Security teams have spent two decades optimizing for the wrong question. Traditional penetration tests and red team engagements have historically fixated on the initial breach — can an attacker get in? — while spending comparatively little time on the question that actually determines business impact: what happens next?
RemoteThreat, an offensive cyber operations startup covered this week by Dark Reading, is building its entire thesis around that gap. The company's position is straightforward: modern attackers — ransomware affiliates, nation-state operators, and initial access brokers alike — operate with the assumption that perimeter defenses will eventually fail, because they eventually do. The startup aims to evolve red teaming beyond traditional methods to simulate attackers' increasingly advanced post-compromise capabilities, testing detection and response inside the environment rather than just the wall around it.
From a defender's perspective, this isn't just vendor positioning. It reflects a shift I've watched accelerate across real incident response engagements: the organizations that survive intrusions with minimal damage aren't the ones with impenetrable perimeters — they're the ones that detect lateral movement in minutes, not months. The median dwell time for intrusions has compressed dramatically, but only for organizations with mature internal visibility. Everyone else is still measuring dwell time in weeks.
What "Assume Breach" Actually Means Operationally
The assume-breach model inverts the traditional red team engagement. Instead of starting from a phishing email or an exposed service, the red team begins with a defined level of access already established — a compromised standard user workstation, a low-privileged service account, or a foothold on a single endpoint — and measures how far they get and how quickly the blue team responds.
This matters because the post-compromise phase is where defenders hold the advantage, and most organizations never test it. Consider the typical attack chain we've reconstructed across dozens of ransomware and espionage cases:
- Initial access is increasingly commoditized — purchased from brokers, sprayed via credential stuffing, or landed through exploitation of edge devices.
- Privilege escalation and credential theft — LSASS dumping, Kerberoasting, DCSync — follow predictable, detectable patterns.
- Lateral movement — PsExec-style service creation, WMI, WinRM, RDP — generates abundant telemetry.
- Objective execution — data staging, exfiltration, mass encryption — is the loudest phase of any intrusion.
Every one of those post-compromise stages is an opportunity to catch an attacker before material damage. Yet in our assessments, we routinely find environments where the SIEM ingests firewall and EDR telemetry for the perimeter, while internal authentication logs, east-west network traffic, and identity-plane events (Active Directory, Entra ID, Okta) are either not collected or not alerted on. That is precisely the blind spot RemoteThreat's model is designed to expose.
Why This Shift Is Happening Now
Three forces are converging to make post-compromise simulation a requirement rather than a luxury:
- Identity has become the real perimeter. With SaaS sprawl and hybrid work, most modern intrusions we've responded to in 2025–2026 never touched a traditional network boundary. They walked in through valid credentials, abused OAuth grants, or hijacked sessions. Testing your firewall rules tells you nothing about whether you'd catch an attacker operating with legitimate tokens.
- Attacker speed has compressed the detection window. Ransomware operators now routinely move from initial access to domain-wide encryption in under 48 hours — sometimes under 8. If your detection and response loop operates on a weekly triage cadence, the math simply doesn't work. Assume-breach exercises measure your mean time to detect and respond against realistic attacker tempo, not against a red team slowly working its way in from the outside.
- Breach and attack simulation (BAS) tooling has matured. Continuous, automated validation of detection controls against MITRE ATT&CK techniques is now operationally feasible for mid-sized teams, not just Fortune 100 SOCs. The barrier to testing post-compromise detections continuously — rather than once a year during a pen test — has collapsed.
Executive Takeaways
For security leaders looking to operationalize the assume-breach philosophy this news represents, these are the steps that deliver measurable defensive value:
1. Redefine your red team scopes to start inside. Mandate that at least one engagement per year begins with pre-staged internal access — a compromised user context or a planted foothold host. Measure the engagement on detection time, containment time, and attacker progression halted, not on whether the red team "got domain admin." They will. The question is whether your SOC noticed.
2. Audit your telemetry for the post-compromise phases. Map your log sources against the ATT&CK tactics that matter after initial access: credential access (T1003), lateral movement (T1021), execution (T1059), and command and control (T1071). If Windows Event IDs 4624/4625 (logon), 4672 (special privileges), 4768/4769/4771 (Kerberos), and 7045 (service installation) aren't flowing into your SIEM with tuned detections, your perimeter investment is theater.
3. Run purple team exercises, not just red team engagements. The highest-ROI format we run pairs the red team with detection engineers in real time: execute a technique, check if it fired, tune if it didn't, repeat. A two-week purple team sprint routinely produces more durable detection coverage than a six-week covert red team engagement, because the output is working detections rather than a report.
4. Test your identity plane explicitly. Every assume-breach exercise in 2026 should include scenarios for token theft, MFA fatigue, OAuth consent abuse, and hybrid identity attacks (on-prem AD to Entra ID pivoting and vice versa). This is where real attackers live now, and it's where most detection stacks are thinnest.
5. Adopt continuous validation, not annual testing. Annual pen tests satisfy compliance frameworks (PCI-DSS 11.4, various NIST CSF assessment requirements), but they don't reflect attacker tempo. Supplement them with automated BAS or scheduled atomic tests (Atomic Red Team, MITRE CALDERA) that re-verify your detections still fire after every major detection-engineering or platform change.
6. Measure what the board should care about. Translate assume-breach results into mean time to detect (MTTD), mean time to contain (MTTC), and percentage of ATT&CK techniques covered by at least one tested detection. These metrics justify budget far more effectively than vulnerability counts, and they directly answer the question RemoteThreat is asking: when defenses fail — and they will — how bad does it get?
Operationalizing This in Your Program
The practical starting point is narrower than most teams expect. Pick five ATT&CK techniques that appear in nearly every intrusion we respond to — LSASS credential dumping (T1003.001), Kerberoasting (T1558.003), PsExec-style remote service execution (T1569.002), scheduled task persistence (T1053.005), and data exfiltration over common web services (T1567.002). Run them in a controlled manner against a test segment. If your stack catches all five with high-fidelity alerts, expand the matrix. If it misses any of them, you have your detection engineering backlog — and you have it before an attacker found the gap for you.
That, ultimately, is the defensive lesson in RemoteThreat's bet: the perimeter will fail, the phish will land, the edge device will get popped. The organizations that come out intact are the ones that treated the post-compromise phase as their real battlefield — and tested it like they meant it.
Related Resources
Security Arsenal Red Team Services AlertMonitor Platform Book a SOC Assessment pen-testing Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.