimes the biggest security weakness isn't a missing product.

It's the gap between products.

Security needs to keep checking

The goal isn't to make security unnecessarily complicated. It's to make it appropriate to the organisation's risk, technology and way of working.

That means looking at what you already have, understanding what it can do, identifying where the gaps are and making the technology work together more effectively.

Because security isn't something you configure once and forget.

Users change.

Devices change.

Applications change.

Threats change.

And what was considered normal behaviour yesterday may look very different tomorrow.

Stop. Check. Protect. And keep validating.

Where Com-X can help

Com-X can help you assess your existing technology environment, identify gaps between security controls and build a more connected approach to cybersecurity, identity, digital workspace and data protection.

The objective isn't to add more technology for the sake of it.

It's to make the technology you have work harder for your security.

Ready to Upgrade your IT & Cybersecurity Solutions?