Cyber attackers quietly accessing business systems over time without detection

The Attacker Doesn’t Need to Be Clever. They Just Need Time.

Liked this post? Share with others!

Most businesses imagine a cyber attack as a loud and active event. The attackers gain entry to the systems and the lights go off, computers go dark and alarms ring while they deliver the attacker’s ransom demands. The IT team are running in circles, the executives barricade themselves in a boardroom and chaos immediately ensues. 

I am sorry to tell you that this is not the way it works in the real world. 

The attacker doesn’t want you to know they’re there. There are no alarms and without visibility your team just continues working because they have no idea they are there. 

Once they get access, the cyber criminals can spend days, weeks or months quietly learning how your business works. They can work out who has access to what, which systems matter, where the valuable data sits and how they can move around without attracting attention.

Most research tells us that it will take around 200 days for a business to discover a cyber attack has taken place. This often will come from a customer alert or the dreaded ransom note. A long time after the initial breach.

The attack doesn’t need to look like an attack

There may be no ransom note. No screens flashing red. No dramatic Hollywood moment where someone announces that the network has been hacked.

Instead, there might be:

  • A compromised account logging in. 
  • Someone accessing a system they don’t normally use. 
  • A malicious inbox rule quietly forwarding emails. 
  • Credentials being collected. 
  • A device behaving slightly differently. 
  • Data being accessed gradually.

The attacker is learning.

While the business carries on working, the attacker is working out what they can take, what they can damage and how they can make their payday as large as possible.

The real advantage is time

This is why visibility matters so much. If an attacker gets into your environment today and you don’t detect them for six months, they have six months to understand your business.

  • Six months to find the important accounts.
  • Six months to discover where the valuable information lives.
  • Six months to establish persistence.
  • Six months to work out how to cause maximum damage.

The longer they remain undetected, the more the balance shifts in their favour.

This is also why I don’t believe cyber security should be built around the assumption that prevention will always work.

Prevention is important. Of course it is, but eventually something will get through. A layer of defence will fail: 

  • A user will click something.
  • A password will be stolen.
  • A vulnerability will be missed.
  • A supplier will be compromised.
  • An attacker will find another way in.

The question then becomes: Will you know they’re there?

Cyber resilience changes the question

Cyber resilience isn’t about believing you can build an impenetrable wall around the business, it’s about making the business harder to compromise, easier to monitor and faster to respond when something gets through.

That means having visibility across the entire digital footprint of your business. 

It means you will need to be: 

  • Monitoring identities and access. 
  • It means watching email. 
  • It means protecting machines. 
  • It means understanding where your data is and who is accessing it. 
  • It means knowing what is exposed to the internet.

Critically, it means having someone who can investigate when something doesn’t look right. An alert sitting in a security console isn’t protection.

Someone needs to see it. Understand it. Investigate it. And act.

That is the difference between having security technology and having security capability.

The worst time to discover an attacker

The worst time to discover an attacker is when your customer tells you.

Or when the bank calls.
Or when the files are encrypted.
Or when someone discovers that sensitive information has left the business.

By then, the attacker hasn’t just gained access, they’ve completed the job.

The objective of cyber resilience is to change that timeline.

See the attacker earlier. Understand what they are doing. Stop them before they achieve their objective.

When something does get through, contain it before it becomes a business crisis. You cannot respond to what you cannot see.

That’s why at J2, visibility isn’t a feature we bolt onto security. Visibility is gained through real cyber resilience. 

Get your cyber resilience score completed today. Hit our website, complete the scorecard and get your cyber security review. 

Understand your gaps in the modern digital world, it’s where cyber resilience starts.

author avatar
John Mc Loughlin Director
John Mc Loughlin is a cybersecurity and digital resilience specialist with experience in email security, phishing mitigation, and data protection strategies. He works with organisations to reduce digital risk and improve operational resilience.

Request Consultant