惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Engineering at Meta
Engineering at Meta
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
腾讯CDC
宝玉的分享
宝玉的分享
量子位
Recent Announcements
Recent Announcements
Martin Fowler
Martin Fowler
J
Java Code Geeks
V
Visual Studio Blog
阮一峰的网络日志
阮一峰的网络日志
Blog — PlanetScale
Blog — PlanetScale
大猫的无限游戏
大猫的无限游戏
博客园 - 叶小钗
S
SegmentFault 最新的问题
B
Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 【当耐特】
小众软件
小众软件
The Cloudflare Blog
Y
Y Combinator Blog
I
InfoQ
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
GbyAI
GbyAI
IT之家
IT之家

Security @ Cisco Blogs

Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time Thrown into the SOC: A Black Hat First-Timer’s Story Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes Distributed Latency Monitoring at Black Hat Black Hat USA 2026: Safeguarding DNS with Secure Access Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha) Frontier AI just raised the stakes, and the old playbook won’t hold up Crypto Agility: Why PQC Is Not a One-Time Upgrade From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For Microsegmentation’s Moment Is Now: Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions Identity Everywhere: Bringing Infrastructure Identity to Agentic IT Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified Class C (Moderate) to Certified Class D (High) Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification Is your SD-WAN ready for AI-powered operations? The Zero Trust Imperative for the Frontier AI Era The Journey towards Logically Air-Gapped Deployment Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall We third-party tested our firewall built for AI-scale. The test tools hit their limit first. SharpHound Recon Attack - How AI enhanced the threat hunt Machine Speed, Human Judgement: How AI Changed the SOC in 2026 Elevating Expertise in the SOC Educate at Event Speed: Cisco Live Security Operations Center What Working the Cisco Live SOC Taught Me About AI, Detection, and Response Cable to Cloud - A Product Engineer's Journey Through the Cisco Live AMER 2026 SOC The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth AIM: Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026 Building the Agentic SOC at Cisco Live Americas 2026 Ten Years in the SOC at RSAC: What We Learned in 2026
Assuming Failure: The Mindset Shift That Actually Improve...
Jason Maynard · 2026-07-27 · via Security @ Cisco Blogs

We all know the uncomfortable truth — no matter how many tools you buy, how many people you hire, or how mature your processes are, you’ll never achieve 100% prevention 100% of the time. The defender doesn’t need to be perfect, and the adversary will make mistakes along the way. This provides an opportunity for defenders: if we assume our controls will fail at some point, we can build a much more resilient architecture.

This isn’t defeatist thinking. It’s realistic, battle-tested strategy that I see work with forward-leaning security teams.

The Hard Truth About Modern Attacks: Initial access is inevitable in most environments even when it appears that we have done all the right things.

Whether it’s through:

  • Public-facing application exploits (now accelerated risk with Frontier AI models)
  • Supply chain compromise
  • Valid accounts (credential stuffing, phishing, social engineering)
  • Initial Access Brokers (IABs) selling access on the dark web
  • and more – they will land

Once they’re in (initial access), the attack chain is well understood thanks to MITRE ATT&CK:

Execution → Persistence → Privilege Escalation → Defense Evasion (now Stealth & Defense Impairment) → Credential Access → Discovery → Lateral Movement → Collection → Command and Control → Exfiltration → Impact (ransomware, data destruction, etc.). Not necessarily in any order.

The adversary needs many things to go right. You only need to make it muddy, murky, and sticky as the defender. The goal is to slow them down long enough for your people, processes, and technology to catch up.

Layered Defense with “Assume Failure” Thinking

A great example is Initial Access with Valid Accounts: we started with username/password, then added MFA, then added 2- or 4-digit codes, then device proximity, then 3rd party identity verification workflows. That is just with valid accounts alone.

The point isn’t that any one layer is perfect and let’s be honest it will never be. The point is that each additional layer buys time and raises the cost for the attacker. When you assume the current layer will eventually be bypassed, you start designing the next layer proactively instead of reactively.

Defenders need to advance their controls by mapping them to the adversaries’ capabilities then assume that control will fail. We then move onto the next adversarial capability that puts my organization at the greatest risk – rinse and repeat.

This same thinking applies across the entire kill chain: Another great example is lateral movement – we all know the adversary needs the network for success but it’s an area we still ignore. If we know lateral movement will be attempted then we need to drive towards micro-segmentation in the campus, across the datacenter workloads, and its applications. This can no longer be ignored and becomes foundational when building resiliency.

Practical Takeaways from the Session

  1. Never design for the expectations of 100% prevention. Design for resilience and speed of detection/response.
  2. Map your controls to the attack chain. Identify gaps where the adversary has too much freedom. MITRE ATT&CK is your friend.
  3. Use breach attack simulation (like the Caldera series I’m doing) to validate assumptions safely.
  4. Build feedback loops. When a control fails (or almost fails), feed that intelligence back into architecture and policy decisions.
  5. Time is your ally. The longer you can make the attacker work, the higher the probability of your layered defenses and SOC team will disrupt them.

Call to Action:

If you haven’t watched the full video yet, go check it out: Assuming Failure Provides Better Defensive Outcomes (bonus elements around SOC of the Future and business context).

Then ask yourself honestly:

  • Where in my environment am I still hoping a single control will save us?
  • Have I mapped my current controls to MITRE ATT&CK tactics?
  • Am I running any kind of regular breach attack simulation or purple teaming?
  • If the adversary lands, can they move freely throughout the campus, datacenter, and applications?
  • Does your SOC understand business context and actually prioritize elevated risk?

I’d love to hear your thoughts in the comments on the video or here. What control do you see failing most often in your environment, and what did you layer on top of it?

— Jason Maynard
Field CTO, Cybersecurity – Canada, Cisco
YouTube: @jasonmaynard8773

Authors

Cisco Cybersecurity Viewpoints

Where security insights and innovation meet. Read the e-book, see the video, dive into the infographic and more...

Why Cisco Security?

Explore our Products & Services