Back to glossary

Assumed breach

1 min read

Assumed breach is a scoping decision in which an engagement starts from a position an attacker would have to earn: a standard user account, a workstation, or a foothold in a network segment. It is a way of spending the budget on what happens after entry rather than on proving that entry is possible.

July 29, 2026
Compartir:

The argument for it is arithmetic. Initial access is a matter of time and volume, and a determined adversary has both, while an engagement has a fixed number of days. Spending most of them on the perimeter frequently produces a report that says the perimeter held, which tells the client nothing about the state of the directory, the segmentation or the detection behind it.

It is not a concession that the perimeter is weak, and it does not replace an external assessment. It is an explicit statement in the rules of engagement about which question is being paid for. The starting position has to be written down precisely, because a domain user on a managed laptop and local administrator on an unmanaged one produce entirely different results, and a report that does not name the starting position cannot be compared with the next one.

In practice this is the discussion that most often stalls the kick off meeting for an internal project, and settling it early is worth a day of testing. What we recommend recording alongside the outcome is what the position cost the attacker to reach, so the report reflects both halves: this is what an intrusion looks like once someone is inside, and this is how much work that entry would have been. From there the engagement is about lateral movement and privilege, which is the substance of the internal testing where the starting position is agreed before the clock starts.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.