The Five Controls That Would Have Prevented Every Major Breach in This Series
This series has covered more than a dozen of the most significant cybersecurity incidents of the past 18 months. A global retailer. Multiple insurance giants. A real estate firm. A government cybersecurity agency. A global fast food chain. Different industries. Different attackers. Different data. One pattern: the same five controls were missing every single time.
Over the course of this series, we've examined breach after breach — analyzing exactly how attackers got in, what they took, how long they went undetected, and what it cost. The incidents span retail, insurance, commercial real estate, government agencies, and fast food. The attackers range from sophisticated groups with documented multi-year track records to small teams who rely entirely on phone calls and social engineering.
The financial impacts range from tens of millions to hundreds of millions of dollars. The reputational damage in some cases exceeded the direct financial cost. And in every single case, the same pattern holds: the breach was preventable. Not with expensive enterprise security tools. Not with a dedicated security operations center. With five controls available to every small business — most of which cost nothing to implement.
The breach pattern — what every incident had in common
The five controls — and what each one closes
Help desk verification protocol
Policy · FreeThe single most impactful control in this series — because it addresses the entry point used in more documented breaches than any other. Every major incident that began with a phone call could have been stopped by one rule: no password resets, no account access changes, and no MFA modifications based solely on a phone call, regardless of how legitimate the caller sounds.
The protocol has three components. First: all IT support requests must be submitted via a ticketing system before any action is taken. Second: if a caller claims to be an employee or vendor, hang up and call back on a known internal number. Third: any request involving admin-level access or MFA changes requires in-person confirmation or a verified video call.
Phishing-resistant MFA with number matching
Configuration · FreeStandard push notification MFA is vulnerable to three documented attack techniques: prompt bombing (flooding approvals until one is clicked), SIM swapping (hijacking a phone number to intercept SMS codes), and real-time phishing relay (capturing and forwarding MFA codes faster than they expire). All three appeared in breaches documented in this series.
Number matching closes prompt bombing immediately — it requires the employee to type a code shown on the login screen into their authenticator app, making automated approval impossible. Phishing-resistant MFA (hardware security keys or passkeys) closes all three by requiring physical possession of a device during authentication.
Credential monitoring — continuous, not periodic
Monitoring · Starts FreeThe 292-day average detection time for credential breaches exists because most organizations check whether their credentials have been compromised periodically — or never. Credential stuffing attacks are automated and continuous. The gap between when a credential is stolen and when it's used against a business system is often hours. Checking once a quarter means the attack succeeds 87 times before you notice.
Continuous credential monitoring watches your domain against breach databases in real time — flagging when a new employee email appears in a breach dump, triggering an immediate password change before attackers test the credential against your systems. The Guardz data shows 31% of SMB users have a compromised credential in any given month. Without monitoring, you have no way to know which 31%.
Vendor and access hygiene audit
Policy · FreeThe 2026 Verizon DBIR documented that third-party breaches now account for 48% of all incidents — up 60% in one year. Nearly half of all breaches no longer happen through a direct attack on the victim's own systems. They happen through a vendor, contractor, or SaaS platform with granted access whose security is outside the victim's control.
Access hygiene has three components: knowing which vendors have access to your systems, ensuring each has only the minimum access required for their function, and removing access when it's no longer needed. The last one is where most businesses fail — a contractor whose account is still active two years after they left, a vendor with access to your full customer database when they only need to send emails.
External attack surface visibility
Monitoring · Starts FreeThe most dangerous security gap isn't the one you know about — it's the one you don't. The open port you never knew was exposed. The DMARC record set to monitor instead of enforce. The admin panel visible from the public internet. The credential in a breach database you never checked. Attackers scan your external attack surface continuously. Most small businesses never look at what's visible from the outside.
External attack surface visibility means knowing what an attacker's automated scanner sees when it hits your domain — before the attacker does. Continuous external monitoring surfaces new exposures as they appear rather than waiting for the annual check that most businesses never get around to.
The implementation checklist
The five controls work as a system. An attacker who can't get through the help desk will try credential stuffing. An attacker who can't use a stolen credential will try session token theft. An attacker who can't get through your front door will try your vendor's. All five matter — not just the most obvious one.
Your five-control implementation checklist
The honest conclusion
Every breach covered in this series generated headlines, investigations, class action lawsuits, regulatory filings, and crisis communications. Every one cost the affected organization more to respond to than the five controls would have cost to implement. And in every case, the root cause was not a sophisticated attack that couldn't be stopped — it was a fundamental gap that had been there, unaddressed, long before the attacker arrived.
The five controls in this post are not a comprehensive security program. They're the minimum — the baseline that stops the attacks actually happening at scale right now. They're the reason some organizations targeted in documented campaigns didn't become breach victims. Those businesses didn't get lucky. They had something in place that made the attacker move on.
One afternoon. Five controls. That's the gap between being in the 89% and not being in the 89%.
📚 Credential Security Series — Read the full series
See how your business scores on all five controls. Veriti Spottr's beta is free.
Get your CyberScore →
Comments
Post a Comment