

The previous newsletter issues looked at what happens when trust fails, when a critical vendor becomes unsafe, when the first hour is still waiting for permission and when detection does not become action quickly enough.
This final issue moves one layer earlier. It asks a more uncomfortable question:
how much of the eventual consequence was quietly built before the incident began?
That is the difficult part of retention drift. Nobody usually decides to create a future breach multiplier. Nobody sits in a meeting and says: let us keep old data, broad access and forgotten identity paths alive so the next incident becomes larger.
It happens in smaller, more reasonable moments. A data copy stays because migration is not finished. A dataset is kept because someone may need it. A service account survives because nobody owns it. An export lands in a reporting environment and becomes normal. A temporary exception becomes part of how the business runs.
When an incident breaks, the initial hours are not defined by technical resolution, but by absolute operational uncertainty. Which records were reachable? Which copies still existed? Which systems held data the business assumed had become irrelevant? Which trusted paths still connected to old data stores, exports, archives or exceptions that nobody had revisited for years? And if those old exceptions are still reachable, they can become exactly the material an attacker wants most: data with leverage, access with consequence, and pathways that still work because nobody had been forced to close them before pressure arrived.
The attacker did not create all of that in the moment. The attacker found it.
A breach is rarely shaped by data volume alone. It is shaped by three quiet multipliers that often exist long before the first public statement is written.
Retention is what still exists. Access scope is what can still be reached. Identity pathways are the trusted routes that still connect people, services, suppliers, integrations and automated processes to that data.
That triad is what makes retention drift more dangerous than storage waste. Old data only becomes a live problem when trust paths still lead to it.
That matters now because attackers increasingly operate through what organisations already trust. Microsoft describes persistent access, identity-driven intrusion and preventable exposure across critical infrastructure.
ReliaQuest described a recent reporting period in which “trust” itself was the key attack surface, with attackers exploiting trusted tools, identities and user behaviour. In healthcare, Vectra describes long reconnaissance periods in which attackers map networks, identify critical systems and look for leverage before impact becomes visible.
Detection still matters. But detection cannot easily clean up years of accumulation once the incident is already moving. Kudelski describes a narrow detection window in some ransomware cases, with attackers moving from initial access to full domain control within hours. By then, old data, forgotten access and trusted pathways may already have defined how wide the incident can become.
That is the real multiplier. Not only what the attacker does. What the environment still allows the attacker to reach.
The point is not to prove that a retention policy exists. The point is to discover whether the organisation can still reduce exposure when old data, broad access and trusted identity paths become a live control problem.
A useful pressure-test is simple: take one sensitive data category and trace it from policy to reality. Where does it live? Where was it copied? Who can reach it? Which identity path still connects to it? What would break if that path was narrowed? And if the answer is “we do not know”, the blast radius is already larger than leadership thinks.
I would not describe retention drift as a legal tail-end issue. It is part of operational resilience because a security breach cannot always be prevented.
When trust breaks, old exposure does not remain old. It becomes current.
Former-customer data becomes customer impact. Dormant access becomes attacker reach. A forgotten export becomes a disclosure problem. A trusted identity path becomes a way to turn yesterday’s exception into tomorrow’s headline.
Retention drift does not create the incident. It can enlarge what the security incident is able to touch.
Control decides whether that exposure becomes theft, encryption, spread or operational collapse once the attacker is inside.
The Odido reporting makes that point visible. The investigation into retention periods is not the core cyber incident, but it shows how old records can create a second layer of consequence once attackers gain access: data exposure, regulatory scrutiny and a longer trust problem for people who believed the relationship had already ended.
But retention discipline is only one part of the answer; it merely reduces what happens to be stored there. It does not, by itself, stop an attacker who has already successfully entered the environment.
That is where operational control becomes decisive. Our platform is built for the exact moment prevention has been bypassed and the organisation must still maintain control. It detects lateral movement, prevents data theft, protects virtual environments, halts ransomware encryption, and interrupts malicious behaviour before a single compromised path escalates into a wider operational crisis.
Consequently, the practical leadership question becomes far sharper than retention alone:
If an attacker reaches your data tomorrow, can you detect the movement and stop the data theft before exposure becomes wider consequence?
If that would be relevant for your team, feel free to contact me:
With this fifth issue, we close the first arc of this newsletter: identity, dependency, first-hour authority, detection delay and retention drift. Together, they point to the same uncomfortable lesson. Modern incidents do not become difficult only because attackers get in. They become difficult because access, data, dependencies, decision rights and operational assumptions have already shaped how much control remains when pressure arrives.
That is why the next phase of Control Under Pressure will widen the lens.
From next month, the newsletter moves into a new editorial theme:
The Governable Organisation
The question is no longer only how to contain a specific incident. It is how to build an organisation that can still make decisions, narrow exposure, preserve operations and explain its actions when prevention has already been bypassed. This next phase connects three S10 content streams:
The Resilience Briefings
Why resilience has changed — and why continuity now depends on control, not only recovery.
CISO & Leadership Dynamics
Why cyber leadership has changed — and why technical reality now has to be translated into governance, authority, budget and accountability.
When Attacks Move
How control is actually lost — through lateral movement, trusted paths, identity misuse, supplier exposure, data reachability and operational delay.
The first multi-series release starts in September 2026.
Thank you for reading this first arc. The next one moves from incident containment to a larger question:
What makes an organisation governable when pressure arrives?