The first alert was not the boundary represented by a cinematic, high-end corporate 3D graphic set against a dark matte charcoal background, optimized for a thought-leadership hero header. On the right side of the frame, a complex network matrix of crisp white and deep navy lines stretches into the distance. A single, sharp amber dot glowing intensely represents the initial alert point. Radiating out from this dot, thin, faint pathways of light stealthily snake deeper into the surrounding network via normal pathways. Slicing vertically through the matrix, slightly further down the track, is a razor-sharp, glowing ice-blue glass wall or boundary vector, cleanly halting the forward motion. The entire left half of the image features expansive, clean negative space with smooth dark gradients for textual overlay. Premium, intellectual B2B technology aesthetic.The first alert was not the boundary represented by a cinematic, high-end corporate 3D graphic set against a dark matte charcoal background, optimized for a thought-leadership hero header. On the right side of the frame, a complex network matrix of crisp white and deep navy lines stretches into the distance. A single, sharp amber dot glowing intensely represents the initial alert point. Radiating out from this dot, thin, faint pathways of light stealthily snake deeper into the surrounding network via normal pathways. Slicing vertically through the matrix, slightly further down the track, is a razor-sharp, glowing ice-blue glass wall or boundary vector, cleanly halting the forward motion. The entire left half of the image features expansive, clean negative space with smooth dark gradients for textual overlay. Premium, intellectual B2B technology aesthetic.
S10 Group Article series · The operational attack realities

The first alert was not the boundary

The first compromise gives leadership a location.
It does not tell them how far the attack has already moved.
Article #3
Published: 11 September 2026
By Stan van Gemert | S10 Group
By Stan van Gemert
The CISO series
When attacks move series

Executive summary

The previous publication, The CISO Role Changed Faster Than Most Organisations Adapted, argued that cyber accountability is meaningful only when it is matched by the authority to act across distributed systems and dependencies. This article shows why that authority becomes decisive during the opening phase of an attack. The first alert identifies where malicious activity became visible; it does not reveal where the attacker entered, which trust paths have already been used or what may be reached next.

Lateral movement turns a local compromise into an operational problem by exploiting ordinary-looking credentials, sessions and connections. Detection gives the organisation a starting point, but containment creates the boundary. The next publication, When Ransomware Becomes a Standing Operational Pressure, widens the lens from the first moments of movement to the sustained executive challenge of keeping the organisation controllable while ransomware pressure persists.

The illusion of a single foothold

The alert had a comforting shape. One endpoint. One account. One server behaving strangely enough to be noticed. On the incident bridge, that made the problem feel smaller than it was. The team had a timestamp, a machine ID, a user name, a location, and a place to begin.

That is what alerts are designed to give: a visible point of concern. But the first visible point is not the same as the boundary.

This opening article in the When Attacks Move series starts with one of the most dangerous assumptions in incident response: that the place where trouble becomes visible is also the place where trouble is contained. It may be. But leadership cannot safely assume that.

The attacker may already have tested credentials, queried directories, opened remote sessions, touched file shares, found backup paths, staged tools, or discovered which systems matter most to the business. What looks like the first sign of the incident may only be the first sign your organisation has been able to see.

You see a dot on the map. The attacker may already have a route.

ALERT IS NOT A BORDER
The first alert tells you where the attack became visible.
It does not prove where the attack began, where it has travelled, or where it can still go.

The isolation assumption

The comforting assumption is simple: one compromised system means one isolated problem.

It is a natural assumption. Executives hear “one laptop” and imagine a local cleanup. Infrastructure teams hear “one server” and begin thinking about rebuild. Security teams hear “one account” and start tracing access. Everyone is working. Everyone is moving. But if the attacker is moving too, the organisation may be solving the first symptom while the actual incident expands.

This is where lateral movement becomes crucial to understand. In business language, it means the intruder is no longer only inside one place. They are testing what else can be reached through credentials, trust relationships, remote sessions, file shares, administration tools and ordinary-looking connections between systems.

To the business, that movement may look like work: a login, a file copy, a directory query, a scheduled task, a remote session or a connection from one trusted system to another.

That is why the early phase is so difficult for leadership. The organisation is not deciding whether something obviously malicious should be stopped. It is deciding how much normal-looking business activity must be interrupted before certainty exists.

That is not a technical footnote. It is the leadership dilemma at the centre of modern incident response.

LATERAL MOVEMENT
An attacker does not need to own everything.
An attacker only needs enough reach to make your executive team unsure what can still be trusted, isolated, or allowed to keep communicating.

Movement turns a breach into an operational problem

A first compromise can still feel local. Movement changes what is at stake.

Finance may become reachable. HR records may become reachable. Patient systems, customer portals, file shares, identity stores, backup paths and supplier routes may all move from “elsewhere in the environment” to “possible next step”. A security incident stops being about the device that raised the alert and becomes about the pathways the attacker is allowed to use before anyone can draw a defensible line around the blast radius.

"Lateral movement" sounds like a clinical security term. Inside the business, however, it represents the immediate collapse of operational boundaries. Infrastructure components that looked entirely separate on a presentation slide are suddenly revealed to be interconnected by hidden trust relationships, shared credentials, and overlooked administrative pathways. The technical term suddenly becomes tangible.

Attackers do not need to destroy the whole estate to change the incident. They only need enough access to make the organisation uncertain about where the next consequence may appear.

Once that uncertainty spreads, every decision becomes heavier. Can the organisation isolate this segment without stopping a critical process? Can the team revoke this account without locking out legitimate administrators? Can they disconnect the file share without disrupting payroll, clinical care, logistics, manufacturing or customer service?

The problem is no longer only where the attacker is. It is what leadership can still interrupt without creating its own crisis.

The first compromise is the entry point.
The incident is the distance the compromise is allowed to travel before control is restored.

The clock is not waiting for the meeting

The public evidence is uncomfortable because it shows that this is not a slow, theoretical risk.

Some intrusions move quickly enough to outrun decision processes. Others remain quiet long enough to understand the environment before leadership fully understands the incident. Both patterns create the same executive problem: by the time leadership has the first confirmed fact, the attacker may already have created the next one.

That is why a clean first alert can be misleading. It can make the organisation feel as if the incident has been caught early. Sometimes it has. But sometimes the alert is only the first visible consequence of work the attacker has already completed.

The first question is therefore not only: “Which machine raised the alert?”
The better question is: “What paths could this compromise have used before we saw it?”
Breakout time, dwell time and trusted movement
The timing evidence behind this article is deliberately kept in one evidence box so the main article can stay focused on the executive consequence.

CrowdStrike’s 2026 Global Threat Report describes average eCrime breakout time falling to 29 minutes in 2025, with the fastest observed breakout recorded at 27 seconds. The point for leadership is not the number alone. It is that lateral movement can become real inside the time normally used to assemble context and coordinate authority.

Mandiant’s M-Trends 2025 report describes global median dwell time rising to 11 days from 10 days in the previous year. That creates the other version of the same problem: not every attacker moves loudly; some remain quiet long enough to study the environment before the first visible business signal appears.

Microsoft Incident Response’s 2026 investigation into a third-party compromise gives the trusted-boundary lesson: identity infrastructure, operational tooling and third-party management relationships can become part of sustained access. Movement may therefore pass through routes the organisation already allowed.

There is one management lesson to be drawn from this: the first alert is evidence of visibility, not proof of containment.
View more details chevron A white downward-facing V-shaped chevron on a transparent background.
View more details
Close more details

Why visibility alone does not create a boundary

A security team can see something and still be unable to stop what it is becoming.

That sentence matters because many organisations have invested heavily in visibility. Dashboards improved. Alerts became richer. Endpoint tools became smarter. Logs became deeper. Detection matured. But detection still creates a question before it creates a boundary. It tells the organisation where to look. It does not automatically decide what to interrupt.

In a calm environment, that distinction is manageable. Analysts investigate. Owners validate. Change boards approve. Business impact is reviewed. Actions are taken through the usual governance channels.

During movement, the sequence breaks. The attacker is not waiting for normal governance. They are using the gap between suspicion and authorised interruption. They are exploiting the hesitation created by partial evidence: enough signal to worry everyone, not enough certainty to make everyone comfortable with disruption.

That is exactly the kind of environment where traditional assumptions about borders become fragile. The attacker does not always cross a visible perimeter. They move through relationships the organisation already allowed.

MOVEMENT OFTEN LOOKS LIKE WORK
The hardest behaviour to interrupt is not always the behaviour that looks hostile.
It is the behaviour that looks administrative, authorised or routine until the consequence becomes visible.

The leadership dilemma

The CISO may want immediate isolation. Systems engineers may warn that isolation could break dependent services. Operations may fear that stopping one route will stop a shift, a ward, a production line or a customer process. Legal may ask what is already known. The CEO may want a clean answer the team cannot yet responsibly give.

Everyone is acting rationally. That is the problem.

Rational hesitation becomes an attacker advantage when the organisation has not pre-agreed what may be interrupted under uncertainty. The earliest containment decision is rarely made with perfect evidence. It is made in the gap between a credible signal and a confirmed map.

That gap is where movement wins.

The business pressure is not whether the security team understands lateral movement. The pressure is whether leadership has already decided how far a system, account, tool or segment may be allowed to communicate once the first serious signal appears.

Without that boundary, the organisation debates the shape of the fire while smoke moves through the building.

When the first alert arrives, who has authority to interrupt movement before the full blast radius is known?

What containment changes

Containment changes the meaning of the first alert.

Without containment, the alert is mostly a starting point for investigation. With containment, it can also become a point of control.

The organisation does not need to prove every detail before reducing what the compromise is allowed to reach. It can narrow possible paths, preserve evidence, limit blast radius and keep the incident from becoming larger while the investigation catches up.

That is the difference between watching movement and governing it.

This is exactly where we focus our efforts—not at the outset as another promised layer of prevention, and not at the tail end as a generic resilience slogan. Instead, we operate at the precise moment where the organisation has seen enough to act, but cannot afford to wait for perfect certainty.

An operational containment layer gives leadership a way to interrupt malicious behaviour, stop lateral movement, prevent data theft, contain blast radius and preserve control while the business is still under pressure.

It is not another way to admire the cascade. It is a way to stop the cascade from becoming the outcome. For executive teams, that distinction is decisive. The objective is not to make every first compromise impossible. That will remain a dangerous promise in any complex environment. The objective is to make sure the first compromise is not automatically allowed to become the business incident.

CONTAINMENT IS NOT PANIC
Containment is not the same as pulling every plug.
Mature containment means interrupting the paths that matter before the attacker turns uncertainty into reach.

The first alert should start a different conversation

The next incident will probably not begin with a board-ready explanation. It may begin with a strange login, a noisy endpoint, a supplier route, a remote tool, a file copy, a credential behaving oddly, or a server doing something it should not.

The first alert may be technically accurate but operationally incomplete. It may tell your organisation where something became visible; it cannot tell your organisation what has already become reachable.

That is why the first alert should start a fundamentally different conversation. It is not only about: "what happened here?" But also: "what can this still become if we do not interrupt it now?"

The first question investigates the compromise. The second protects your organisation.

The first alert was not the boundary. It was the moment your executive team had to create one.

SEE HOW YOU CAN MAINTAIN CONTROL
Pressure-test whether the first alert in your environment can become governed containment before movement turns one compromise into wider business consequence.

We can run a free, remote resilience assessment inside your own environment.

Hear first when a new S10 Group release is published

Would you like to receive a short note when S10 Group publishes a new article or newsletter?

Leave your name and email address below. We will send a short update when a new release is available, with a brief summary and a direct link to the publication.

No noise. No automated campaign stream. Just a simple signal when there is something worth reading.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Coming soon

Monday 14 September:
"When Ransomware Becomes a Standing Operational Pressure"

Friday 16 September:
"What happens when something still slips through?".

Further readings