Secure development lifecycle (SSDLC): what it is and how to put it in place
What the secure development lifecycle is, what happens in each phase, what SAST, DAST and SCA add, and where to start if you have nothing in place today.
The Cyber Kill Chain does not describe an attack: it describes a chain, and a chain breaks at any one of its links. That is its whole value as a model of defence, and it is why it is still standing so long after it was published. Here are its seven phases, what actually happens in each one, how they map onto MITRE ATT&CK, and the point at which it is cheapest to break it.
The Cyber Kill Chain is a model Lockheed Martin published to describe a targeted attack as a sequence of seven linked steps. The name comes from military vocabulary: a kill chain is the chain of steps that has to be completed in order to reach an objective.
The description is not the important part. The consequence is: if the attacker has to complete all seven steps and the defender only has to break one, the structural advantage belongs to the defender. That is the entire argument of the model, and it is why it is still used to organise a defence even though the way attacks are carried out has changed a great deal since.
It is worth saying from the start where it falls short, because the model often gets used as though it were a complete map and it is not. The chain is linear, and a real attack goes back and forth. It was designed for intrusions from outside, so it handles badly the attacker who is already inside, the employee who does something they should not, and the compromised supplier who comes in through the front door. And it compresses into a single box, "actions on objectives", the longer half of any real intrusion.
There are seven and not six. It is the most repeated mistake when the model is summarised: weaponisation and delivery get folded into one box because they sound similar, and they are two different moments with two different defences.
One nuance that changes how the chain reads: today it is common for whoever walks phases 1 to 4 not to be whoever walks phase 7. There are initial access brokers who specialise in getting in and selling the way in. So the same chain can have two owners, and the phase that gets bought is precisely the one almost every company detects worst.
MITRE ATT&CK is what most people use today for the same purpose, and the reasonable question is whether it replaces the chain. It does not: they answer different questions. The chain tells a story in order. ATT&CK is a catalogue of tactics and techniques observed in real attacks, with no obligation of order.
The approximate correspondence, for anybody who has to translate from one vocabulary to the other:
And that is where the comparison earns its keep: six ATT&CK tactics fit inside the last box of the chain. The chain spends six of its seven phases on how the attacker gets in and one on everything they do afterwards, which is where most of the time is spent and where the damage is actually decided. If you organise detection with the chain in your hand, you will build six controls at the perimeter and one for everything else. That is its blind spot, and it is why it is worth using both: the chain to explain, ATT&CK to cover.
Every phase works for breaking the chain, but they do not cost the same and they are not worth the same.
The earlier, the cheaper and the less reliable. Stopping it at delivery (mail filtering, macro blocking, browser isolation) is the cheapest thing there is and it stops an enormous amount of noise. But anybody who puts an afternoon into it gets past, because only one has to get through.
The later, the more expensive and the more decisive. Detecting at installation and at command and control is where you cut off the one who already got in, which is the one who is going to do you harm. It costs more because it demands seeing what happens inside the machines and in outbound traffic, and it demands that somebody looks.
Out of that comes a sensible way to check your chain instead of assuming it:
The difference between those two questions is the one most often confused at the point of buying. "Can they get in?" almost always has the same answer. "How long do we take to see it?" is the one that varies from one company to another.
This example is five years old and we say so up here on purpose, because a case with no date reads as though it were yesterday. It is still the best one for explaining the chain, for a specific reason: it is an attack whose damage did not happen in the last phase, but in the reaction to the last phase.
Between 6 and 7 May 2021, Colonial Pipeline, which carries about 45 % of the fuel consumed on the east coast of the United States, suffered a ransomware attack attributed to the DarkSide group. The attackers stole nearly 100 GB of data and threatened to publish it, which is the double extortion pattern that became general around then: first they take the information and then they encrypt, so that having backups stops being enough.
What we are not going to cover, and why. A great deal of detail circulates about how they got in and about how much was paid. It is not in this article. A piece about attack chains is not the place to fill in the first link with what everybody takes as read, and the particulars of one incident are not what makes the model useful. The source is linked above for anybody who wants them.
What can be read in terms of the chain, and this is the lesson: the encryption was phase 7, but to get there there was reconnaissance, a way in, installation, command and control, and an exfiltration of 100 GB that had to leave through something over a fair stretch of time. A hundred gigabytes do not go in a heartbeat or through an invisible channel. Every one of those moments was a chance to break the chain before the damage, and not one was taken. And the shutdown of the pipeline network, which is what made the news, was a decision by the company in the face of uncertainty, not a direct effect of the malware. When you do not know how far the attacker got, you switch off. Knowing how far they got is, nearly always, the difference between an incident and a crisis.
If you take one thing away, let it be this: the question is not whether your company can be attacked, but at which link the chain would break if you were attacked tomorrow. And that question has a testable answer.
A reasonable order for answering it, from least to most effort. First, look at what you expose: what is published in your name that you did not know was there, and which of your credentials are circulating in other people’s breaches. Second, prove that getting in is not trivial, from outside and without credentials. Third, and this is the one almost nobody does, test what happens after the way in: how far somebody who is already inside moves, and how long you take to see it.
The first two steps give you a list of things to fix. The third gives you something different and more uncomfortable: a measurement of your detection time. That is the number that really separates the companies that come out of an incident from the ones that end up in the news.
First published on 29 November 2023. Last reviewed on 3 August 2026.
If any of this looks like a problem you are carrying, half an hour on a call scoping it with a senior pentester is worth more than reading another article.
Talk to a senior pentesterPick a time that suits you. You tell us what you need and where you are, and we explain how we work and how we can help.