Cybersecurity teams have long been focused on identifying and patching “attack surfaces” – areas of a system or network where vulnerabilities can be exploited by attackers. But a growing body of evidence suggests that this approach is missing the mark, as hackers are increasingly using complex chains of techniques to breach even seemingly secure systems.
Take, for example, the case of an unnamed financial institution whose employees were unwittingly used as pawns in a high-stakes attack. It began with a phishing campaign targeting a specific subset of staff, who were tricked into clicking on a malicious link that installed malware on their devices. From there, the attackers exploited the network privileges granted to these compromised accounts to gain access to sensitive data and launch further attacks across the organization.
But here’s the key: this was not just about individual vulnerabilities or “attack surfaces” – it was about creating an active attack path, where multiple techniques were used in sequence to achieve a specific goal. The attackers had mapped out the network, identifying choke points where they could exploit privilege escalation and create a “bottleneck” for their malicious activities.
This type of scenario is not unique, unfortunately. According to research, over 80% of data breaches involve some form of identity exposure – often through phishing or other social engineering tactics. And once an attacker has gained access to a compromised account, the damage can be catastrophic, as seen in the case of a major healthcare provider whose network was breached after an employee clicked on a malicious email.
So what does this mean for cybersecurity teams? It’s time to shift our focus from patching individual vulnerabilities to understanding how attackers are using complex attack chains to breach our systems. This requires a more nuanced approach, one that takes into account the intricacies of modern networks and the ways in which attackers can use privilege escalation, lateral movement, and other techniques to achieve their goals.
In practical terms, this means moving beyond traditional threat modeling and towards a more proactive, risk-based approach – one that prioritizes the identification and mitigation of high-risk attack paths. By doing so, we can better anticipate and prepare for the types of attacks that are increasingly becoming the norm in today’s digital landscape.
Source: The Hacker News — 2026-09-15