The Pattern Hidden in Every Breach
Every major incident looks like its own story - AI governance one week, an enterprise authentication bypass the next, then a banking malware campaign, a cloud migration, a nation-state compromise, a national blackout. Read enough of them and the same thing keeps surfacing underneath. The breach is rarely the beginning of the story; the beginning is almost always an assumption that had never been tested. Storm-0558 exposed the assumption that a consumer signing key could never authenticate an enterprise account. ServiceNow, that the platform holding the map of every system deserved less scrutiny than the systems. Kimi K3, that self-hosting a model resolves the trust question. The Iberian blackout, that transparency and operational security are the same objective. FASTCash, that banks on shared payment rails carry risk independently. The subject of the analysis is not the technology - it is the widening distance between what organisations believe about their systems and how those systems actually behave under pressure, which may be one of the most important attack surfaces in modern security.
By Aderinola Mercy Oguntokun
DSI Advisory Services
Every major incident looks like its own story. Read enough of them and the same thing keeps surfacing underneath — not a technology, but an assumption no one had tested.
Every major security incident appears to tell a different story.
One week the industry is discussing AI governance. The next it is an authentication bypass in an enterprise platform. Then it is a banking malware campaign, a cloud migration, a nation-state compromise, or the post-mortem of a national infrastructure failure. Different technologies. Different vendors. Different sectors. Different countries.
The temptation is to treat each event as its own story.
Look closely enough, however, and the same pattern begins to emerge.
The more incidents we examined over the past year, the more difficult it became to believe that these were isolated failures requiring isolated lessons. Beneath the technical details, the CVEs, the patch advisories, and the forensic timelines, the same organisational pattern kept appearing.
The breach was rarely the beginning of the story.
The beginning was almost always an assumption.
An assumption that had remained invisible because it had never been tested.
When a Chinese threat actor tracked as Storm-0558 reached into the mailboxes of some twenty-five organisations — including US State and Commerce Department officials and Congressional staff — in mid-2023, the lesson was not fundamentally about email security.1 It was about an assumption buried in the code. A signing key meant only for consumer accounts should never have been able to authenticate an enterprise one; the boundary between the two was taken as a fact of the architecture. It failed for a precise reason: the team responsible for enterprise authentication had assumed the identity library validated the token’s issuer on its behalf. It did not, and no one had tested whether it did. The separation everyone relied on existed only in an assumption no one had checked — and a signing key from 2016, long past when it should have been retired, was still live to exploit it.
ServiceNow’s repeated authentication failures were not simply about a REST endpoint or an AI sandbox.2 They exposed something larger. Organisations had treated the platform documenting every critical system as if it were just another internal tool. The assumption was that production systems deserved the highest scrutiny. In reality, the platform containing the map of those systems deserved exactly the same level of governance, because compromising the map often becomes the fastest route to compromising everything it describes.
The rapid migration towards Chinese open-weight models — the newest of them, Kimi K3, released only in July 2026 as the largest open-weight model yet published — revealed another assumption.3 Many organisations believed that moving a model onto their own infrastructure resolved the security question. Self-hosting addressed data sovereignty. It did not automatically address model behaviour, weight provenance, or the integrity of the software supply chain embedded within the model itself. The assumption that infrastructure alone determines trust proved to be incomplete.
The Iberian blackout of 28 April 2025, which cut roughly sixty per cent of Spain’s generation and left much of the peninsula dark for around ten hours, presented a different lesson altogether.4 Public investigations exist to improve resilience, establish accountability, and rebuild trust. Yet every technical explanation also becomes intelligence. Every dependency diagram, failure sequence, and operational timeline helps defenders understand what happened. It may also help future attackers understand how the same system behaves under stress. Transparency and operational security are not opposing objectives, but neither are they identical.
The FASTCash campaign challenged another institutional assumption: that financial attacks should be understood institution by institution.5 The January 2026 operation demonstrated something more uncomfortable. Banks connected through shared payment infrastructure do not experience risk independently. What appeared to be separate incidents across multiple countries was, in operational terms, a single coordinated campaign exploiting common architectural dependencies. The lesson was not confined to one institution. It was about the exposure created by the ecosystem itself.
Even cloud migration projects revealed the same underlying pattern. Recovery was often treated as the moment systems became available again. Operational reality proved otherwise. Trust cannot simply be restored because infrastructure returns online. It has to be rebuilt deliberately through validation, staged restoration, and continuous verification. Availability is an operational milestone. Trust is a governance decision.
Taken individually, these incidents appear to have very little in common. One examines AI governance, another enterprise software, another banking infrastructure, another national critical infrastructure, another cloud resilience, and another identity systems. Read only at the level of technology, they belong to different industries, different threat categories, and different conversations.
What connects them is not the subject matter. It is the destination. Each incident ultimately reveals an institutional assumption that had quietly become accepted as fact until reality demonstrated otherwise.
That observation may explain why so many security failures feel surprising despite organisations investing more heavily than ever in technology, monitoring, and detection. Security programmes rarely fail because they ignore known problems. They fail where assumptions have quietly replaced verification. Authentication boundaries are assumed to exist because they always have. Suppliers are assumed to remain available because they have never disappeared before. AI models are assumed to behave consistently because they produced the expected output yesterday. Internal operational platforms are assumed to warrant less scrutiny than production systems because they are perceived as supporting the business rather than running it. Over time, these assumptions cease to be recognised as assumptions at all. They become characteristics of the environment that nobody remembers proving.
Viewed through that lens, many of today’s security challenges begin to look less like collections of unrelated incidents and more like different expressions of the same organisational habit. Technologies evolve, vendors change, regulations mature, and threat actors continuously adapt. Organisational assumptions, however, often persist long after the environments that created them have changed.
Need intelligence like this on a decision you're facing?
DSI Advisory Services helps boards, business leaders, defence institutions, and security leaders understand threats before they reach the horizon — where cyber, geopolitics, and business risk converge.