A premium conceptual technology graphic on a reflective white background illustrating the illusion of system availability. A geometric sapphire glass cube on the right appears perfectly intact on the outside, but contains an internal structural fracture where incoming data streams instantly transform into a volatile orange and purple electrical threat. This internal pollution is completely trapped and isolated by an integrated vertical brushed-titanium barrier outlined in a sharp neon light-blue containment line, ensuring the data pathways extending to the far left remain perfectly clear, secure, and filled with a calm blue binary stream.A premium conceptual technology graphic on a reflective white background illustrating the illusion of system availability. A geometric sapphire glass cube on the right appears perfectly intact on the outside, but contains an internal structural fracture where incoming data streams instantly transform into a volatile orange and purple electrical threat. This internal pollution is completely trapped and isolated by an integrated vertical brushed-titanium barrier outlined in a sharp neon light-blue containment line, ensuring the data pathways extending to the far left remain perfectly clear, secure, and filled with a calm blue binary stream.
S10 Group Article series · Why leadership changed

Trust Often Breaks Before Systems Fail

Why availability can conceal a loss of reliable operating evidence
Article #12
Published: 30 September 2026
By Stan van Gemert | S10 Group
By Stan van Gemert
The CISO series

Executive summary

The previous publication, "When Trusted Systems Become the Attack Path", showed how a valid account, approved supplier connection or expected software channel can become unsafe when the conditions behind its approval change. Access remains operational even though the route no longer deserves the same freedom.

This article examines the next executive problem. Services may still be available while confidence in identity, data activity, instructions and administrative state is already deteriorating. Your teams are then expected to keep the business moving with evidence that may itself be part of the incident.

Containment cannot determine which facts are true, but it can limit what compromised access and uncertain activity are still allowed to do while the operating picture is rebuilt. The practical objective is to preserve decision space before unreliable signals become wider consequence.

The next publication, "The Attacker Had a Map Before Leadership Had a Picture", turns to the asymmetry that created the problem. It examines how attackers can map accounts, dependencies and recovery paths before your executive team has assembled a reliable picture of the incident.

The systems were still running

The data platform was online, the login portal responded and the finance workflow still moved. The first dashboard was green enough to calm the room until someone asked which activity could still be relied upon.

That question changed the incident. A valid login might represent a stolen credential, a routine query might be active extraction and an instruction from a familiar executive might be synthetic. An administrative change could have been made through permissions that were legitimate yesterday and dangerous now. Availability remained visible, but the evidence behind safe operation was becoming unreliable.

Many cyber incidents become harder at precisely that point. Nothing has failed clearly enough to force a common response, yet your teams can no longer assume that a working system, recognised identity or completed workflow is evidence of legitimate activity.

The first loss of control may be the ability to distinguish safe activity from harmful activity inside systems that still appear to work.

Availability can conceal a loss of operating certainty

Availability answers whether a service responds. It does not establish whether the person behind a session is legitimate, whether a database query serves its expected purpose, whether an instruction came from the authority it appears to represent or whether an administrative change preserved a safe state.

That difference places your executive team in an uncomfortable position. Keeping services online may preserve revenue, care, production or customer access, but continued operation can also extend the incident when the signals used to authorise work are no longer dependable.

The difficulty is not simply that facts are incomplete. Some of those facts arrive through identities, logs, requests and administrative records that may already have been altered or misused. The incident therefore affects both the environment and the evidence used to govern it.
When normal operation carried the risk
Snowflake customer instances. In 2024, Mandiant described UNC5537 using credentials stolen by infostealer malware to access customer database instances, query data and exfiltrate records through native platform functions. Mandiant found no evidence that the incidents it investigated resulted from a breach of Snowflake's enterprise environment. Mandiant and Snowflake notified approximately 165 potentially exposed organisations. The platform remained operational; the problem was that valid access no longer represented legitimate use.Arup deepfake fraud.

Arup confirmed that fake voices and images were used in a Hong Kong fraud in which an employee transferred HK$200 million after video calls from people posing as senior officers. Arup also said its internal systems were not compromised. The systems processed the request; the failure lay in the integrity of the authority behind it.

Sources:
https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion
https://www.theguardian.com/technology/article/2024/may/17/uk-engineering-arup-deepfake-scam-hong-kong-ai-video

Source boundary:
The Snowflake case concerns compromised customer credentials, not a breach of Snowflake's enterprise environment.
The Arup case illustrates false authority and request integrity.

Together, the cases show that a working login, approved route or functioning workflow may look legitimate, but does not prove that the activity behind it is always safe.
View more details chevron A white downward-facing V-shaped chevron on a transparent background.
View more details
Close more details

Identity can preserve the appearance of normality

Identity-based attacks are difficult to recognise because the first evidence may look like normal work. Logs can record a known user while the person behind the session is an attacker. A cloud console can show an administrator even though the credential has been stolen. A service account may act within its permissions while violating the purpose for which those permissions were granted.

The response should not treat every unusual action as hostile; that would make normal operations impossible. It should recognise that authentication is only one part of the decision. Behaviour, timing, destination, device, privilege and consequence determine whether continued access remains proportionate.

Once those signals become inconsistent, your teams are managing two linked problems: the suspicious activity itself and the declining reliability of the evidence used to decide what should continue.

IDENTITY DISTINCTION
A recognised identity can establish how access was granted.
It cannot establish the intent behind every action that follows.

The executive team must act before the evidence stabilises

The board will ask whether customers are affected, legal and privacy teams will ask whether notification duties have been triggered, and operations will need to know which services can remain available. Communications will need language that can survive the next confirmed fact. The CISO may not yet be able to provide one definitive account because scope depends on signals that are still being tested.

If valid accounts may be compromised, user activity is uncertain. If query logs contain attacker activity, the exposure picture is uncertain. If privileged changes may have been made by an adversary, recovery state is uncertain. Waiting for every ambiguity to disappear gives the incident more time; acting without a bounded rationale can create unnecessary disruption.

Your response model therefore needs explicit confidence levels, reversible actions and pre-agreed authority. Teams should know what is confirmed, what remains plausible, which evidence threshold permits a containment move and who can accept the operational consequence while investigation continues.

If the systems remain available but the evidence is unreliable, which activities can your teams pause before certainty returns, and who has authority to make that decision?

Containment protects the decision space

Containment does not restore reliable evidence by itself. It limits what uncertain access and harmful behaviour can still do while investigators rebuild the picture. A suspect session can be terminated, an affected workload separated, a data-movement route restricted or a privileged path narrowed before every identity question has been resolved.

The distinction matters because uncertainty expands through action. Every unchecked query, export, session and administrative change can increase the number of systems, people and decisions that later require validation. A bounded intervention reduces that expansion without treating the entire environment as hostile.

Detection tells your teams that something may be wrong. Containment gives them a way to reduce the consequence while they establish what is true.

CONTAINMENT IMPLICATION
Containment cannot make uncertain evidence reliable, but it can stop that uncertainty from acquiring more reach.

Recovery requires renewed confidence

A service that answers is not automatically ready for unrestricted use. Where identity or administrative state has become uncertain, reconnection may require token and credential rotation, privileged-account review, query analysis, renewed access boundaries and validation that recovery has not reopened the same path.

The objective is not perfect certainty about every event. It is enough reliable evidence to explain which identities, routes, workloads and transactions may operate again, under which conditions and with which monitoring. Recovery becomes defensible when those decisions are explicit rather than inferred from uptime.

Reliable action is part of the control architecture

Your CISO cannot rebuild operational confidence alone, but the role includes helping the executive team distinguish availability from safety, fact from assumption and reversible action from irreversible exposure. That work connects technical evidence to decisions about access, continuity, communication and recovery.

The boundaries should exist before the incident: which identities and systems carry exceptional authority, which requests require independent verification, which behaviours justify immediate interruption and which evidence must be preserved so that each decision remains traceable afterwards.

Reliable operation is therefore not a background assumption. It is a condition your teams must be able to test, narrow and restore.

The quiet failure comes first

A ransom note, failed portal or production outage gives an incident a visible name. The earlier failure is often quieter: a session that should have been challenged, a query whose purpose changed, an instruction that imitated authority or an administrative action that passed the technical check while violating the business reality.

By the time systems fail, the evidence behind safe operation may already have been weakening for days. Availability is therefore a poor final reassurance. The stronger question is whether your teams still know what they can safely allow, interrupt and restore.

Your organisation remains governable when it notices the loss of reliable signals early and limits what uncertainty can still do before visible failure removes the remaining choices.

Where our platform fits

Our platform adds an operational containment layer after prevention has been bypassed. It does not replace identity governance, forensic investigation, independent request verification or the business owners who decide which activities may continue. Our role is to help authorised teams interrupt harmful behaviour while those disciplines establish what happened and what remains safe.

Ransomware Containment is our core platform. Its agentless monitoring identifies active file-encryption behaviour across SMB and NFS activity and can isolate the affected user or session while existing antivirus and endpoint controls remain active. Server Intrusion Protection and Virtual Server Protection are additional features running on the same platform, extending control to compromised administrator use on servers and host-level threats in virtual environments.

Our platform helps interrupt lateral movement and data-theft paths while investigation continues and recovery decisions are being made. The practical value is clear: keep the incident boundary smaller, preserve room for evidence-led decisions and prevent a minor compromise from becoming an operational cascade.

The next horizon

The next publication turns from degraded operating evidence to the period in which the imbalance was created. "The Attacker Had a Map Before Leadership Had a Picture" examines how reconnaissance gives an attacker a practical view of accounts, dependencies and recovery paths before your executive team sees the full incident.

It asks what must already be containable when the first meeting begins with fragments rather than a map.

Hear first when a new S10 Group release is published

Would you like to receive a short note when S10 Group publishes a new article or newsletter?

Leave your name and email address below. We will send a short update when a new release is available, with a brief summary and a direct link to the publication.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Coming soon

Friday 2 October, Operational Attack-series #4: "The Attacker Had a Map Before Leadership Had a Picture"

Monday 5 October, Resilience-series #5: "When the Systems Are Back, the Real Impact Begins"

FOCUSED RANSOMWARE RESILIENCE ASSESSMENT

Compare controlled file-encryption scenarios with your existing security controls active, first without Ransomware Containment and then with it. The assessment itself is limited to encryption, but alongside the assessment results, we can explain how our platform and its additional Server Intrusion Protection and Virtual Server Protection features, helps detect and interrupt lateral movement, reduce the risk of data theft, protect remote server access and defend virtual environments such as VMware and Hyper-V. That makes the session useful not only as a ransomware-containment test, but also as a practical discussion about what your organisation can still control when identity, privilege and infrastructure trust come under pressure.‍
A bright conceptual image of upright frosted-glass blocks in sequence. The first block has tilted forward but is stopped by a fixed brushed-titanium pillar rising from the surface, while the remaining blocks stay stable and undisturbed

Further readings