- A technique-first approach can make it more difficult for security teams to stay ahead of evolving threats and tactics. A greater emphasis on understanding and containing attacker behaviour can help organisations be more proactive.
- Attackers want to gain access and reach critical assets, ultimately stealing data, deploying ransomware, or disrupting operations.
- Get your organisation prepared by investing in controls designed to crack their playbook.
New cyber threats are emerging constantly. In fact, when writing this article, I did a quick search of the tactics that made the news in June 2026.
There was a ClickFix fake CAPTCHA attack, a Browser-in-the-Browser phishing campaign, and a new API-driven ClickFix payload. A whole new set of techniques have emerged, compared to June 2025, where you had email bombing combined with vishing, alongside a cross-platform ClickFix attack.
Each new cyber threat generates a fresh wave of concern and prompts the inevitable question from the board: “Could this happen to us?”
Yet, this technique-first approach can make it more difficult for security teams to stay ahead of evolving threats. A greater emphasis on understanding and containing attacker behaviour can help organisations be more proactive.
Why a behaviour-based security strategy is the way forward
Attack methods change quickly and often. So, when organisations centre their security strategy around specific techniques used by attackers, they risk focusing on a threat that might be outdated within weeks or months. They end up playing an endless game of whack-a-mole.
Whilst the techniques and procedures might change, the tactics and objectives generally don’t. Different threats, such as the ones I mentioned above, typically follow the same pattern.
Attackers want to gain access and reach critical assets, ultimately stealing data, deploying ransomware, or disrupting operations. Focusing on interrupting those behaviours is far more likely to build lasting resilience in your organisation than those chasing every new attack trend.
So, why are security teams not doing this already?
The ‘band-aid’ effect in security
The cybersecurity industry has become very good at spotting individual threats. Frameworks such as MITRE ATT&CK provide defenders with a common language for describing adversary behaviour, while threat intelligence helps organisations understand the latest campaigns.
That leads to organisations becoming overly focused on defending against individual techniques, rather than the behaviours that drive them. It’s like a plumber spot-fixing dozens of individual leaks instead of replacing the pipe.
This reactive mindset also feeds into the tool sprawl issues organisations face. When a new technique arises, security teams assess whether existing controls can detect it. If they can’t, another tool is evaluated, another feature is enabled, or another product is added to the stack.
The average organisation now runs 83 different security solutions from 29 vendors. Some overlap considerably, and others exist because they addressed a specific threat that emerged several years ago but have never been retired.
When I ask the organisations I meet to describe the overall security outcome they are collectively trying to achieve, I’m normally met with silence.
This becomes a fragmented security strategy built around tools rather than outcomes. Teams are left with multiple partial views that rarely fit together, creating gaps that attackers can exploit. In fact, nearly 40% of incident response cases involve security tool or management gaps that allow attackers to establish a foothold, move laterally and escalate privileges without being detected.
The advantage of focusing on attacker behaviour
Lateral movement is a good example of the fact that, irrespective of how the attacker enters, they almost always need to move through the environment to reach high-value assets. Our Global Cloud Detection and Response Report found that nearly 90% of respondents experienced a cybersecurity incident involving lateral movement.
Stopping lateral movement makes the vast majority of attack paths significantly harder. The same principle applies to other core attacker objectives. These security challenges have always existed and don’t change with the latest phishing lure or a new malware family.
Building security around outcomes, not threats
By focusing on attacker behaviour, security controls continue to deliver value even as attack techniques evolve. However, doing so calls for a shift in mindset.
Security leaders should start by defining the outcomes they want to achieve and then assess whether their operating model supports those goals. Instead of asking how to stop every possible attack, organisations should ask how to make it significantly harder for attackers to do damage once they gain access.
The goal should be to contain and stop the foundational attacker behaviours of lateral movement, persistence and privilege escalation. This means prioritising controls that limit what attackers can do once inside the environment, such as segmentation, rather than relying solely on preventing initial compromise.
Reducing operational complexity should also be prioritised, and that’s done by removing redundant tools and consolidating controls.
The AI era changes the speed, not the objective
AI is already enabling faster, more autonomous attacks. For defenders, that can feel like an impossible race to win, but the attacker’s objectives and behaviour will be the same.
That’s why organisations shouldn’t just respond to AI by accelerating their own cycle of reactive security spending. Instead, they should double down on the controls that make those core attacker ploys significantly harder to achieve.
In the next inevitable breach, the headlines and industry discussion will undoubtably focus on the novel tactics involved. But fundamentally, the attackers will still follow the same basic playbook. Get your organisation prepared by investing in controls designed to crack their playbook, stopping a compromise from becoming a major breach.
Raghu Nandakumara is VP of industry strategy at Illumio.
Read more
Protecting against cyber attacks backed by generative AI – Threat actors are turning to generative AI capabilities to evolve social engineering and other cyber attacks — here’s how businesses can stay protected














