Most people picture a cyber attack as a genius in a hoodie guessing passwords forty thousand times an hour. That picture is wrong, and believing it is genuinely dangerous.
Real intrusions are not genius. They are processes — a repeatable chain of steps, each one individually unremarkable, followed by hand to hand until someone reaches a system worth taking. Almost every serious breach ever reported looks boring in retrospect. The organisations that got hurt did not fail because their attacker was brilliant. They failed because one link in the chain was weak and nobody closed it.
This is the cyber attack chain: the path an attacker walks from first contact to the damage they do. Understanding it is the difference between reacting to breaches and preventing them.
The framework below follows the structure that the MITRE ATT&CK knowledge base popularised and that most security teams now use to describe real intrusions.
The Cyber Attack Chain, Stage by Stage
| Stage | What the attacker is doing | The control that breaks it |
|---|---|---|
| Initial access | Getting a foothold | MFA, patching, user training |
| Execution | Running their code | Application allow-listing, EDR |
| Persistence | Surviving a reboot | Patch cadence, credential hygiene |
| Privilege escalation | Becoming admin | Least privilege, no shared logins |
| Lateral movement | Spreading sideways | Network segmentation |
| Exfiltration | Copying the data out | DLP, egress monitoring |
| Impact | Ransomware, fraud, destruction | Offline backups, segmentation |
Two features of this table decide whether you survive. First, the chain is sequential — break any single link and the whole intrusion stalls. Second, it is not instant. In most real cases the gap between first access and final damage is measured in days or weeks. That dwell time is the single most important fact in this entire article, and we will come back to it.
Stage 1: Initial Access — Almost Always Something Boring
This is where breaches are won or lost, and it is where almost everyone overestimates the threat. Attackers rarely break in through a sophisticated exploit as their opening move. The CISA data and most incident post-mortems point to the same small set of mundane entry points:
- A reused password on a service with no MFA. Attackers do not guess. They take credential lists from previous breaches and try them elsewhere at scale, a technique called credential stuffing. It works because people reuse passwords.
- A convincing phishing message. Not clumsy Nigerian-prince spam. Realistic fake invoices, fake delivery notifications, password-reset emails that route to a genuine-looking login page.
- An unpatched internet-facing system. Security updates exist for a reason. Systems running known-vulnerable software are not “targeted” — they are scanned for continuously by automated tools.
- Someone with access simply giving it away. A contractor with valid credentials. A support engineer talked into resetting a password. A password read aloud over a phone call.
Notice that three of those four have nothing to do with hacking. That is the point. The entry to the chain is usually a business-process failure, not a technical one.
Stage 2-4: Getting Comfortable and Taking Over
Once inside, the attacker’s problem changes. They are no longer breaking in; they are settling in. The technical term is footing, and the tactics are well documented in the OWASP Top 10 and the MITRE framework.
They will try to run their tooling, hide it from antivirus, install something that survives a reboot, and then quietly escalate from an ordinary user account to an administrator. The most effective controls here are unglamorous:
| Control | Why it works | Effort |
|---|---|---|
| Least privilege | Stops a single stolen password becoming a domain takeover | Low, ongoing |
| No shared logins | Removes the single biggest forensic blind spot | Low |
| Multi-factor authentication | Breaks the credential-stuffing chain outright | Low |
| Phishing-resistant MFA | Survives fake login pages that steal real MFA codes | Medium |
| Patch cadence | Removes the automated footholds before they are used | Medium |
The NIST Digital Identity Guidelines are the reference for doing the identity half of this properly, and they are worth reading even if you are a one-person business.
Stage 5: Lateral Movement — Why Segmentation Matters
This is the stage most small organisations have never thought about, and it is where a small incident becomes a catastrophe.
Lateral movement simply means the attacker uses access they already have to reach somewhere they should not be. If your invoicing laptop, your CCTV recorder, your solar inverter’s monitoring interface and your staff Wi-Fi are all on one flat network, then compromising any one of them is effectively compromising all of them. There is no boundary to cross.
Segmentation is the fix, and it is far less expensive than people assume. Even a basic home or small-office setup can separate three things:
- Trusted devices — your laptops and phones, which can talk to everything
- Untrusted devices — TVs, speakers, cameras, and anything with a default password, which can reach the internet but not your computers
- Critical systems — routers, inverters, file servers, which accept no inbound connections from anything but an admin device
We wrote about securing monitoring systems in more detail in solar inverter security and smart monitoring, and the same segmentation logic in Wi-Fi and router security applies here.
Stage 6-7: Exfiltration and Impact
The endgame depends entirely on what the attacker wants. Money, data, reputation, or just disruption.
Ransomware sits here, and it is now a business model rather than a piece of software: access is obtained, a portion of your data is stolen, and you are threatened with public release unless you pay. This is covered properly in ransomware and small business.
The important defensive fact is that this stage is the hardest for the attacker and the easiest for you. Offline, tested backups, correctly scoped credentials, and network segmentation make the difference between a bad week and the end of a business. We discuss how to prepare in password security in 2026 and how attackers obtain credentials in the first place in the cyber attack chain.
The One Number That Matters: Dwell Time
Here is the statistic that should reframe how you think about all of this. In many mature environments, the gap between an intruder first getting in and their final disruptive action is days to months.
That window is a gift, and it is the entire basis of modern detection. EDR, log monitoring, anomaly alerts and network segmentation all exist to convert that silent period into an alarm.
For a small business without a security team, you can capture a meaningful slice of it with almost no budget:
- Turn on login and MFA logs for your email and cloud accounts, and actually look at them monthly
- Set a calendar reminder to review the list of devices connected to your network
- Turn on login alerts on anything that sends or receives money
- Keep one offline backup you have tested restoring from
None of this is advanced tooling. All of it converts a potential six-month silent intrusion into something you would notice in a day.
Why Boring Wins
The most useful takeaway from studying real intrusions is how unimpressive they are. A chain that starts with a password that appeared in a breach three years ago, escalates because one user was local administrator, spreads because the network was flat, and ends with a demand for payment is not a story about elite hackers. It is a story about five separate controls that were never implemented.
You do not need to out-resource anyone. Understanding the cyber attack chain is enough, because the earliest, cheapest link to break is the first one. Every stage of this chain has a control, and the four highest-value controls in the whole framework are multi-factor authentication, unique passwords, prompt patching and network segmentation. None of them is expensive. All of them are cheap compared to one incident.
Frequently Asked Questions
What is the cyber attack chain?
A sequence of stages an attacker works through, from gaining initial access through execution, persistence, privilege escalation, lateral movement and exfiltration to final impact. The MITRE ATT&CK framework is the standard vocabulary for describing it.
What is the most common initial access method?
Stolen or reused credentials, most often from an earlier breach, tried against other services. Phishing and unpatched internet-facing systems are the other two common entry points. Genuine zero-day exploitation is rare in real intrusions.
How long does a typical cyber attack take?
Compromise itself can take minutes, but the gap between first access and final damage is usually days to months. That dwell time is what gives defenders a chance to detect and respond.
Can small businesses defend against the attack chain?
Yes, and the highest-value controls are cheap: multi-factor authentication, unique passwords in a password manager, prompt patching, network segmentation, and tested offline backups. Each of these breaks a different link.
Is it true that most breaches take months to discover?
Frequently, yes, and it depends heavily on organisation size and logging maturity. This is the strongest argument for turning on and reviewing access logs — the detection gap is where most damage is done.
Key Takeaways
- The attack chain is sequential. Break one link and the intrusion stalls.
- Initial access is usually a credential problem, not a technical one.
- Flat networks are why small incidents become total ones. Segment.
- Dwell time is your advantage, but only if you are logging.
- MFA, unique passwords, patching, segmentation and offline backups cover most of it.
Next: how attackers get hold of your passwords in the first place, and how to protect your router and home network.
Image: “Data Centre Server Racks” by BalticServers.com, CC BY-SA 3.0, via Wikimedia Commons.
Sources: MITRE ATT&CK · CISA: Recognize and Report Phishing · OWASP Top 10 · NIST SP 800-63B Digital Identity Guidelines
0 Comments