"What happens when something still slips through?" represented by a premium 3D conceptual engineering render set against a pristine, bright white backdrop, tailored for a high-end thought-leadership header. On the right side of the frame, a horizontal track of polished silver steel runs across a glossy, reflective white floor. A single, transparent sapphire glass sphere enters the track from the edge, internally fractured with a subtle, glowing amber data thread—representing the initial foothold. However, slightly further down the path, a heavy, solid vertical block of brushed titanium has stepped down onto the track, completely halting the sphere's forward momentum. Along the point of impact, a vibrant, light-blue neon edge glow activates, cleanly absorbing the kinetic energy and containing the disruption. The entire left half of the image features expansive, clean white negative space with smooth light gradients, optimized for high-contrast dark typography. Elite corporate technology brand aesthetic."What happens when something still slips through?" represented by a premium 3D conceptual engineering render set against a pristine, bright white backdrop, tailored for a high-end thought-leadership header. On the right side of the frame, a horizontal track of polished silver steel runs across a glossy, reflective white floor. A single, transparent sapphire glass sphere enters the track from the edge, internally fractured with a subtle, glowing amber data thread—representing the initial foothold. However, slightly further down the path, a heavy, solid vertical block of brushed titanium has stepped down onto the track, completely halting the sphere's forward momentum. Along the point of impact, a vibrant, light-blue neon edge glow activates, cleanly absorbing the kinetic energy and containing the disruption. The entire left half of the image features expansive, clean white negative space with smooth light gradients, optimized for high-contrast dark typography. Elite corporate technology brand aesthetic.
S10 Group Article series · Why leadership changed

What happens when
something still slips through?

Prevention reduces the chance of entry.
It does not decide what remains controllable after entry.
Article #5
Published: 16 September 2026
By Stan van Gemert | S10 Group
By Stan van Gemert
The CISO series

Executive summary

The previous publication, "When Ransomware Becomes a Standing Operational Pressure", argued that ransomware in healthcare is no longer best understood as an exceptional outage. It is a continuing operational pressure that can combine encryption, data theft and disruption while exploiting the obligation to keep essential services running.

This article follows the leadership question that pressure creates. Prevention may reduce the chance of entry, but it does not decide what remains controllable once something still slips through. In that moment, the CISO is no longer dealing only with an alert, a suspicious account or a compromised pathway. The question becomes what can be safely stopped before uncertainty spreads through identities, suppliers, systems, workflows and operations.

This article shows why modern cyber resilience is increasingly determined after prevention has been bypassed. Detection may reveal that something is wrong, but leadership still needs an executable containment path: which trust routes can be narrowed, which identities can be restricted, which supplier connections can be interrupted, and who has the authority to act before full certainty exists.

The next publication, "The Dashboard Was Green. The Data Was Gone", moves from the leadership dilemma to the operational consequence. It examines how an organisation can remain available, functional and apparently calm while sensitive data has already left its control.

The moment the conversation changes

A serious incident often begins quietly for executive teams. Not every cyber crisis starts with a ransom note. Sometimes it starts with one account behaving strangely. A helpdesk workflow that should have been routine. A remote session that looks valid at first glance. A supplier route that is still trusted because it has always been trusted.

That is where the conversation changes for the CISO.
The question is no longer only: do we see something suspicious?
The question becomes: what can we safely stop?

It is a different kind of question. If an identity is disabled, which processes stop with it? If a supplier route is narrowed, which services become unavailable? If a network segment is isolated, does the organisation protect itself or accidentally interrupt something critical?

The MGM Resorts incident remains useful here because public reporting and analysis have repeatedly pointed to a manipulated service-desk or identity workflow as part of the attack path. The important lesson is not only that attackers found a way in. The more uncomfortable lesson is that a trusted process can become unsafe while the organisation still depends on it.From the outside, the organisation may still look technologically mature.

From inside the incident room, the question becomes much more practical: what do we still trust enough to keep running?
MGM and the trusted-path problem
MGM is a useful background case for this article because it shows how a modern incident can move through trusted operational processes rather than an obvious technical failure.

The supplied source direction frames the incident around social engineering, helpdesk workflow, identity controls and the operational consequences that followed once the attacker moved through a trusted route. In that moment, the CISO problem is no longer only detection. It becomes organisational controllability: which identity paths, administrative routes and business systems can be restricted without creating wider disruption?

That is the lesson to carry into other sectors. In a hotel, hospital, bank or manufacturer, the trusted route may have a different name: a support process, a cloud identity, a supplier connection, a privileged workflow or a remote management path. Under normal conditions, these routes enable the business. Under hostile conditions, they can become the attacker’s cover.

What this proves for leadership: Responsibility can move towards the CISO in minutes, while the levers that determine the outcome sit across identity, infrastructure, suppliers, operations, legal, communications and business continuity.

Control question: If a trusted identity path became unsafe tomorrow, who could restrict it - and what business consequence would that decision create?
View more details chevron A white downward-facing V-shaped chevron on a transparent background.
View more details
Close more details
THE MOMENT AN INCIDENT CHANGES
An organisation may still look functional.
The real incident often begins when leadership no longer knows which trusted pathways remain safe enough to keep operational.

The assumption that holds until it does not

Many organisations have spent years building resilience around a reasonable assumption: if prevention is strong enough, the business remains stable.

That assumption shaped budgets, compliance programmes, tooling discussions, maturity reporting and board updates. It also gave leadership a form of comfort. More controls. Better visibility. Stronger prevention. More evidence that the organisation was taking cyber risk seriously.

None of that is wrong. Prevention still matters. Detection still matters. Compliance still matters.

But the problem starts when those investments create the impression that the outcome is mainly decided before the attacker enters.

In real incidents, the decisive moment often comes afterwards. It comes when the organisation has to decide what to stop, what to keep running, what to isolate, what to restore, what to explain and what to accept temporarily in order to prevent wider harm.

That is a very different resilience test.

A CISO can know that an alert is serious and still face an organisation that is not ready to contain safely. The team may see malicious behaviour, but not yet understand the operational consequence of stopping it. Everyone may agree that action is needed, while nobody is fully comfortable with the first move.

Prevention may reduce the chance of entry.
It does not automatically decide what remains controllable after entry.

When trust becomes the incident

Once attackers move through trusted pathways, the incident is no longer only about the original point of entry. The problem starts to spread through questions.

Which identities are still safe? Which sessions are legitimate? Which administrative routes are being used normally and which are being abused? Which systems can still communicate? Which supplier links should remain open? Which data paths might already be exposed?

These questions are not abstract. They are the kind of questions that slow a CISO down in the exact moment when speed matters. Not because the CISO lacks urgency. Often the opposite is true. The urgency is clear. What is unclear is the operational cost of each move. This is why serious cyber incidents so often become leadership incidents. The organisation is no longer only trying to remove an attacker. It is trying to preserve enough certainty to keep making responsible decisions. And that certainty can disappear before systems fully fail.

Applications may still be available. Employees may still work. Customers may still transact. Patients may still be treated. But if the organisation no longer knows which access, data flows or dependencies can be trusted, control has already started to weaken.

Applications may still function normally while executive teams already lose confidence in the identities, sessions, and operational pathways underneath them.

Why the AI warning matters here

There is another reason this has become harder. Attackers do not only exploit software. They exploit time.

They exploit the time it takes to review a patch. The time it takes to coordinate with a supplier. The time it takes to approve a containment decision. The time it takes to understand which business process depends on which identity, system or connection.

That is why recent public warnings from financial supervisors about frontier AI matter for this article. The warning is not that AI makes cybercrime sound more futuristic. The warning is more practical: stronger models can increase the speed, scale and complexity of cyber attacks, including the analysis of newly disclosed weaknesses.

A software update used to give defenders useful information: this is what changed, this is what needs to be patched, this is what needs to be planned. But that same update can also tell attackers where the weakness was. If AI helps them analyse that change faster, the time between “a weakness is known” and “someone is trying to use it” becomes shorter.

An organisation may still be testing the patch, waiting for a maintenance window, checking business impact, coordinating with a supplier, or trying to understand whether the change will break something critical. That is the real issue.

It is not a story about exotic future attacks. It is a story about time disappearing from the defender’s side of the table.

THE TIME PROBLEM
Attackers increasingly exploit the time between vulnerability disclosure, organisational coordination, operational approval and executable containment.

The gap is not only technical

This is where the discussion needs to become very practical.

The answer is not simply “patch faster”. Of course organisations should patch faster where they safely can. But every CISO knows the reality. Critical environments are not always simple to change. Legacy systems exist. Supplier dependencies exist. Operational windows exist. Testing matters. Some systems support patient care, payments, logistics, manufacturing or customer operations that cannot be interrupted casually.

So the real question is not only whether your organisation can close every weakness in time. The real question is what happens when it cannot. If attackers enter before the weakness is closed, can malicious behaviour be seen? Can spread be interrupted? Can data movement be narrowed? Can your organisation isolate the unsafe route without shutting down more of the business than necessary?

This is the moment where many mature environments discover the difference between having security tools and having an executable control path.

An alert may be visible. A risk may be understood. But if your organisation does not know what it can safely stop, the attacker still benefits from hesitation.

If attackers can move from public weakness to operational compromise faster than your organisation can patch or coordinate, prevention alone becomes a fragile assumption.

The issue is bigger than incident response

This article is neither a tactical checklist nor a deep technical walkthrough; it is a strategic evaluation of corporate governability. It addresses the critical misconception many organisations still carry into resilience planning: the belief that a complete prevention programme will determine the outcome of a breach.

Modern incidents continuously challenge that assumption. The outcome of an intrusion is heavily shaped post-entry, when executive teams must act without the luxury of complete certainty. It is determined by the capacity to narrow trust paths, interrupt lateral spread, preserve business continuity, protect forensic evidence, validate clean recovery, and defend decisions while your organisation is under intense pressure.

That is exactly why "something slipped through" should not be treated as an automatic failure. It only becomes catastrophic when your organisation lacks a pre-governed mechanism to contain the threat once it occurs.

Containment as operational stabilisation

An operational containment layer transforms containment from a clinical security term into an active governance mechanism. It is not introduced to add another passive dashboard, nor to serve as an additional visibility layer, and it is certainly not a promise that nothing will ever pass your perimeters.

Instead, containment matters because it provides executive teams with a calculated, actionable move when internal trust is incomplete. It enables your organisation to interrupt lateral spread, reduce the blast radius, limit data-theft escalation, preserve business continuity wherever possible, and stabilise the environment while high-stakes decisions are still being formulated.

Preserving control under pressure resides at the exact centre of the resilience discussion. True capability is neither about promising a fiction of perfect prevention, nor about waiting for total confidence until every variable is understood. It is about the absolute capacity to maintain control when a threat has already entered the environment—and your business simply cannot afford to wait for complete certainty.

For a CISO, that distinction matters deeply. In the heat of a live incident, the executive bridge is not judged solely on whether an attacker entered the network; your team is judged on whether the situation remained fundamentally governable after entry


Governed, not assumed.

CONTAINMENT IMPLICATION
Containment is the missing operational move between seeing the problem and allowing uncertainty to spread through the organisation.

Pressure-test question

If something slipped through tomorrow, would your executive team know which systems must survive first?

Would technical leadership have the visibility to determine which identities can be restricted immediately without breaking critical operations?

Would your organisation know which supplier routes can be narrowed safely, which operational pathways create the highest escalation risk, and who carries the pre-agreed authority to contain a threat before certainty fully exists?

If a newly disclosed weakness were being actively exploited before the next maintenance window, would there still be a pre-governed mechanism to interrupt malicious behaviour inside the network?

If those answers are unclear, resilience may still be measured too heavily through prevention assumptions. The real question is not whether every intrusion can be prevented. The real question is what remains controllable once prevention is no longer the deciding factor.

The next horizon

This article looked at the moment where prevention stops being the centre of the resilience discussion and controllability takes its place. Our next article follows another consequence of that shift.

Once attackers move through trusted environments, spread rarely follows organisational charts. It follows identity, access, suppliers, business workflows and operational relationships instead.

Control can still be regained - if a containment move exists.

Hear first when a new S10 Group release is published

Would you like to receive a short note when S10 Group publishes a new article or newsletter?

Leave your name and email address below. We will send a short update when a new release is available, including a brief summary and a direct link to the publication.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Coming soon

Friday 18 September:
"The Dashboard Was Green. The Data Was Gone"

Monday 21 September:
"When One Breach Becomes Everyone’s Problem"

Further readings