A cyberattack is a seven-stage process. Most companies defend only one or two of those stages.
Picture a room full of cubicles, employees hunched over their desks.
The camera moves in on the tired face of Paolo, who is struggling to keep up with his deadlines. He’s opening an email from a customer. Something about the message is off, but he doesn’t notice. He clicks a link. A black window with white text flashes up for a split second, then the screen turns red.
It’s the scene Hollywood has taught us to recognize. And it has one fundamental flaw: time.
In reality, Paolo clicks that link and, from where he sits, nothing unusual happens. In the background, a small piece of code runs and connects to a remote server. The connection is outbound, so it passes through the firewall undisturbed. Paolo’s workstation has become a beachhead: someone now has a foothold in the organization’s network.
Nobody notices.
Over the following days and weeks, the threat actor moves quietly through the network, sideways, slowly escalating privileges, exfiltrating sensitive documents found along the way. Only once they have enough privileges do they finish the job. Only then is the network compromised, the files encrypted, the backups deleted.
The ransomware message on the screen isn’t the attack. It’s the signature telling you the attack is already over.
The kill chain: seven stages, not one
In 2011, Lockheed Martin published a model that changed the way we think about cybersecurity. They called it the Cyber Kill Chain. The idea was borrowed from military language: an attack isn’t an instantaneous event, it’s a sequence of linked stages. Each one has to succeed for the next to be possible. Break the chain at any point and you stop the attack.
The model identifies seven stages.
Reconnaissance. Automated scanners crawl the internet 24 hours a day. They look for open ports, vulnerable software versions, exposed admin panels. They aren’t looking for you. They’re looking for a specific vulnerability, and you happen to be one of the results. Shodan, Censys, proprietary tools: the process is continuous and needs no human involvement. It leaves no trace in your systems. It triggers no alerts. By the time it’s done, someone already knows what you expose and where the best way in is.
Weaponization. For mass attacks, this stage is already done upstream. Ready-made kits, prepackaged malware, exploits already built for known vulnerabilities, battle-tested phishing templates. They’re bought on the criminal market, complete with reviews and technical support. The threat actor doesn’t need to write a single line of code.
Delivery. The vector is launched. A mass email campaign, an automated scan that finds the open door, an exploit fired at thousands of systems at once. This is the moment when the threat actor depends on an exposed vulnerability or a human action, and it’s the stage where most companies concentrate their defenses.
Exploitation. The payload runs. On the victim’s screen: nothing. No slowdown, no message, no visible sign. Antivirus
often detects nothing, not because it’s faulty, but because the code is designed specifically to look legitimate.
Installation. Something persistent gets installed: a backdoor, a remote agent, a mechanism that survives a reboot. From this moment the threat actor has a fixed point inside the network. They can come back whenever they like, even days later, even if the original session is cut off.
Command and control. The compromised system opens a connection to an external server controlled by the threat actor. Encrypted, indistinguishable from normal web traffic. It passes through the firewall without a problem because it’s outbound: it’s your system calling out, not someone knocking at the door. To the firewall, it’s ordinary browsing.
Actions on objectives. Only now does the threat actor do what they came for. In the simplest cases it’s automatic: encryption and a ransom demand. In the more sophisticated ones, a human operator explores, harvests credentials, maps the network and exfiltrates data before acting. This is the stage that causes the irreversible damage, and it often comes days or weeks after the initial entry.
The dwell time problem
Fourteen days. That’s the median time a threat actor spends in a network before being discovered, according to the latest Mandiant M-Trends report (2026), up for the second year in a row from eleven days in 2024.
Fourteen days in which the threat actor is already inside: they’ve completed the first six stages and are preparing the seventh. They map the network, harvest credentials, work out where the most valuable data sits. Fourteen days in which everything looks normal: the logs record activity indistinguishable from legitimate activity, and the perimeter tools see nothing out of the ordinary.
Because the threat actor isn’t attacking the perimeter. They’re already inside. They move using legitimate protocols and real credentials, generating traffic identical to that of an administrator doing their job.
The firewall doesn’t see them. The antivirus doesn’t see them. The SIEM collects the logs, but if nobody actively correlates them at the right moment, they only record activity that looks normal.
What we see, if we see anything at all, is only the final stage, the seventh of seven. The first six have already happened, in silence, in a stretch of time the threat actor used to maximize the damage.
Defending only at the perimeter leaves five of seven stages uncovered
This is the conclusion the kill chain model makes hard to ignore.
The security spending of many Italian SMBs is concentrated on the perimeter: firewalls, antivirus, anti-phishing filters, VPNs. Tools that mainly cover delivery (stage 3) and, in part, exploitation (stage 4). Necessary tools, but not sufficient.
Stages 1 and 2 (reconnaissance and weaponization) happen outside the network and can’t be intercepted by perimeter tools. Stages 5, 6 and 7 (installation, command and control, actions on objectives) happen inside the network, where the perimeter doesn’t reach.
An effective security strategy doesn’t abandon the perimeter. It completes it with the ability to answer the question the perimeter can’t: what happens if someone is already inside?
It’s a different question from “how do I keep someone out?” It calls for different tools, different logic, a different posture. And it requires accepting an uncomfortable but realistic premise: that the initial entry, to some extent, can happen. Paolo’s email isn’t the exception. It’s much closer to the rule.
The difference between a manageable incident and an operational disaster isn’t measured by how the threat actor got in. It’s measured by how quickly they’re detected once inside, and at which point in the chain.