assume breach

expression

security

The security posture that plans as if attackers are already inside, because someday they will be.

It reframes the job from building a perfect wall to limiting what a successful intruder can reach: segmentation, least privilege, detection, rehearsed response. The grim industry version: there are two kinds of companies - those that have been breached, and those that do not know it yet.

Assume breach is the posture that treats compromise as a current condition rather than a future possibility, and its value is in what it changes about where effort goes. If prevention is assumed to work, investment concentrates at the perimeter; if compromise is assumed, detection, containment and recovery become equally important.

The evidence supports the posture. Dwell time, the interval between intrusion and discovery, has historically been measured in months, and organizations frequently learn of a breach from an outside party rather than from their own monitoring. Any model that assumes you would know is contradicted by the data.

What it changes in practice is concrete. Segmentation so a foothold does not become the whole network, least privilege so a compromised account is not a compromised environment, monitoring for lateral movement rather than only at the boundary, and incident response that is rehearsed rather than documented. It also changes design questions: not whether this can be breached, but what an attacker can reach from here, how quickly it would be visible, and how the blast radius is bounded. That is a more useful question because it has an answer.

Also known as: assume compromise

All glossary entries