What 20 Years in Offensive Security Taught Me About How Companies Get Breached
I've conducted hundreds of penetration tests over the past two decades. I've sat across from CISOs, IT directors, and executive teams, sometimes hours after a breach, sometimes years before one, and the same patterns keep appearing. The tools change. The industries change. The company sizes change. But the underlying reasons organizations get compromised? They're remarkably consistent.
This isn't a technical post. It's an honest account of what I've observed across two decades in offensive security, from training red teams across the GCC to running sessions at Black Hat. If you work in cybersecurity training in Dubai, Riyadh, Doha or anywhere across the region, these patterns matter because they define what we should actually be preparing people for.
The Firewall Is Not the Fortress You Think It Is
The single most dangerous assumption in corporate security is that a strong perimeter means a strong defense.
I've walked into organizations with enterprise-grade firewalls, next-generation antivirus, and six-figure security budgets, and found significant vulnerabilities within hours. Not because the tools failed. Because tools are only as effective as the people configuring and monitoring them.
Perimeter defense was designed for a time when data lived inside a building. That model is largely obsolete. Hybrid work, cloud infrastructure, third-party integrations, and SaaS platforms have dissolved the boundaries organizations are still trying to protect. The perimeter doesn't end at the office anymore, it ends at every employee device, every vendor login, and every API connection in the stack.
When I train teams, the first mental shift I push is this: stop thinking about walls and start thinking about access points.
The Front Door Is Almost Always a Credential
Ask most executives how attackers get in and they'll describe something dramatic, a zero-day exploit, a sophisticated piece of malware, a nation-state actor. The reality is far less cinematic.
According to Verizon's 2025 Data Breach Investigations Report, which analyzed over 22,000 security incidents and 12,195 confirmed breaches, credential abuse and exploitation of vulnerabilities remain the leading initial attack vectors. Credential abuse was the initial access vector in 22% of breaches, and 88% of basic web application attacks involved stolen credentials.
Attackers are not breaking down the door. They are walking in with a key that someone left lying around, a reused password, a phished login, credentials harvested by infostealer malware from an employee's personal device. The 2025 DBIR found that 46% of unmanaged devices in infostealer logs contained company credentials. Personal laptops. Personal phones. Devices nobody in IT even knows are accessing corporate systems.
The organizations I've seen recover fastest from incidents are those that treat identity as their primary security perimeter, not their last line of defense.
The Human Element Is Not a Training Problem. It's a Culture Problem.
Every security team knows the statistic. According to the Verizon DBIR 2025, the human element directly contributed to 60% of all breaches, making it the single largest driver of successful attacks.
Most organizations respond to this by running an annual phishing simulation and ticking a compliance box. That is not a solution.
The human element is persistent because it is structural. Employees are busy, under-resourced, and often operating without a clear understanding of what a real threat looks like in their specific environment. A generic awareness module watched once a year does not change that. It does not build instinct. It does not prepare someone for the moment a convincing email arrives at 4pm on a Friday.
What actually changes behavior is repeated, contextual exposure, simulations that reflect real scenarios, debriefs that explain why something was dangerous, and leadership that treats security as a shared responsibility rather than an IT department problem.
Third Parties Are the New Blind Spot
This is the pattern I've watched grow most sharply over the past several years. Third-party involvement in breaches skyrocketed in the past few years.
Your vendors, contractors, and technology partners have access to your systems. In many cases, that access is broader than it needs to be, poorly monitored, and governed by a security assessment that was done once at the point of onboarding, and never revisited.
Attackers know this. Targeting a large organization directly means navigating mature security controls. Targeting a smaller vendor with access to that organisation is often far easier. The entry point is not your system, it is someone else's system that connects to yours.
I've seen this play out repeatedly in the GCC, where rapid digital transformation and large-scale infrastructure projects have created complex vendor ecosystems that outpaced the security frameworks meant to govern them.
What This Means for Organizations in the GCC
The UAE is the most targeted nation in the region, accounting for 40% of all dark web posts related to the Gulf, while Saudi Arabia follows with 26% of threat actor interest. IBM's 2024 Cost of a Data Breach Report identified security skills shortage as one of the top three factors amplifying breach costs for businesses in the Middle East.
The region is investing significantly in digital infrastructure. The security investment, and more importantly, the security culture, is not keeping pace.
The organizations that consistently manage to avoid or contain breaches share a common posture: they assume compromise is possible, they invest in detection and response rather than only prevention, and they treat security awareness as an ongoing program rather than an annual obligation. They also work with practitioners who understand how real attackers think, not just how to pass a compliance audit.
The Pattern Is Predictable. That Is the Opportunity.
After 20 years of this work, the most important thing I can tell you is that the vast majority of breaches are not sophisticated. They exploit the same weaknesses, the same assumptions, the same gaps in human behavior that have existed for decades.
That predictability is not discouraging. It is an opportunity. If the attack patterns are consistent, so is the preparation. The organizations and individuals willing to understand how attackers actually operate, not how we assume they do, are the ones that stand a real chance.
That is exactly what this work is about.
By: Tarek - Lead Trainer