Corporate & Thought Leadership

The SOC Van Pelt Report: What the Rams and Chargers Teach Us About Security Spending

by SOC Van Pelt

Two Week 1 blowouts, one shared cause: expensive upgrades that were never configured to work. 

You know what’s worse than a bad defense? A bad defense you paid a fortune for. And you know what’s worse than that? Finding out afterward that the expensive thing wasn’t broken, it was just misconfigured out of the gate.

If you watched the Rams get run out of Melbourne by the 49ers, or the Chargers blow a fourth-quarter lead to a Cardinals team that hadn’t won a game in over a year, you saw two different versions of the same problem: spending big doesn’t fix anything if the setup underneath it is off.

With the game being in Australia, there’s a VPN joke here somewhere, but I’ll leave that to people with punnier minds among us. 

The Rams: All-Star Hardware, Bad Configuration

The Rams didn’t just build a defense this offseason, it felt like they drafted a fantasy football roster and put it on the field for real.. Aaron Donald came out of retirement. Myles Garrett and Trent McDuffie arrived via trade. Jaylen Watson signed in free agency. On paper, this unit should have needed its own PSA grading. 

But something that looks good on paper doesn’t always turn out. And the guy everyone was most excited about didn’t even get on the plane (McVay held Donald back to build up conditioning). The rest of the star-studded defense took the field anyway and got steamrolled for 27 points. Because, functionally, the defense wasn’t properly configured. Elite pieces, installed separately, never actually set up as one system.

The Chargers: New Scheme, Same Old Collapse

Meanwhile, the Chargers spent the entire offseason rebuilding an offensive line that finished dead last in the league in pass block win rate, which is a truly special way to end a season. They fired their OC and O-line coach, hired Mike McDaniel, and brought his offensive line coach over from Miami. They drafted linemen. They signed linemen. They committed real money to fixing the one thing sabotaging Justin Herbert year after year.

Then their big free-agent center signing tore his ACL before Week 1 even started, a rookie got shoved into the fire, Herbert got sacked three times, and the Chargers coughed up a fourth-quarter lead to finish the day looking exactly like the team they were supposedly done being. The plan wasn’t wrong. The plan just had a single point of failure, and when that hardware failed, there was no adequate backup plan.

Here’s How This Translates to Your Cybersecurity Strategy

Does any of this sound familiar? It should. Companies do this constantly. They buy the best firewall on the market, roll out a shiny new EDR platform, or hire a big-name consultant to overhaul the security program, and then act shocked when the breach happens anyway. Nine times out of ten, the tool wasn’t the problem. The misconfiguration was.

The Rams’ defense wasn’t bad. It was unintegrated, the security equivalent of buying four best-in-class tools and never actually configuring them to talk to each other. Default settings everywhere, no one tuning the alerts, nobody testing how the pieces work as a system. Aaron Donald on the couch doesn’t sack anybody, and a firewall still sitting on its factory defaults doesn’t stop anybody either.

The Chargers’ offense wasn’t bad either. It was one misconfigured dependency away from collapse, the equivalent of a security architecture that only works if every single piece performs exactly as planned, with no fallback when one of them doesn’t. The moment that one setting broke, so did everything built on top of it.

Buying the best hardware, hiring the best people, and drawing up the best plan all still require the boring part: configuring it correctly, testing it under pressure and building in a backup for when something breaks anyway. The Rams and Chargers will get more reps. So will your security stack, if you let it. Don’t let your security stack operate in week one mode indefinitely. 

But here’s where the analogies fall short. The Chargers and Rams can turn things around next Sunday. For the rest of us, there’s no week two to bounce back after a breach.

Share This Article

An Article By

SOC Van Pelt

Sports & Cybersecurity Analyst

SOC Van Pelt is SonicWall’s resident sports and cybersecurity expert, bridging the gap between high-stakes game day strategy and enterprise threat defense. Whether breaking down why a chaotic network misconfiguration looks suspiciously like a prevent defense or arguing that IT teams should just take the field goal, SOC Van Pelt translates complex security lessons into a language real people actually want to read.

Related Articles

  • Threat Intelligence del primo semestre 2023: Sulle tracce dei cybercriminali che agiscono nell’ombra
    Read More
  • I nuovi dati di Threat Intelligence rivelano una crescente ondata di cryptojacking
    Read More
  • I dati più recenti sulle minacce testimoniano i cambiamenti nel panorama cyber nel 2022
    Read More