Preventive vs. Detective Controls
Preventive controls aim to stop incidents before they happen, while detective controls identify incidents that occur despite prevention, and both are essential components of a defense-in-depth cyber program.
Why the Distinction Matters
Different control types reduce risk in different ways. Preventive controls (firewalls, access controls, encryption) reduce the frequency of successful attacks. Detective controls (SIEM, IDS, DLP) reduce the impact of attacks that succeed, by shortening dwell time and enabling faster response.
A program heavy on prevention with weak detection is brittle: successful attacks produce disproportionate consequences. A program heavy on detection with weak prevention creates unnecessary incidents. Balanced programs invest in both, calibrated to the specific threat and asset profile.
Adding Corrective and Compensating
The preventive/detective split is a starting point. Fuller taxonomies add corrective controls (limiting damage after detection, restoring systems) and compensating controls (alternatives applied when a required primary control cannot be used). Some frameworks add deterrent controls (discouraging attackers) and directive controls (guiding behavior).
Preventive vs. Detective in CRQ
Quantified programs model preventive and detective controls differently. Preventive controls typically reshape frequency distributions (reducing how often events occur). Detective controls typically reshape severity distributions (reducing how large the loss is when events do occur). Investment decisions can be evaluated against the specific dimension they affect.
Related Terms
Turn Cyber Risk Into Financial Exposure the Board Can Act On
Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.


