Cybercriminals do not need to break your best protection: they can simply go around it
When an organization invests in a new cybersecurity technology, one question naturally comes up: can this protection be hacked?
The question is legitimate. It is not, however, always the one a cybercriminal is asking.
Attackers rarely seek to prove that they can defeat the organization's most sophisticated technology. Their objective is generally far more concrete: accessing an account, stealing data, obtaining privileges, disrupting operations, diverting money, installing malware, or maintaining a presence in the systems.
How they get there ultimately matters rather little. If a protection is extremely difficult to break, the attacker can simply look for another path.
Recent advances in authentication illustrate this reality perfectly. Passkeys, for example, neutralize several traditional forms of phishing by eliminating the password a user might unwittingly hand over to a fraudster. That is a considerable advance. Yet researchers continue to explore techniques for reaching the desired objective by intervening elsewhere in the process. In doing so, they remind us of a fundamental rule of cybersecurity: an attacker does not necessarily need to break your best protection when they can find a way around it.
The attacker is looking for a result
To understand the problem, you have to look at the digital environment from the point of view of whoever is trying to compromise it. Imagine an organization that has just deployed a particularly robust authentication method. From the company's point of view, this technology represents a new line of defense. From the attacker's point of view, it simply represents a change in the terrain.
- An attack method becomes less effective? They look for another one.
- Authentication becomes hard to compromise? They turn to account recovery.
- The account is strongly protected? They try to hijack an already authenticated session.
- The server is hard to reach? They examine the workstations.
- Employees are well trained? They turn to the suppliers.
- Administrative privileges are strongly protected? They look for an account with enough permissions to make progress.
This logic matters because it changes how an organization should assess its own security. The question is no longer only whether a protection can be broken. You have to seek to understand which other paths would make it possible to achieve the same result.
The attack path matters more than the front door
A cyberattack can be thought of as a sequence of steps.
- The attacker gains an initial presence.
- They discover their environment.
- They look for interesting identities or resources.
- They attempt to obtain more privileges.
- They move toward other systems.
- They finally seek to reach the data or capabilities that represent their true objective.
The first compromise is therefore not necessarily the most dangerous event. What matters is what it enables next. A compromised user account with very few privileges in a heavily segmented environment may have limited reach. The same account, in an environment where systems are widely interconnected and privileges are too generous, can become the starting point of a far larger compromise. Security must therefore be thought of in terms of possible paths.
If this protection falls, how far can someone go? That question is often far more revealing than: “Is this technology secure?”
Phishing evolves along with protections
Phishing is an excellent example of this capacity for adaptation. For a long time, its main objective was simple: convince a user to provide their username and password on a fake page. Multi-factor authentication made that approach less effective. Attackers then developed new techniques. Some sought to obtain the temporary codes. Others used MFA fatigue techniques by flooding users with approval requests. Still others sought to intercept sessions or exploit various steps surrounding the authentication process.
Passkeys now make several of these scenarios much more difficult. Attackers and researchers are therefore turning their attention to other components of the process. This evolution should be interpreted positively: new protections really do force attackers to work harder. But it also demonstrates why no protection should be considered in isolation. When we close a door, the adversary immediately starts looking for the windows.
The best defense is to multiply the obstacles
If an attacker looks for the easiest path, an effective cybersecurity strategy must make all the important paths progressively harder. This is one of the reasons defense in depth remains essential. Strong authentication protects identity.
The principle of least privilege limits what an identity can do. Segmentation reduces the movements possible between systems. Monitoring makes it possible to detect unusual behavior. Encryption protects the data. Rigorous session management reduces certain hijacking opportunities. Response mechanisms make it possible to contain an incident quickly.
None of these measures carries the organization's security on its own. They reinforce one another.
An attacker who manages to get past one protection must then face another, and then another. At a certain point, the cost, the time, the risk of detection, and the complexity of the attack become significant enough to considerably reduce their chances of success.
Zero Trust: verifying continuously rather than just once
This approach also explains the importance of Zero Trust. In a traditional architecture, a successful authentication could sometimes open relatively broad access to the environment. Zero Trust rests on a different logic. Identity remains important, but it is only one element of the decision:
- Which device is being used?
- What is its security posture?
- Which resource is being requested?
- Is this request consistent with the user's role?
- Is the observed behavior normal?
- Has the risk level changed since authentication?
A legitimate identity can be compromised. A legitimate session can be hijacked. An authorized device can become vulnerable. Trust must therefore be assessed continuously. This approach considerably reduces the value of a first compromise for the attacker. Entering the environment becomes merely the first step of a journey that remains tightly controlled.
The human factor does not disappear
Technological progress reduces certain forms of human error. That is an excellent thing. A well-designed system should avoid asking users to be constantly capable of distinguishing an extremely sophisticated attack from a legitimate interaction. People nevertheless remain an important component of the organization.
Cybercriminals can target employees, managers, technical support, suppliers, and even executives. Artificial intelligence, moreover, increases the potential quality of these manipulations. Fraudulent communications can be personalized. Voices can be reproduced. Images and videos can be fabricated. Public information can be analyzed quickly to prepare far more credible manipulation scenarios.
The response therefore cannot rest on awareness training alone. The processes themselves must be designed to resist manipulation. An unusual financial request may require independent validation. A sensitive account recovery may require several verification mechanisms. A change to significant privileges may require additional approval. Technology and processes must work together to protect people.
Suppliers can become an alternative path
An organization can also have excellent internal cybersecurity and depend on dozens, even hundreds, of suppliers. SaaS software, cloud services, consultants, partners, payment systems, communication platforms, APIs, and technology providers all become digital relationships with the organization. Some hold access. Others handle data. Still others run essential code or services. For an attacker, these relationships can represent alternative paths.
Why attack a heavily protected company directly if one of its suppliers holds access that makes it possible to reach part of its environment? Third-party risk management therefore becomes a direct component of the cybersecurity architecture. The organization must understand not only its own protections, but also its dependencies.
Artificial intelligence creates new paths
Integrating AI into operations will add still more possibilities. Artificial intelligence agents will be able to consult data, use applications, call APIs, produce documents, trigger processes, and sometimes make certain decisions.
To function, they will need identities and permissions. They will therefore themselves become components of the access paths to systems. A new question will gradually appear in security analyses:
If this AI agent is manipulated, compromised, or led to act incorrectly, how far can it go?
This question closely resembles the one we already ask about a compromised human account. The principles therefore remain the same: minimal permissions, segmentation, control over sensitive actions, traceability, monitoring, and the ability to intervene. As systems become more autonomous, these principles become even more important.
Thinking like the attacker without waiting for the attack
Organizations can gain a considerable advantage from a change of perspective. Instead of waiting for an attack to reveal an unexpected path, they can look for those paths themselves.
- What could an attacker do after compromising a workstation?
- What could they reach with a user account?
- What would happen if they obtained an already authenticated session?
- Which supplier could become an intermediary?
- Which data would be accessible?
- Which systems would allow lateral movement?
- Which combination of permissions could become dangerous?
- Which mechanisms would make it possible to detect that progression?
This kind of analysis makes it possible to go beyond an inventory of security technologies. It makes it possible to understand how the organization actually defends itself when an adversary starts looking for its own way in.
Cybercriminals operate in the same technological environment as the organizations they target. When defenses advance, their methods evolve. When a technology closes off one avenue of attack, they look for another option. This dynamic will continue. Authentication will become more robust. Biometrics will advance. Encryption will evolve. Zero Trust architectures will become widespread. Artificial intelligence will strengthen defensive capabilities. And attackers will keep looking for the spaces left between these protections.
An organization's resilience therefore depends on its ability to understand its possible attack paths, limit privileges, segment its environments, monitor behaviors, and prepare its teams to react when a protection is bypassed.
At Quantum Beyond, our experts support the IT, cybersecurity, and management teams already in place in order to strengthen this capability. They bring complementary expertise that makes it possible to examine architectures from different angles, put certain security scenarios back to the test, and identify attack paths that can cut across several systems, technologies, or processes.
This collaboration allows internal teams to retain their operational control while benefiting from an additional perspective to strengthen their environment. Because an attacker will always look for the path that seems most accessible to them. The objective of a resilient organization is to ensure that every path leads to another protection.
