When most of us think about protecting something valuable, we naturally focus on the thing itself. If you want to protect your house, you lock the doors. If you want to protect your phone, you use a passcode. If you’re protecting company data, you secure the systems where that data lives.
Attackers don’t always think that way. Sometimes the easiest way through the front door is to never use the front door at all.
That stood out to me while reading this week’s cybersecurity news. Valve notified customers about a breach that didn’t happen at Valve, but at its logistics provider. Levi Strauss reported an incident that started with social engineering against employees. Hedge funds were targeted through help desk processes. Attackers compromised TrueConf servers and turned trusted software updates into a delivery mechanism for malware.
The targets and techniques were different, but the idea behind them was remarkably similar:find an easier path.
We spend a lot of time in Security identifying the things that matter most. Critical applications, sensitive data, privileged accounts, cloud environments, endpoints, and network infrastructure all deserve that attention. But protecting an asset also means understanding all the paths that can eventually lead to it.
That can include a vendor with access to your data, an employee who can approve a request, a help desk capable of resetting credentials, an application that automatically trusts software updates, or a seemingly ordinary business process connected to something much more important.
This is where looking at your environment from an attacker’s perspective becomes useful.
Instead of only asking, “Is this system secure?” try asking, “How else could someone get here?”
Maybe they don’t need to defeat your MFA if they can convince someone to reset it. Maybe they don’t need to compromise your environment if a trusted vendor already has the information they want. Maybe they don’t need to attack an endpoint directly if they can compromise software the endpoint already trusts.
None of this means we should stop trusting people, vendors, or technology. Organizations couldn’t operate that way. Trust relationships are what allow businesses to function.
The lesson is simply that those relationships are part of the Security picture too.
One of the best exercises a Security team can perform is to choose something important and work backward. Who can access it? What systems connect to it? Which vendors support it? What processes can change that access? What happens when someone forgets a password? What software does it inherently trust?
You’ll probably discover that the path to the asset is more complicated than the asset itself, and attackers are very good at finding those paths. We should be just as good at understanding them.



