DEV Community

Serguey Shinder
Serguey Shinder

Posted on

Most Breaches Aren't Clever. They're Boring.

When people picture a breach, they picture something cinematic. A hooded figure, custom malware, a zero-day nobody's ever seen. It makes for good television. It's almost never what actually happens.

The real breaches are painfully boring. An employee reused a password that leaked in someone else's breach three years ago. A server sat unpatched for eight months because nobody owned it. A storage bucket was left public "temporarily." Someone clicked a link in an email that looked close enough to real. The intrusion wasn't a work of genius. It was an open door somebody forgot to close.

This is uncomfortable, because boring problems don't get budget. It's easier to buy an exciting new tool than to do the unglamorous work of tracking every asset, enforcing multi-factor authentication, patching on a schedule, and revoking access the day someone leaves. The exciting tool feels like security. The boring hygiene actually is security.

I've stopped being impressed by sophisticated threats and started being afraid of basic neglect. The attacker doesn't need to be brilliant if you've left the fundamentals undone. They'll take the easy path, because there's always an easy path when nobody's minding the boring stuff.

So the most valuable security work on most teams isn't hunting advanced threats. It's closing the dull, obvious gaps: know what you have, patch it, lock it down, turn on MFA, and take access away the moment it's no longer needed. It won't feel heroic. It's what actually keeps you out of the headlines.

The breach that gets you probably won't be clever. Which means the defense that saves you doesn't have to be either. It just has to be done.

– Serguey Shinder

Top comments (0)