
Buying tools is easy. Running them is the actual job.
Category : Business | Posted : May 1, 2026
Any IT company or team can swipe a credit card and sign up for intrusion monitoring, backup software, endpoint protection, and spam filtering before lunch. The vendors have made it that easy. Trial accounts, slick dashboards, a few green checkmarks, and you can tell leadership you’re “covered.” The trouble is, buying the tool isn’t the job. Running it is. We’ve watched this pattern play out in IT security and backup for twenty-five years. An organization licenses the right products, the dashboards turn green, and everyone moves on. Then something goes wrong, and the gap between “we have the tool” and “the tool actually did its job” turns out to be wider than anyone realized. Backup is the cleanest example. Industry surveys consistently find that a meaningful share of organizations who go to restore from backup don’t get all their data back. The [2024 State of the Backup Survey](https://drj.com/industry_news/2024-state-of-the-backup-survey-says-security-incidents-and-data-loss-on-the-rise/) found that only 42% of organizations who experienced data loss recovered all of their data on restore. These are organizations with backup systems in place. The tools were running. The jobs were completing. The restore still came up short. Somebody, somewhere, looked at a green dashboard last Tuesday and told themselves things were fine. The tool isn’t the thing. The human running it is. At Smart Dolphins we run a centralized services team whose whole job is making the tech, security, and backup stack do what it claims to do. We human-verify backup jobs daily. Not “the dashboard says green,” but a person confirming the job ran, the data is recoverable, and yesterday’s quiet failure isn’t sitting there waiting to ruin somebody’s week. That sounds unglamorous because it is. It’s also the part of the work that determines whether the protection you’re trusting in is real on the day you actually need it. The same logic applies to patching, to endpoint protection, to spam filtering, to identity and access. Each of those tools has a dashboard. Each dashboard can be green while something underneath is quietly broken or misconfigured or drifting out of policy. The work of catching that drift isn’t done by the tool. It’s done by someone whose job is to look, verify, tune, and fix. So when you’re thinking about your own setup, whether that’s your MSP, your internal IT team, or the security stack you’ve been told is handled, the question worth sitting with isn’t which tools you have. It’s who’s watching them, tuning them, and verifying them on a Tuesday afternoon when nothing is on fire. That Tuesday afternoon work is what determines whether the tool is an asset or an expensive illusion. Buying tools is easy. Running them is the actual job, and it always has been.
Why Are We Paying Nearly the Same Money for Less Protection?
Microsoft just raised prices across most of its business SKUs. Business Basic, Standard, E3, E5,…
MFA is on. The floor for attacking it just dropped.
MFA was on. It had been on for years. The training had been done, the…

