Skip to content

Nobody Thinks They Will Be Breached Next Week

And the time available to correct a bad assumption keeps shrinking

Jason Rivera, Field CISO at SimSpace and former US Army intelligence officer, on miscalculation, breakout time, and testing under realistic conditions

Cybersecurity is a responsive discipline, and nobody says that out loud often enough. You get the alert, and you respond to the alert. The function is called incident response. Threat hunting means hunting for something that already happened. Every defensive practice in a standard program assumes an interval between the adversary arriving and the organization acting, and the whole model quietly depends on that interval being long enough to work inside.

But the interval is closing. Breakout time measures how long it takes an adversary to move laterally after gaining access, and CrowdStrike's 2026 Global Threat Report puts the average at 29 minutes, down 65 percent in a single year, with the fastest observed breakout at 27 seconds. The year before, the fastest stood at 51 seconds. Push that trajectory out another five years and it approaches zero, at which point alert triage and incident response stop describing anything real. And underneath the speed problem is an older one that never went away, which is that organizations keep getting surprised by adversaries they never properly understood.

Welcome to Issue 04 of InfoSec Leadership by InfoSec Relations, featuring Jason Rivera. He started as a US Army intelligence officer, supporting cyber operations at US Cyber Command, then built threat intelligence and security operations programs at Deloitte for Fortune 500 companies and government agencies, ran intelligence solution engineering at CrowdStrike, and is now Field CISO at SimSpace. You can also watch our full podcast interview here. Let's get started.

Every Breach Traces Back to Something You Got Wrong

A Field CISO and former US Army intelligence officer on why miscalculation causes breaches, and what to change in how you test, buy, and review.

"Every single breach that happens is always a surprise," he observes. "No CISO actually believes they're going to get breached next week. A breach is always a strategic surprise. So I would argue that the main thing anybody does incorrectly when they get breached is they've miscalculated." And he splits that miscalculation into two failures that compound each other. "They miscalculate on two fronts. The first is the adversary themselves. They don't understand the adversary, they don't understand what the adversary is capable of. But that misunderstanding is then further amplified when not only do they not understand the adversary, they don't know what they should do about it."

Which is a more uncomfortable diagnosis than a missing control, because it locates the failure in judgment rather than in budget. A miscalculation is something a person made, and the honest version of a post-incident review asks what the organization believed about its adversary that turned out to be wrong. Most reviews never get there, because it is easier to name the gap in coverage than the gap in understanding. So build that question into your incident retrospectives directly, and record what your team assumed about the attacker before the incident alongside what actually happened.

What You Are Defending Decides How You Defend

Before any of that becomes tractable, an organization has to be honest about what it is actually protecting, and Rivera's offensive background made that unusually clear to him.

"This idea of critical assets, or what some people call crown jewels, really is the foundation of your defense," he explains. "If you're a hospital, then the number one thing that must happen is MRI machines, dialysis machines, X-rays. The things keeping people alive, those systems must not be compromised." A utility carries a different answer entirely, built around industrial control systems and the equipment delivering power and water. A government entity answers differently again. "So from an offensive mindset, what I realized is that no one target is the same, and therefore no one attack strategy must be the same."

The consequence of that runs in a direction most security programs resist. If attacks worth worrying about are bespoke to the target, then a defense assembled from generic best practice is answering a question nobody asked. Rivera puts the operator's version of it plainly, that his ability to achieve an objective was largely a function of how the target defended itself. So write down your five most critical assets and check whether your controls, your monitoring, and your testing actually concentrate there. If your program would look identical at a hospital, a bank, and a utility, it is not yet a defense of anything in particular.

Checklists Feel Like Progress

There is a specific failure mode that follows from generic programs, and Rivera names it without much diplomacy.

"Security professionals often fall into the trap of tunnel vision," he cautions. "They have a little checklist. They think if they do the checklist and they do all the right things, oh, I bought my EDR, I bought my firewall, I'm doing alerts and triage, I'm doing threat hunting, I'm doing incident response. But then the question is not just are you doing it, but are you doing it well? Are you doing it correctly? Are you doing it in a manner that's actually going to defend yourself, or are you doing it in a manner that's going to maybe achieve compliance and maybe make your boss happy, but you're not really affecting what you're trying to accomplish?"

And the trap works because the motions are genuinely satisfying. A completed checklist produces evidence, evidence produces a clean audit, and a clean audit produces the feeling of having done the job. None of which touches the question of whether any of it would hold. So take one control you consider mature and test whether it does what you believe it does, under conditions you did not design to be favorable. One honest answer about one control is worth more than a fully populated compliance matrix.

Twenty-Seven Seconds Changes What Response Means

All of which matters more now, because the window for getting it wrong keeps shrinking.

"I remember when I first joined CrowdStrike in 2018, the fastest breakout time was like eighteen minutes and fifty-one seconds," Rivera recalls. "Last year, according to their global threat report, the fastest breakout time was twenty-seven seconds. So think about that. In a seven-year time span, it went from eighteen minutes and fifty-one seconds to twenty-seven seconds. And the very obvious question I'll throw to the audience, where does that breakout time go in the next five years? Right above zero. So let's think about that for a second. What does the world look like when the breakout time is right above zero? There is no more alert triage. There is no more incident response. Or the way that we think of these things ceases to function in their current state."

His recollection of the 2018 figure tracks CrowdStrike's reporting from that period, when the fastest breakout attributed to Russia-nexus adversaries sat just under nineteen minutes. Either way, he is describing a structural problem rather than a scary statistic, and the distinction matters for how a security leader should act on it. Every defensive function carries a built-in assumption about elapsed time, and those assumptions were never written down because nobody had to question them. So map your own chain end to end and put a real number against each hop, from event generation through enrichment and triage to containment. Then set that number beside twenty-seven seconds. Any control that only works because a person reviews it inside that window needs automation behind it or a redesign, and knowing which of your controls fall into that category is worth more than another sensor.

There is a second asymmetry underneath the timing one that rarely gets stated. Security teams have to be right every time, adversaries only once, and the adversary also moves first. Rivera adds a third disadvantage specific to this domain, that physical movement can be observed by satellite and signals intelligence while movement inside a network largely cannot, which is why strategic surprise keeps happening to organizations that looked well prepared.

Adversaries Behave Like Water

Given that asymmetry, the question of what fails first during an incident has a less satisfying answer than most people expect.

"I said in a podcast that the adversary is like water," Rivera shares. "You ever watch water go down a stream, throw a rock in the stream. What does the water do? Does the water get angry? Does it get upset? No. It just goes a different direction. You poke a hole in the dam, now the water's coming through that place." He extends the point to how malware itself has changed, noting that code which once only altered its appearance now adapts dynamically and makes judgment calls about its own capability while running.

But when pressed on whether people, process, or tooling breaks first, he refuses the false comfort of blaming the stack. His answer is that technologies and processes do not exist independently. They exist because a leader made a decision based on their understanding of the situation, which means the failure always resolves back to a person. And that holds even in a future where agents run the front line, because people still decide which agents, how they operate, and what their decision thresholds are. So treat your control set as a record of past judgments rather than a fixed inventory, and review the reasoning behind the significant ones as deliberately as you review the tooling.

Clean Test Environments Produce Clean Lies

Which brings the argument to the part of Rivera's current work that has the most immediate application, and to a limitation of standard testing that most security leaders have never been told plainly.

"There is no pen tester, and there is no breach and attack simulation capability, that is going to deploy ransomware on your environment," he underscores. "There is no pen tester or BAS tool that's going to blow something up in real life. There's no pen tester or BAS tool that's going to take your data and put it on the dark web. There's only a certain extent that these capabilities will go within the cyber domain, because what they don't want to do is cause real damage." And that restraint, entirely sensible in itself, means the results come back from a version of reality that has been made safe. "For me to know the truth, if I'm going to make a good decision, I must know the truth. Not the truth I want to hear, but the full extent of the truth."

His prescription is to test somewhere messier. "Real life is messy, real life is dangerous, and we get that in the physical sense, but we don't get it in the cyber sense," he points out, and he reaches for the printer behind him as the example, wondering aloud whether in a proper simulation that printer should break, or be the point of entry, or introduce some network flaw nobody planned for. Which is the practical instruction hiding in an offhand remark. When you next scope an exercise, insert conditions you did not choose. Degrade something. Break a dependency. Let the environment misbehave while the exercise runs, because an assessment conducted under favorable conditions tells you how your program performs on a good day, and adversaries do not schedule around good days.

The same discipline applies to buying decisions before it applies to testing ones. Rivera's first question for a leader who has never stress-tested a stack is not about tooling at all. Do you understand what problem you are solving, do you have a hypothesis about what the tool should accomplish, and can you construct an environment complete enough to test that hypothesis against the objective. Test in isolation and you get an isolated answer that does not describe your organization.

Collect on Yourself Before You Buy Threat Feeds

The same inversion runs through his advice on intelligence, which he approaches as a discipline with a defined life cycle rather than a subscription.

"Good intelligence provides good information around actionable things that are relevant to your ability to make decisions," he notes. "So for an intelligence leader, my very first question is, do you actually understand yourself? Before you go and get threat feeds and do whatever it is you think you're going to do, are you aware of your own stuff? Do you have access to your alerts? Do you have the right tools in place? Because if you're not collecting on yourself, then you might have a great understanding of the adversary, but you can't apply that to who you are."

He describes the cycle as planning and direction, then collection and processing, then analysis and production, then dissemination and feedback, and he is direct about which step gets skipped. Teams go straight to collection, then to analysis, then to publishing reports, without ever establishing their priority intelligence requirements or answering why they are doing any of it. So before renewing a feed or hiring an analyst, write down the three decisions you want intelligence to change. If you cannot name them, more intelligence will produce more noise, and noise does not just fail to help. Rivera argues it actively lowers your understanding of the real situation.

There is a structural problem waiting underneath even good intelligence, and he does not pretend otherwise. Intelligence describes the past by nature, since every indicator, every threat report, and every adversary profile captures who someone was at a time and in a place. The evolution he expects is a move from predictive to preemptive, working out what an adversary will do before they do it, and he sees AI as the thing that makes that shift possible.

Trust Has to Come Before Efficacy

Which leads naturally to what a security leader should ask when someone arrives selling exactly that capability.

"The skepticism that I often see is around the area of trust," Rivera stresses. "The AI capability claims it can do a thing. It looks good in the demo. But how do I validate trust? And in what location do I validate this trust? Not only trust, but also efficacy. I need to know that if I allow this thing to have control over aspects of my environment, it's not going to behave destructively." And he puts the two in a deliberate order. "It can be effective. Say it's great at finding alerts and triaging and doing whatever, but in the process it's destroying business-critical assets, then it doesn't matter how good it is, because I don't trust it."

So make both provable rather than promised, and make the demonstration happen somewhere realistic. Ask a vendor to show the capability behaving safely under conditions that include failure, not only conditions that include success. Rivera is unequivocal that neither trust nor efficacy can be established anywhere else, and equally unequivocal about the timeline pressure behind the question, expecting AI on the front lines of every large organization within five years.

Basics First, Then Correctly, Then Optimally

For organizations that know they are behind, his advice runs in a strict order, and the first instruction is a refusal.

"Always the basics first," he highlights. "If you don't have EDR, if you don't have visibility, if you can't see what's going on, then nothing else really matters. Please don't get AI. Please don't do other things until you have the basics." Visibility comes first, then the capacity to respond, contain, isolate, and prevent. And he is blunt about why nothing else belongs on the roadmap until those exist, because an organization in crisis has no special projects, only a crisis.

But the sequence continues past the basics, and this is the part most programs never reach. Once you are doing the right things, ask whether you are doing them the right way, since owning an EDR and using it well are separate achievements. Then ask whether you are doing them the best way available, whether the same outcome could be reached faster or at lower cost. Rivera's view is that continuous iteration through that progression is what distinguishes strong leaders, while weaker ones run the loop once and then trust their own judgment too completely to question it again. Which returns the argument to where it started, since failing to challenge your own understanding is how a miscalculation survives long enough to become a breach.

Power Is Becoming More Distributed

He closes on a belief he has abandoned, and it reframes how a security leader should think about who is capable of reaching them.

"I once believed that nation states had exceptional, unmatched capabilities," Rivera reflects. "I once believed that if you had all the money and all the technology and all the power in the world, that you could have your way on the battlefield." He no longer holds that view, and points to how quickly the line between a powerful adversary and a less powerful one has blurred. "Things like AI, things like drones, things like decentralized cryptocurrency wallets, all of these things are creating capabilities that allow those who have less capability and less funding to sort of even the playing field. Nation states are not as powerful as they used to be, and power is beginning to become more and more distributed because of technological advancement."

Which is the assumption to operate on. The set of adversaries capable of reaching your organization is growing rather than holding steady, and a threat model built around who could afford this attack last year describes a world that no longer exists.


CISO Action Plan

Speed and tooling get the attention, but Rivera's argument is that breaches trace back to judgment. Here is what he recommends security leaders settle now.

For the engineering view of what happens when the response window closes, our recent feature on detection engineering against AI agents goes inside the assumptions that are quietly becoming legacy.


Thank you for reading InfoSec Leadership.

If you found this analysis useful, please subscribe to the InfoSec Leadership newsletter so you never miss an update.

Lead with clarity, defend with purpose.

S Pattnaik Technical Contributor and Volunteer Host


This issue draws on InfoSec Relations' interview with Jason Rivera, Miscalculation and Machine Speed, with a Former Army Intelligence Officer and Field CISO, hosted by S Pattnaik for InfoSec Leadership.