Why Is Testing Isolated Attack Techniques Not Enough?

Why Is Testing Isolated Attack Techniques Not Enough?

Malik Haidar has spent his career at the intersection of high-stakes threat intelligence and corporate resilience, navigating the complex digital battlefields of multinational corporations. As we move through 2026, the landscape has shifted from defending static perimeters to managing fluid, AI-driven exposures that defy traditional security checklists. Malik’s approach transcends the typical technical silo; he views cybersecurity through a business lens, recognizing that a single blocked payload means nothing if the overall attack path remains open. In this discussion, he explores the critical evolution from testing individual security techniques to mastering “Attack Chaining.” By analyzing why an overwhelming majority of organizations still face major breaches despite having “validated” defenses, Malik provides a roadmap for moving toward a unified, automated, and truly resilient security posture that mirrors the sophisticated behavior of modern adversaries.

While many teams validate individual EDR agents or phishing simulations, these isolated tests often fail to reflect the reality of a breach. Why is the technique-by-technique approach no longer enough?

The fundamental problem is that we are treating cybersecurity like a series of independent hurdles when, in reality, it is a high-speed relay race run by the adversary. When a security team runs a standalone test on an EDR agent, they are asking a very narrow question: “Can this tool see this specific piece of malware?” That is a useful data point, but it ignores the “broken link” theory that defines modern intrusions. Real attackers, especially those utilizing AI-powered tools, do not care if you have blocked 90% of their favorite techniques; they only need the 10% you missed to form a viable path. They chain these events together—starting with a simple phishing lure that harvests a credential, which then provides a foothold for privilege escalation, leading to lateral movement, and finally, data exfiltration. If your testing only looks at those steps in isolation, you are missing the gaps between the tools, teams, and alerts where the most dangerous activity actually lives. It is the sequence that kills a business, not the individual technique, and until our testing reflects that continuity, we are just checking boxes while the house burns down.

The data suggests a massive gap between feeling secure and actually being secure, with a staggering percentage of organizations suffering attacks despite their testing efforts. Can you elaborate on why so many organizations fall victim even after “passing” their security audits?

It is a sobering reality that 93% of security leaders reported a business-impacting cyberattack in the last 12 months, even though almost all of them had some form of validated defense in place. This discrepancy exists because most breach and attack simulation programs are essentially academic exercises based on a static library of techniques, like the MITRE ATT&CK framework. You run technique 1234, it gets blocked, and you feel a sense of accomplishment, but that feeling is often an illusion. The adversary is not a static script; they are adaptive, especially now that 88% of leaders see AI accelerating how fast attackers move once they gain that initial entry. We saw this play out vividly with the DGFiP breach in 2025, where no single step was particularly revolutionary or “exotic.” Instead, it was the seamless coordination of credential abuse and lateral movement that turned survivable weaknesses into a national headline. About 84% of professionals point to siloed tools as the reason these exposures go unnoticed, proving that when your security posture is a collection of disconnected islands, the attacker simply swims between them.

How does the concept of Attack Chaining fundamentally change the way a security team views their defensive perimeter compared to traditional Breach and Attack Simulation?

Attack Chaining shifts the perspective from a defensive “list of things we have” to an offensive “path an attacker takes.” Traditional Breach and Attack Simulation (BAS) is often a snapshot in time—a report that is stale the moment it hits your inbox because the environment has already changed. With Attack Chaining in OpenAEV, we are automating multi-stage paths end-to-end, which allows us to see how a harvested token or a misconfigured permission on one machine can be used to unlock the next. It’s an interactive, living process where the real output of one action—like an open port discovered during recon—directly informs and triggers the next step in the sequence. Instead of a spreadsheet of failed tests, you get a dynamic graph that branches in real-time, showing you exactly how a threat actor would pivot through your specific architecture. This provides the realism of a high-end red-team engagement but does so continuously and at a fraction of the cost, ensuring that you aren’t just protecting the perimeter, but the entire internal journey an attacker might attempt.

Walk us through the technical orchestration of an attack chain—how do conditional logic and live mapping turn a static list of vulnerabilities into a dynamic simulation?

The magic happens through five core capabilities that turn a simulation into a mirror of reality, starting with open, conditional chaining logic. We build reusable paths where “if/then” statements dictate the flow: if a credential works, the chain pivots to a new asset; if a control blocks the step, the system can stop or even reroute to find a different way in. As this happens, live attack path mapping renders every hop and pivot on a visual graph, so you aren’t just reading a post-mortem summary but watching the intrusion unfold as it happens. This traceability is vital because it surfaces “chokepoints”—those specific, high-leverage nodes where a single fix can collapse an entire downstream attack path. We also maintain strict scope and safety controls, defining exactly which assets are in-bounds so that the simulation can run autonomously without risking production stability. By treating social engineering as a first-class stage, a click on a fake landing page becomes a structured finding that feeds directly into the next lateral movement phase, creating a seamless, automated loop.

Social engineering is often treated as a disconnected exercise, like a periodic phishing test. How does integrating these human elements into an automated chain change the risk assessment for a corporation?

For too long, we have treated phishing as a “compliance” metric rather than a “technical” entry point, which is a dangerous mistake. In a true Attack Chain, a phishing email or an SMS lure is not the end of the test; it is merely a node in a much larger graph. When a user clicks a link or submits a credential, that finding is immediately ingested by the orchestrator to launch the next phase of the attack, such as credential harvesting or establishing a foothold. This approach forces the organization to look past the “click rate” and focus on the “impact rate.” It asks the hard questions: if an employee in accounting falls for a lure today, how many minutes does it take for that mistake to turn into a full-scale data exfiltration event? By making social engineering a functional part of the chain, we bridge the gap between human error and technical exploitation, mirroring exactly how 2026-era intrusions start and evolve.

With the introduction of XTM One, we are seeing a move toward fully autonomous simulations. What does it look like when an AI orchestrator takes over the red-teaming process?

Going fully autonomous represents a paradigm shift where we move from human-led, deterministic testing to AI-driven judgment and adaptation. In this mode, an operator defines only the objective—such as “access the payroll database”—and the scope, and then the AI agent within XTM One takes the wheel. This orchestrator agent plans the path, reacts to the defenses it encounters, reorders its steps on the fly, and even generates realistic phishing content tailored to the environment. It can call on specialized sub-agents for payload creation or complex exploitation, meaning the “red team” is now running 24/7 at machine speed. This isn’t just about automation; it’s about intelligence and the ability for the simulation to “think” like an adversary who is constantly probing for the path of least resistance. The result is a unified exposure score that reflects your actual risk in real-time, feeding straight into your strategy rather than sitting in a siloed report.

What is your forecast for the future of exposure management?

I believe we are rapidly approaching a “zero-latency” era of security validation where the gap between a new vulnerability appearing and a simulated attack chain testing it will shrink to almost nothing. In the coming years, the distinction between “vulnerability management” and “threat simulation” will disappear entirely, merging into a single, continuous discipline of exposure management. Organizations will no longer brag about how many patches they deployed; they will measure success by how many “killable” attack chains they have successfully collapsed. AI will not just be the tool of the attacker, but the core of the defender’s immune system, constantly running thousands of autonomous simulations to find and fix chokepoints before a human adversary can even finish their reconnaissance. We are moving toward a world where resilience is not a state you achieve once a year, but a dynamic, living attribute of the network itself.

subscription-bg
Subscribe to Our Weekly News Digest

Stay up-to-date with the latest security news delivered weekly to your inbox.

Invalid Email Address
subscription-bg
Subscribe to Our Weekly News Digest

Stay up-to-date with the latest security news delivered weekly to your inbox.

Invalid Email Address