# Cybercriminals: the 'auditors' you never hired

DevFeed: [Cybercriminals: the 'auditors' you never hired](<https://devfeed.tech/articles/cybercriminals-the-auditors-you-never-hired-8331.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/cybercriminals-auditors-never-hired/>)

Author: Steven Connolly

Published: 2026-06-09T08:50:00Z

Content type: opinion

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Business Security](<https://devfeed.tech/topics/business-security.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [blog-post](<https://devfeed.tech/tags/blog-post.md>), [breach](<https://devfeed.tech/tags/breach.md>), [business](<https://devfeed.tech/tags/business.md>), [business-security](<https://devfeed.tech/tags/business-security.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>)

## AI overview

The article examines normalcy bias in cybersecurity and argues that organizations may mistake the absence of obvious alerts for safety. It connects delayed responses and normalized breach risk with the continued rise in significant cyber incidents, citing figures from the NCSC Annual Review 2025.

## Source excerpt

Every organisation gets audited. The question is who does the auditing.