Lesson 1 of 1 in The Whole Chain, Defended
Breaking One Link
The attacker needed every stage to succeed in order. You need only one of them to fail. Read the chain backwards and it stops being a list of fears and becomes a short list of cheap, early habits that break most attacks before they are ever a crisis.
4 min read
Not yet reviewed
That was a lot of ways to lose. Reconnaissance, the way in, staying, climbing, spreading, the payday. It feels hopeless.
Look at it backwards. For any of that to reach the payday, the attacker had to win every single round, in order. You do not have to win them all. You have to make one of them fail.
That is the part I do not enjoy you knowing. My chain is only as strong as its weakest link — and you get to choose which links exist.
Legal
This chapter gathers up the whole attack you have studied. The line has been the same at every stage and holds here: understanding the chain is how you break it on your own systems. Using any of it against systems you do not own or have permission to test is a crime, and knowing the damage first-hand is exactly what should make that easy to refuse.
The chain only holds if every link does
An attack is a sequence, and a sequence has a beautiful weakness: break any one link and the whole thing stops. The attacker must get in *and* stay *and* climb *and* spread *and* get out with something worth money. The defender who breaks the second step never has to worry about the fifth. This is the asymmetry in your favour, and most of security is learning to use it.
Reconnaissance don't hand them the map; assume public is public
Initial access MFA everywhere, patch what's exposed, unique passwords
Persistence rotate credentials and revoke tokens, not just malware
Privilege escal. least privilege; no secrets in files; patch internally
Lateral movement segment the network; unique local passwords
Exfil & extortion tested backups; encrypt at rest; hold less data
- Line 2One line does most of the work. Multi-factor authentication breaks the two most common ways in at once, which is why it is the first thing on every list in this course.
- Line 6By the time you are defending here, the attack has already succeeded five times. Cheaper to have broken it above.
If you could add only one control to an organisation that had none, and it had to give the most protection for the least cost, what would you choose — and why does the chain make the answer obvious?
Break it early, break it cheap
The links are not equally expensive to break. Near the end — detecting exfiltration, recovering from ransomware — the controls are costly and the damage is already partly done. Near the start — a second factor, a patch, a unique password — the controls are nearly free and nothing has happened yet. The whole art is to move your effort toward the front of the chain, where it buys the most and costs the least.
Defending late
Detect the data leaving.
Recover from the encryption.
Explain the breach to customers.Defending early
A second factor stops the login.
The story ends at the first link.
There is nothing to explain.Both columns "work" in that both can stop a loss. Only one of them stops it before it is a loss. Early is not just cheaper; it is the difference between a non-event and an incident.
The whole thing you can do this month
You have collected a "this week" action at the end of every chapter. Here they are in one place — the short, cheap list that breaks the common chain at several links at once. None of it needs a budget, and together it puts you ahead of most of the internet.
Note
Turn on multi-factor authentication everywhere, starting with your email. Use a password manager so every account has a unique password. Turn on automatic updates, and patch anything internet-facing first. Check what has already leaked about you and retire those passwords. Test a backup by actually restoring it. Put untrusted devices on a guest network. Do your everyday work as a standard user, not an administrator. And name your realistic attacker, so the rest is aimed at the right one.
The last thing to carry away is the asymmetry itself. It can feel, reading about attackers, as though they hold all the advantages — the surprise, the patience, the choice of when. But they carry a burden you do not: they have to be right every time, at every link, and you only have to be right once. Choose your one link, break it early, and most of the story never gets told.