A premium conceptual technology graphic on a reflective white background demonstrating reconnaissance containment. A multi-layered sapphire glass infrastructure model on the right is silently mapped by an adversary's unverified amber and purple wireframe network. A large titanium magnifying lens hovers above to illustrate stealthy tracking, while a vertical brushed-titanium containment block outlined in a sharp neon light-blue line cleanly intercepts and isolates the amber reconnaissance vector at a central junction, ensuring the infrastructure pathways extending to the far left remain perfectly clear, secure, and filled with a calm blue light stream.A premium conceptual technology graphic on a reflective white background demonstrating reconnaissance containment. A multi-layered sapphire glass infrastructure model on the right is silently mapped by an adversary's unverified amber and purple wireframe network. A large titanium magnifying lens hovers above to illustrate stealthy tracking, while a vertical brushed-titanium containment block outlined in a sharp neon light-blue line cleanly intercepts and isolates the amber reconnaissance vector at a central junction, ensuring the infrastructure pathways extending to the far left remain perfectly clear, secure, and filled with a calm blue light stream.
S10 Group Article series · The operational attack realities

The Attacker Had a Map
Before Leadership Had a Picture

Why reconnaissance creates an information advantage
before the first executive decision
Article #13
Published: 02 October 2026
By Stan van Gemert | S10 Group
By Stan van Gemert
When attacks move series

Executive summary

The previous publication, "Trust Often Breaks Before Systems Fail", examined how services can remain available while confidence in identities, data activity, instructions and administrative state is already deteriorating. Your teams may still be operating even though the evidence behind safe decisions has become less reliable.

This present article looks at how that imbalance develops. Before the first executive meeting begins, an attacker may already have mapped privileged accounts, critical servers, backup routes and operational dependencies. Your organisation is then trying to establish the incident boundary while the attacker is acting on a picture assembled earlier.

The practical response is not to demand impossible certainty from the first hour. It is to define in advance which movement may be interrupted, who has authority to act and which essential operations must remain protected while the picture is still forming.

The next publication, "When the Systems Are Back, the Real Impact Begins", follows the incident beyond restoration. It examines why service recovery can close the outage while data exposure, evidence gaps, notification duties and other consequences continue.

The first executive meeting began without answers

The room had system names, uncertain timestamps, partial log extracts and one difficult question: what do we know for certain? Security could explain why it had escalated. Infrastructure knew which systems were producing unusual signals, while operations knew which processes could not be interrupted without consequence. Legal needed caution, communications needed language, and the CEO needed a coherent picture that nobody could yet provide.

Across the environment, the attacker may already have assembled one. It would not be complete, but it might show where privileged accounts lived, which servers mattered, whether recovery routes were reachable and which disruption would create the most pressure with the least noise.

That is the operational meaning of reconnaissance: the attacker reduces uncertainty before incident command has agreed what kind of event it is facing.

VISIBILITY IS NOT THE BEGINNING
The visible event may be the point at which your executive team joins an incident
the attacker has already had time to prepare.

The incident did not begin when the room filled

A cyber incident is often described as a sudden strike in which an alert appears, a service fails or a ransom note announces that the crisis has begun. That neat dividing line is convenient, but modern attacks rarely respect it.

The visible event may be the final act of a longer preparation cycle. Before encryption, data theft or outage, an attacker may have listed directories, checked privileges, tested remote access, reviewed backup paths, studied cloud connections and identified the dependencies that matter most to the business.

Your organisation enters the incident when it sees something. The attacker may have started the useful work much earlier. The response is therefore not limited to what has just happened; it must account for what may already have been learned, prepared and staged.

The attacker as an unauthorised internal auditor

During the quiet phase, an attacker can behave less like a burglar and more like an unauthorised internal auditor. They map ownership, permissions and dependency. They find forgotten systems, old VPN accounts, over-permissioned service users, reachable file shares, remote administration routes, backup consoles, identity infrastructure and business-critical applications whose ownership is assumed rather than clear.

The purpose is leverage. Which process will create immediate executive pressure? Which data could create legal exposure? Which trusted route enables movement without obvious malware? Which recovery path can be damaged before the visible attack, and which dependency could turn an internal incident into a public crisis?

Reconnaissance reveals how your organisation actually works: the exceptions, old connections, broad permissions and accounts that reach further than the clean architecture diagram suggests. The attacker does not need to understand the environment better than every specialist. They need a more useful picture than your decision-makers have at the moment an intervention cannot wait.

Detection is not arrival

Mandiant's M-Trends 2025 report, based on its investigations of targeted attack activity during 2024, reported a global median dwell time of 11 days. The figure is useful context, not a universal countdown and not a measure of reconnaissance alone. It shows that discovery can follow compromise by a material period; individual incidents can be much faster or much slower.

The US Department of Energy recorded that Colonial Pipeline proactively shut down its pipeline system on 7 May 2021 in response to ransomware and announced a full restart on 13 May. The defensible executive lesson is narrow: cyber uncertainty can drive operational decisions before every fact is settled.

Together, the sources support this article's narrower asymmetry: the visible incident may begin after the attacker has already had time to learn and prepare.

Sources:
Mandiant - M-Trends 2025 report:
https://services.google.com/fh/files/misc/m-trends-2025-en.pdf
‍
U.S. Department of Energy - Colonial Pipeline Cyber Incident:
https://www.energy.gov/ceser/colonial-pipeline-cyber-incident

Source boundary:
The dwell-time figure is not a reconstruction of every attack or of reconnaissance alone. The public Colonial Pipeline record does not establish that operational technology was compromised, nor does it prove that one particular control would have prevented the event.
View more details chevron A white downward-facing V-shaped chevron on a transparent background.
View more details
Close more details
RECONNAISSANCE IS LEVERAGE
The attacker is looking for the route, dependency, account or data set that will create the greatest pressure while your own picture remains incomplete.

Your executive team starts behind

The first executive picture has to be assembled under pressure. One team is deciding which alerts matter, another is tracing connections to finance, clinical operations, manufacturing or customer services, and someone else is asking whether backups are safe, whether a segment can be isolated and who owns an application nobody has discussed in years.

That gap does not prove incompetence. It reflects an environment that crosses cloud services, vendors, identities, shared storage, older applications and new platforms. Those connections enable the business to operate, but they are difficult to understand quickly once the incident has made their condition uncertain.

The attacker had time to test a practical map. Your senior decision-makers must assemble their own while consequences are developing and stakeholders see different parts of the same event. Security sees attack activity, operations sees disruption, finance sees cost, legal sees exposure and communications sees reputational risk. The CEO has to weigh all of them without knowing which view is complete enough to support action.

The attacker's advantage is therefore informational as well as technical: they may know what they intend to do before your organisation knows which movement it needs to stop.

Normal activity can also be preparation

Mature environments may have endpoint visibility, identity logs, SIEM alerts, vulnerability scanners, incident playbooks, backup dashboards and escalation procedures. Each contributes to the response, but their presence does not guarantee a usable incident picture when the first difficult decision arrives.

Reconnaissance can resemble ordinary administration. A directory query, file listing, remote session, cloud-console check, backup inventory or service account connection may each have a reasonable explanation. The sequence, timing and destination may nevertheless describe preparation for a wider attack.

The pattern often becomes clear only after time has passed. Your teams wait for a picture that justifies action, while the attacker uses the incomplete picture to keep moving. More visibility can sharpen the evidence; it does not by itself create the authority or mechanism to interrupt what the evidence reveals.

CONTROL DISTINCTION
Visibility improves the incident picture.
Control depends on whether your teams can change the attack path before that picture is complete.

What the map removes

Reconnaissance gives the attacker information and removes options from your response. Time has already passed, the first alert may not describe the full event and nobody can yet prove the complete blast radius. A suspicious system becomes a suspicious environment, and an account-level concern becomes a question about routes, permissions and dependencies.

The technical investigation has now become an executive decision problem: can your organisation act safely while only part of the environment is understood? Many response processes slow at this point because they were designed around confirmation. The attacker is operating on preparation.

The decision comes before certainty

Interrupting an account, route, workload or dependency too early can damage the business. It may stop a clinical process, logistics workflow, payment chain, production line or customer-facing service. Waiting too long can allow the attacker's map to define the eventual blast radius.

The decision sits between suspicion and proof. Your teams need pre-agreed boundaries for what may be isolated, who may authorise the move, which operations receive protection first and how much uncertainty is sufficient for a reversible containment action.

Without those boundaries, the attacker's picture keeps improving while your decision-makers try to make their own picture defensible.

What must your teams be authorised to contain before the incident picture is complete?

Containment while the picture is still forming

Containment cannot give incident command perfect knowledge. It can limit what the attacker's knowledge is allowed to become while your teams are still building their own picture.

If response depends on full understanding, your organisation waits. If your teams can reduce movement, restrict suspicious communication, protect critical paths and bound the incident under uncertainty, decision-makers gain room to think without giving the attacker equal room to expand.

Where our platform fits

Our platform adds an operational containment layer after prevention has been bypassed. We do not replace prevention, detection, investigation or recovery. We help authorised teams act once the evidence is strong enough to justify concern but not yet complete enough to support certainty.

Ransomware Containment is our core platform. Server Intrusion Protection and Virtual Server Protection are additional features running on it, extending available controls to compromised administrator use on servers and threats at the virtual infrastructure layer. Broader platform capabilities can help interrupt malicious behaviour, lateral movement, data-theft paths and ransomware encryption while investigation continues.

The practical objective is not to admire the attacker's map more accurately. It is to reduce what that map can still be used for while preserving the smallest viable operating environment.

CONTAINMENT IMPLICATION
Your teams do not need a perfect map before they can reduce the routes available to the attacker.

The map should not remain one-sided

The next incident may begin with a quiet login, routine query, remote session, backup check or service account reaching a system it does not normally need at that hour. Nothing may look broken while the attacker uses that calm to learn and your teams use it to wait.

By the time the room fills, the routes that matter may already be known on the other side. The answer is not to demand impossible certainty from the first meeting. It is to ensure that the first meeting is not the point at which authority, boundaries and containment begin.

The attacker may have a map before your executive team has a picture. Your advantage begins when the boundaries already exist.

The next horizon

The next publication moves from the information advantage before and during the attack to the consequences that remain after systems return. When the Systems Are Back, the Real Impact Begins examines why service restoration can close the outage while data exposure, evidence, notification duties and other consequences continue.

It asks which work must remain governed after the dashboard turns green.

Hear first when a new S10 Group release is published

Would you like to receive a short note when S10 Group publishes a new article or newsletter?

Leave your name and email address below. We will send a short update when a new release is available, with a brief summary and a direct link to the publication.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

FOCUSED RANSOMWARE RESILIENCE ASSESSMENT

Compare controlled file-encryption scenarios with your existing security controls active, first without Ransomware Containment and then with it. The assessment itself is limited to encryption, but alongside the assessment results, we can explain how our platform and its additional Server Intrusion Protection and Virtual Server Protection features, helps detect and interrupt lateral movement, reduce the risk of data theft, protect remote server access and defend virtual environments such as VMware and Hyper-V. That makes the session useful not only as a ransomware-containment test, but also as a practical discussion about what your organisation can still control when identity, privilege and infrastructure trust come under pressure.‍
A bright conceptual image of upright frosted-glass blocks in sequence. The first block has tilted forward but is stopped by a fixed brushed-titanium pillar rising from the surface, while the remaining blocks stay stable and undisturbed

Coming soon

Monday 5 October, Resilience-series #5: "When the Systems Are Back, the Real Impact Begins"

Wednesday 7 October, Leadership-series #5: "Backups Restore Systems. Not Trust."

Further readings