The line gets repeated so often in cybersecurity circles that nobody questions it anymore: attackers only need to be right once, defenders need to be right every time. It sounds true. It’s also mostly wrong, and believing it is making a lot of security teams worse at their jobs. Cisco Talos made the case this week using, of all things, Wimbledon: a tennis player who wins barely more than half their points can still dominate a match, because winning isn’t about a single perfect shot. It’s about stringing together enough small advantages over time. Intrusions work the same way. An attacker doesn’t need one miracle exploit. They need dozens of steps to go right in sequence, and that gives defenders dozens of chances to make one of them go wrong.

Two other stories from this week back that up in very different ways. Datadog Security Labs flagged campaigns using dormant, years-old GitHub accounts to quietly map corporate organizations, repositories, and users, weeks or months before anything resembling an attack happens. And Dark Reading reported that Iran’s cyber operations have moved well past critical infrastructure, hitting anything internet-facing regardless of sector, because obscurity was never a real defense to begin with. Neither of these is a smash-and-grab. Both are patient, multi-stage operations that give defenders far more than one shot at detection.

The One-Shot Myth Ignores How Attacks Actually Start

Ransomware headlines make it feel like breaches happen in an instant: one phishing click, one exposed RDP port, and suddenly it’s game over. In reality, the compromise you read about in a press release is usually the last visible step in a chain that started weeks earlier. The GitHub reconnaissance campaigns Datadog described involve operators scraping organization structure, repo names, and user lists through the GitHub API, often using accounts that have sat dormant for years specifically so they blend in with normal traffic. That’s not an exploit. That’s homework. And homework leaves a trail: unusual API call volumes, legitimate-sounding but oddly generic user agents, access patterns that don’t match how your actual employees use GitHub.

Iran’s broadened targeting tells a similar story from the opposite direction. When a threat actor stops caring whether you’re a power utility or a mid-size logistics company and instead scans for any internet-facing vulnerability, the “why would they target us” defense evaporates. That mindset, common among smaller IT shops that assume they’re beneath notice, is exactly the kind of thinking the one-shot myth reinforces. If you believe attackers are surgical and rare, you underinvest in the boring, continuous work of threat detection. If you understand they’re opportunistic and patient, you start looking for the reconnaissance phase instead of waiting for the exploitation phase to tell you something’s wrong.

Illustration representing dormant ghost accounts being used to quietly enumerate corporate systems
Dormant accounts, aged just enough to look ordinary, are doing the quiet legwork before any attack begins.

Defense In Depth Isn’t A Buzzword. It’s Just Math

Here’s the part the tennis analogy actually nails: if an attacker needs to win, say, eight sequential points to close out an intrusion, and your defenses give you even a modest chance of catching each one, your odds of stopping the whole chain compound fast. That’s the entire logic behind defense in depth, and it’s why chasing a single silver-bullet control is such a waste of budget. A firewall that blocks the initial scan is one shot at winning. A firewall plus threat-protection rules on outbound traffic plus brute-force lockouts on exposed logins plus alerting on anomalous API usage is five or six shots. You don’t need every layer to be perfect. You need enough layers that the attacker’s probability of running the table drops toward zero.

This is also why security hardening pays off disproportionately compared to its cost. Hardening doesn’t stop a determined, resourced attacker outright, but it removes cheap, reliable paths and forces them into steps that are noisier, slower, and more likely to trip an alert. Every extra step is another point they have to win.

Reconnaissance Is The Cheapest Detection Opportunity You’re Ignoring

Most incident response programs are tuned to catch exploitation and lateral movement, because that’s where the damage happens. Far fewer are tuned to catch the recon phase, even though it’s often the longest and noisiest part of the whole operation. Attackers scraping your GitHub org, enumerating your employee list on LinkedIn, or fingerprinting your externally exposed services are generating log data right now that most organizations never look at until after something breaks. Treating reconnaissance as a detection surface, not just an afterthought in a post-incident timeline, is one of the highest-leverage changes a security team can make without buying anything new.

Where To Actually Put Your Detection Budget This Quarter

None of this requires a platform overhaul. It requires shifting attention toward the early, unglamorous stages of an attack chain where you have the most chances to intervene.

  1. Audit third-party OAuth grants and API access to code repositories. Revoke anything unused in the last 90 days, and alert on new personal access tokens with broad scopes.
  2. Baseline normal API and login behavior for the services attackers actually use for recon, GitHub, cloud consoles, VPN portals, so anomalies stand out instead of drowning in noise.
  3. Enforce brute-force lockouts and rate limits on every externally facing login, not just the ones you consider high value. Iran’s opportunistic targeting doesn’t care which system was “important.”
  4. Segment internet-facing assets from internal infrastructure so a single exposed vulnerability isn’t a straight line to the crown jewels.
  5. Build incident response runbooks around slow-burn campaigns, not just smash-and-grab ransomware, so a months-long recon-then-strike operation gets flagged before it reaches the exploitation stage.

Do this consistently and you’re no longer betting everything on catching the one moment of exploitation. You’re betting on catching one of many.

Stop Grading Your Team On A Curve That Doesn’t Exist

The “defenders must be perfect” framing does real damage beyond bad strategy. It burns out security teams who measure themselves against an impossible standard, and it lets leadership off the hook for underfunding the boring, continuous parts of a cybersecurity program, logging, monitoring, patch cadence, because the org has quietly accepted that a breach is inevitable anyway. It isn’t. Most successful intrusions involve multiple detectable failures, not one unavoidable one. Reframing security around “how many of their steps can we catch” instead of “did we stop the one thing” changes what gets funded, what gets measured, and what gets forgiven when something does go wrong.

Frequently Asked Questions

Does defense in depth actually reduce breaches, or is it just more tools to manage?
It reduces breaches when each layer targets a different stage of the attack chain, recon, initial access, lateral movement, rather than duplicating the same control. The goal is more independent chances to detect, not more dashboards.
How do we detect reconnaissance if it looks like normal API or login traffic?
Baseline what normal looks like for your actual users first, then alert on volume spikes, unusual access patterns, or activity from accounts that have been dormant for long stretches, all signs seen in recent GitHub enumeration campaigns.
Should smaller organizations worry about state-linked actors like Iran’s cyber units?
Yes, if you’re internet-facing. Recent reporting shows targeting driven by exploitable vulnerabilities rather than sector or size, so any exposed, unpatched, or weakly authenticated service is fair game.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.