Lesson 1 of 1 in Initial Access
The Front Doors
Four ways in cover the overwhelming majority of breaches: a phished click, a reused or stolen password, an unpatched internet-facing service, and a compromised supplier. Told through real incidents, ranked by how often each is the way it actually happened.
4 min read
Not yet reviewed
This is the part with the genius zero-day, right? The exploit nobody has ever seen?
Almost never. Why would I burn something rare on you when you will click a link, or reuse a password, or leave a known hole unpatched for eight months? I knock, or I just log in.
Which is the good news hiding in the bad. If the common way in is boring, the defence is boring too — and boring is affordable.
Legal
Every technique below is a criminal offence when used against a system you do not own or have written permission to test — phishing a real person, trying stolen passwords, exploiting an unpatched server. This chapter exists so you recognise these doors on your own house and lock them, not so you try them on someone else's.
The doors, in the order they are actually used
Rank the ways in by how often each one is how a breach really started, and the list is almost the opposite of the dramatic version. The exotic exploit is at the bottom. At the top is a person, and a password.
1. Phishing trick a human into handing over access
2. Stolen credentials a reused or leaked password, and no second factor
3. Unpatched service a known hole, public for months, still open
4. Supply chain break a supplier you trust, arrive through them
- Line 1The perennial leader. It does not attack a machine; it attacks a person's trust, which has no patch.
- Line 3Note "known". The dangerous holes are usually not secret zero-days but published ones with a fix already available — and not applied.
How people imagine the way in
A secret exploit no one has ever seen,
used once, against a specific target.How it usually goes
A password that leaked in 2019, tried
against a login with no second factor.The gap between these two pictures is where most security budgets go wrong: spent guarding against the rare and dramatic while the common and boring door stands open.
Three real front doors
In 2021 the Colonial Pipeline ransomware attack — which stopped fuel across the US east coast — began with a single leaked password to a remote access account that had no second factor. No exploit; a login. In 2017 Equifax lost the records of nearly 150 million people through a known vulnerability in a web framework (Apache Struts) that had a patch available for months before the breach. And in 2020 the SolarWinds compromise reached thousands of organisations at once by first breaking the software supplier they all trusted, then riding a poisoned update in through the front door each of them had opened for it.
Colonial Pipeline, Equifax and SolarWinds look like three completely different attacks. What do all three initial accesses have in common?
Closing the common doors
The defences map straight onto the ranking, and they are cheap relative to what they prevent: a second factor on every login defeats most phishing and nearly all stolen-password attacks at once; patching your internet-facing systems first closes the known-hole door; a password manager makes every password unique so a leak from one place cannot travel; and knowing which suppliers can reach your systems is where the fourth door starts.
Note
If you do one thing from this entire course, make it this: turn on multi-factor authentication everywhere it is offered, starting with your email. Your email is the account that can reset all the others, and a second factor is the single control that closes the two most common doors at the same time.
One thing you can do this week: list the accounts that could reset your other accounts — your email first — and turn on multi-factor authentication on every one of them. It is the highest-value hour in security, and it is free.