Skip to content
Security Teams Must Shift from Finding Risk to Disrupting Attacks

Security Teams Must Shift from Finding Risk to Disrupting Attacks

Darkreading June 22, 2026

Security teams have unprecedented visibility but attackers still succeed. Defense requires understanding adversary execution, not just exposure.

For more than two decades, cybersecurity has largely been built around a simple premise: if organizations can see enough and expose enough, they can secure enough.

Asset inventories grew larger. Vulnerability scanners became more sophisticated. Exposure management platforms emerged to correlate ever-expanding volumes of security data. Security teams gained unprecedented visibility into their environments.

Yet despite all this visibility, attackers continue to succeed.

The problem isn't a lack of information. It is a lack of context related to adversary execution and procedural intelligence.

Most security programs can answer questions such as:

What assets do we have?

Which vulnerabilities exist?

Which systems are most critical?

Which findings have the highest severity scores?

Far fewer can answer a more important question:

Can an adversary successfully execute an attack against our environment?

That distinction matters because attackers do not operate through asset inventories, severity scores, or dashboards. They execute based on procedural commands.

They perform reconnaissance. They obtain credentials. They move laterally. They evade defenses. They establish persistence. They execute a sequence of commands and actions designed to achieve a specific objective.

Every successful attack is ultimately a chain of executable steps. Unfortunately, most defensive programs still evaluate risk as if those steps exist in isolation.

Asset management remains essential. Organizations need to know what they own.

Vulnerability management remains essential. Organizations need to understand weaknesses in their environment.

The problem arises when these activities become the primary lens through which risk is evaluated. A vulnerability does not create risk simply because it exists. An asset does not create risk simply because it is important.

Risk emerges when assets, vulnerabilities, and adversary procedures intersect and understanding which assets are relevant to procedures and attacker success. A critical vulnerability on an isolated system may represent little practical risk. A moderate vulnerability enabling or leveraging a procedure actively used by a threat actor targeting your industry may represent a far greater concern.

Yet many security programs still prioritize according to severity scores, asset criticality rankings, or generalized risk formulas that fail to account for how attacks are actually executed.

The result is predictable: teams spend enormous amounts of effort reducing theoretical risk while leaving meaningful attack paths intact.

Modern security programs have become highly effective at identifying exposure. What they often lack is an understanding of execution. Exposure tells us something could happen. Execution tells us how it happens.

This difference fundamentally changes defensive decision-making. Instead of asking:

"Which vulnerabilities are most severe?" Security teams should increasingly ask: "Which vulnerabilities enable the procedures adversaries use to execute attacks against us?"

Instead of asking: "Which assets are most critical?" They should ask: "Which assets are operationally relevant to attacker success?"

Instead of asking: "How many findings do we have?" They should ask: "Where can we disrupt attacker execution?"

These questions shift security from observation to action.

The cybersecurity industry is entering another period of optimism driven by AI and agentic security systems. Recent announcements promise autonomous security operations, AI-driven investigations, automated remediation, and agents capable of independently identifying and exploiting vulnerabilities. While these capabilities represent meaningful advances in how security teams operate, they do not fundamentally change the defensive equation.

AI can process more data than humans. It can identify patterns, correlate events, uncover vulnerabilities, and even execute actions. But none of these capabilities inherently explain how an adversary will execute an attack or which conditions increase the likelihood of attacker success.

The missing ingredient is procedural intelligence.

Risk does not emerge because a vulnerability exists. Risk emerges when a vulnerability enables an adversary procedure. An asset does not become important because it appears in an inventory. It becomes important when it is relevant to attacker objectives and the successful execution of a procedure. Likewise, defensive controls create value not because they are deployed, but because they can disrupt the procedures adversaries rely on to achieve their goals.

Without understanding these relationships, organizations risk applying AI to symptoms rather than causes. AI may accelerate analysis and execution, but procedural intelligence provides the context required to understand how attacks are executed, where attacker success becomes possible, and where defensive action will have the greatest impact.

This shift represents more than another security framework or management methodology. It represents a change in how defensive security is measured.

Historically, success has been defined by visibility: How many assets are tracked. How many vulnerabilities are identified. How many alerts are generated.

Increasingly, success should be measured by defensibility: Can the organization disrupt attacker execution? Can critical adversary procedures be detected? Can attacks be interrupted before objectives are achieved? Can defenders understand where meaningful control gaps exist?

These are fundamentally different questions. And they produce fundamentally different priorities.

Security teams are not suffering from a shortage of data. They are suffering from a shortage of decision-making context.

The evolution of cybersecurity will not come from collecting more information assets, vulnerabilities, or exposures. It will come from understanding how those elements converge and contribute to real-world attacker execution.

Visibility remains important. But visibility alone is not defense.

Organizations that can connect threats, vulnerabilities, assets, and defenses through the lens of actual adversary commands execution will be better positioned to prioritize resources, accelerate decision-making, reduce residual risk, and ultimately disrupt attacks before they succeed.

Because, in the end, attackers do not win because organizations lack visibility. They win because they know which procedures to leverage in your environment to successfully execute an attack.

Frank Duff is a leading expert in threat-informed defense and the evaluation of security capabilities. Before joining Tidal Cyber, he founded MITRE’s ATT&CK® Evaluations program, which transformed how the industry measures the effectiveness of EDR, deception, and managed security services. He also led public-private research initiatives to accelerate government adoption of cutting-edge security tools and oversaw adversary emulation, purple team, and cyber operations research for U.S. Government customers.

How Organizations Are Managing Incident Response

How Enterprises Are Developing Secure Applications

Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy

Essential News & Insights from Black Hat USA 2025

How Enterprises Are Harnessing Emerging Technologies in Cybersecurity

Say Yes to AI: Securing Innovation Without Compromise

Zero Trust Identity: Beyond Traditional Authentication

Advanced Persistent Threats: A Practical Guide to Detection and Response

The Frontier AI Era: Why Cybersecurity Must Move at Machine Speed

Build vs. Buy: The Hidden Cost of Building Your Own AI Security Stack

Extracted Entities