by SOC Van Pelt

You know what feels worse than throwing an interception in the red zone when you have the chance to tie the game with a field goal?
Not much.
You probably thought I’d have something, huh? Well, I don’t. That’s about as bad as it gets. And if you watched the Patriots' brutal choke against the Seahawks last night, you saw what happens when someone tries to play hero ball and force a big play instead of staying patient.
And yeah, I’m about to tell you how this translates to your cybersecurity strategy.
When you think of the exciting parts of football, what do you picture? Probably something like Bryce Underwood’s Hail Mary to win the game against Western Michigan last weekend (regardless of how we feel about that clock). That’s football at its most exhilarating. It’s also not something you see every weekend.
We've all booed when our team decides to kick a field goal instead of going for the flashy play. But here's the uncomfortable truth: most of the time, the field goal is the right call.
Michigan's last-minute Hail Mary doesn't disprove that; it actually proves it. They weren't in field goal range, so the Hail Mary wasn't a bold choice. It was their only choice.
That's the real rule: you don't call a Hail Mary because it's a good or high-percentage play. You call it because you're out of good plays.
The Patriots didn’t need a Hail Mary or a forced ball into coverage. What you saw Drake Maye do was try to make a flashy, game-winning hero play when the safe option was sitting right there.
Companies take this exact same gamble in cybersecurity all the time. They’ll try to execute a massive, sweeping security overhaul when all they really needed was a consistent patching cadence, proper multi-factor authentication (MFA) or managed services.
But saying “We’re on a solid patching schedule now” or “All employees are using MFA” isn’t flashy, is it? It’s the humble field goal. It puts points on the board, but nobody’s parading it around or putting it on a highlight reel.
Here’s the thing, though: field goals stack up.
This week, the Patriots rushed and went for the big play instead of staying methodical. When companies overhaul their cybersecurity structure overnight and play hero ball, they end up with misconfigurations galore and may even be more vulnerable than they were before. Sometimes, stacking up those field goals is the move. If you make six field goals and your defense is strong, you may look up and see you’re winning 18-0 without doing anything flashy at all.
Of course, if the numbers favor going for the touchdown, you take it. Somewhere, an IT team is being told to 'just go for it' when the field goal is available. But what if going for it means risking the whole game? Do you force the ball into coverage? Or do you take the points and live to fight another drive?
I bet Drake Maye has an answer for you.
Share This Article

An Article By
An Article By
SOC Van Pelt
Sports & Cybersecurity Analyst
SOC Van Pelt
Sports & Cybersecurity Analyst
SOC Van Pelt is SonicWall’s resident sports and cybersecurity expert, bridging the gap between high-stakes game day strategy and enterprise threat defense. Whether breaking down why a chaotic network misconfiguration looks suspiciously like a prevent defense or arguing that IT teams should just take the field goal, SOC Van Pelt translates complex security lessons into a language real people actually want to read.