Article

Comfort is not security: Paula Januszkiewicz on why a clean report can still be wrong

Published on
September 11th, 2026
NIC 2026 SPEAKER SERIES "5 questions with"
We have put the same five questions to the practitioners leading sessions this October, people who spend their working days in the trenches rather than on a stage. Third up: Paula Januszkiewicz, Founder and CEO of CQURE, back on the security track with two deep technical sessions on identity and forensics.

What do you believe that most of your peers would disagree with?

I'm not sure this would be controversial among my peers, but I think we still overestimate what tools and formal security checks can guarantee. I've seen organizations with mature security stacks and recent penetration tests still suffer incidents, simply because important weaknesses were missed. That's why the quality of testing matters so much. A superficial test can be worse than people realize, because it creates comfort without necessarily creating security. For me, the strongest teams aren't the ones with the most tools or reports, but the ones that keep questioning what they may still be missing.

What do teams still accept as normal, even though it creates unnecessary risk?

Teams get used to complexity very quickly. A temporary exception stays for years, someone keeps access they no longer need, or an old protocol remains because one application still depends on it. Each decision may have been perfectly reasonable at the time. The problem comes later, when dozens of these small exceptions start connecting and nobody has the full picture anymore. That's where unnecessary risk builds up. For me, the key is regular review: not asking who made a bad decision, but simply, "Do we still need this today?"

When did something last go wrong that genuinely surprised you, and what changed afterwards?

What still surprises me isn't usually the attacker's technique. After years in incident response, the patterns are familiar. The surprise is how often simple questions become difficult during a real investigation: when did this start, which account was used, where did the attacker move next, what data was touched? Sometimes the answer isn't available because the right logs were never collected or retained. That's changed how I think about readiness. Incident response doesn't begin when the phone rings. It begins earlier, with logging, telemetry, retention, and knowing what evidence your systems can actually give you.

What is one thing someone can change on Monday morning without waiting for a project, budget, or permission?

Choose one privileged account and follow it properly. Not in a policy document, but in the real environment. Where can it log on? What groups is it in? Which systems trust it? Is it used interactively? Could its credentials end up on a workstation or server where they should never appear? This exercise takes much less effort than a large security programme, but it often exposes surprising dependencies and old assumptions. You don't need a new budget to improve security. You can start by understanding one important access path better than you understood it on Friday.

What will people experience at NIC that they cannot get from a blog post or webinar?

At NIC, people will see things happen live, not just hear the polished conclusion afterwards. We can follow an attack path as it develops, inspect what the operating system is actually doing, look at where credentials appear, and use forensic artefacts to piece together what happened step by step. That matters because real environments rarely behave exactly like a diagram or a blog post. Something unexpected always comes up. NIC also has a very technical audience, so we can stop, dig into those surprises, challenge assumptions, and go much deeper than we normally could in a webinar or recorded session.

Paula is on the security track twice, both Wednesday in Room 1: Breaking Identity at Scale: From DPAPI & TBAL Secrets to Full Domain Compromise at 1:20pm, and Windows Knows What You Did: Deep Dive into Automatic Destinations at 4:00pm.

Subscribe to newsletter

Subscribe to receive the latest blog posts to your inbox every week.

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.