Skip to main content
CybersecurityVulnerability Management

Cybersecurity Tests Miss Mark by Focusing on Isolated Techniques

A dimly lit monitoring room with rows of empty computer screens displaying generic system diagrams and blank interfaces.

“93% of security leaders say their organization suffered a business‑impacting cyberattack in the past 12 months,” Filigran’s State of Threat Management report finds — a striking metric that reframes the debate about how organizations validate security.

Filigran's report: numbers that point to a hidden gap

Filigran’s State of Threat Management report supplies the arithmetic behind the complaint security teams have been making for years: testing controls against individual techniques is not stopping breaches. Alongside the headline 93% figure, the report states that 88% of security leaders believe AI is accelerating how quickly attackers move once inside, and 84% identify siloed tools and disconnected testing as a principal cause for exposures going undetected until exploitation. Those percentages, taken together, underline a recurring operational failure: defenses may be validated in isolation but still fail when adversaries string steps together.

The DGFiP breach in 2025: a chain, not a single failure

Filigran cites the 2025 breach of France’s tax authority, the DGFiP, as an illustrative case. According to the source, no single step in that intrusion was particularly exotic. Instead, a coordinated sequence — initial access, credential abuse, lateral movement, and exfiltration — turned a handful of individually survivable weaknesses into a major breach. The account emphasizes that each control along the way may have "worked" on its own, and yet the chain still succeeded by exploiting gaps between tools, teams, and alerts.

OpenAEV's Attack Chaining: testing sequences end to end

Filigran presents Attack Chaining, a capability in OpenAEV, as a response to that exposure gap. Rather than exercising single techniques against controls, Attack Chaining links techniques into live, multi‑stage attack paths that use the real output of one action to decide the next. A harvested credential, an open port, a token, or a misconfigured permission becomes a literal branching point: recon reveals a target, a credential dump yields a password, that password unlocks the next machine, and the chain adapts as it discovers what exists in the environment. The vendor frames this as delivering the realism of a red team engagement in minutes and at lower cost, allowing continuous, repeatable testing that keeps pace with a changing environment.

The five technical levers that make chaining work

  • Open, conditional chaining logic: operators build reusable, multi‑stage paths that branch automatically based on live findings; the logic stays inspectable so teams can update it as tactics evolve.
  • Live attack path mapping: every hop and pivot renders on an interactive graph in real time, giving defenders visibility into how a path is forming rather than only a post‑mortem summary.
  • Transparent, actionable findings: every result (credential, IP, token, file) becomes a structured finding that explains why an action ran, what it returned, and how it drove the next step — enabling the identification of chokepoints where a single fix collapses downstream risk.
  • Scope and safety controls: chains run inside pre‑defined guardrails — permitted assets, allowed actions, and escalation limits — enabling autonomous execution without losing control of boundaries.
  • Social engineering as a first‑class stage: phishing emails, SMS lures, and fake landing pages are nodes in the chain; a click or submitted credential feeds directly into subsequent stages, so an end‑to‑end path can move from pretext to exfiltration seamlessly.

XTM One autonomous orchestration and operator‑led alternatives

Filigran describes two execution models that use the same conditional engine and scope controls. Operator‑led mode lets humans build the conditional logic and control execution for deterministic, repeatable testing. Autonomous Attack Chaining hands judgment to an AI orchestrator powered by XTM One: an operator defines an objective and scope, and the orchestrator plans, executes, and adapts — calling specialist agents for payload creation, code generation, recon, or exploitation as needed. Both modes aim to feed results into a unified exposure score rather than leaving findings as isolated reports.

What this means for technologists, procurement leaders, and policymakers

  • Technologists and security teams: run multi‑stage chain tests regularly, inspect the conditional logic and interactive graphs, and hunt for chokepoints where a single remediation collapses entire attack paths.
  • Procurement and enterprise leaders: demand continuous, end‑to‑end validation that integrates social engineering and chained techniques into exposure scoring rather than accepting point‑in‑time, technique‑only testing as sufficient.
  • Policymakers and regulators: consider whether assurance frameworks and reporting should recognize chain testing as a distinct capability given how sequences — not isolated controls — produce many business‑impacting breaches.

The core takeaway Filigran advances is direct: testing attack surfaces — individual techniques — and testing attack chains are different tasks, and organizations that only do the former are at growing risk as adversaries move faster and coordinate steps that exploit the seams between tools and teams. Filigran has scheduled technical webinars to demonstrate chain testing in practice: (Europe) Tuesday, September 29 at 11am CEST, and (Americas) Thursday, October 1 at 11am EDT.

Read the original story: https://thehackernews.com/2026/09/attack-chains-not-just-attack-surfaces.html