attackers only need to be right once

expression

security

The defender's dilemma: attackers can fail repeatedly at no cost, while defense must hold everywhere, always.

True as economics, and worth the modern counterpoint: a defender only needs to detect once, and an intruder must stay invisible through every step of a long kill chain. Assume-breach thinking exists to turn that second asymmetry into practice.

The attacker needs to succeed once, the defender needs to succeed every time, and the asymmetry is real and frequently overstated. It is worth holding both halves.

The real part is that a defender must cover every path while an attacker chooses one, which means defensive work scales with the size of the environment and offensive work scales with the difficulty of the easiest way in. That is genuinely unequal, and it is why inventory, attack surface reduction and consistency matter so much.

The overstatement is that a single success ends the matter, and it does not. An intrusion is a campaign: initial access, then persistence, escalation, discovery, lateral movement and exfiltration, and the attacker must avoid detection at every one of those stages. The defender needs to be right once at any stage to interrupt it. That is the entire premise of assume breach and of investment in detection, and it inverts the aphorism usefully. The defeatist reading is bad strategy; the accurate reading is that prevention is asymmetric against you and detection is asymmetric in your favour.

Also known as: defender's dilemma

All glossary entries