In this article

The Gap In Today's Models, Frameworks and Regulatory Compliance

Most security tools only show parts of the attacker journey, which leaves gaps in how exposure is understood and acted on. KELA connects identity risk, threat actor intelligence, and external exposure into one unified view to help security teams see activity earlier and respond with more context.

a black and red logo with the word ikela
By KELA Cyber Intelligence Center
a man in a suit and tie looking at the camera
Fact-check by Lewis Henderson, Director, Intelligence Communications

Published September 2, 2026

Ransomware 5.0: A 2026 CISO Guide to AI-Driven Attacks

Cyber attacks rarely happen in a single moment. Most intrusions follow a sequence of actions that starts with reconnaissance and ends with data theft, operational disruption, ransomware deployment, or long-term persistence inside an environment. As attack methods become more advanced, organizations are under increasing pressure to improve visibility across every stage of the intrusion process while also meeting stricter regulatory and operational requirements.

This is where attacker models, security frameworks, and compliance standards play a major role. Models such as the Cyber Kill Chain, MITRE ATT&CK, CTEM, and the Diamond Model help security professionals understand how attackers operate, move across systems, and achieve their objectives. In this blog, we’ll look at how modern attacker lifecycle models map across cyber intrusions, where major compliance frameworks place their operational focus, and how security controls change across the pre-breach, during-breach, and post-breach stages of an attack.

» Start with KELA and stay ahead in identifying advanced threat actors and operations

Standard Attacker Lifecycle Models and How They Map Across an Intrusion

Industry attacker-lifecycle models divide cyber intrusions into structured stages so organizations can understand how attacks develop and where defensive controls should be applied. While different models use different terminology, most follow a similar progression from preparation and exploitation through to persistence and operational impact. The main stages found across standard attacker models are:

  • Reconnaissance: Attackers begin by collecting information about the target environment before attempting exploitation. This can include identifying exposed infrastructure, employee information, suppliers, cloud services, or vulnerable applications. Reconnaissance often involves phishing research, vulnerability scanning, and social engineering preparation designed to improve the likelihood of successful access.
  • Weaponization: During weaponization, attackers prepare the tools and delivery methods needed for the intrusion. This may involve creating malware payloads, phishing attachments, malicious links, exploit kits, or credential theft infrastructure. In many cases, attackers customize these payloads specifically for the target organization.
  • Delivery and initial access: This stage focuses on gaining entry into the environment. Common techniques include phishing emails, stolen credentials, exploitation of internet-facing applications, abused remote access services, and malicious downloads. In frameworks such as MITRE ATT&CK, this stage aligns closely with Initial Access tactics.
  • Exploitation and persistence: Once access is gained, attackers attempt to establish a stable foothold within the environment. Persistence mechanisms may include backdoors, scheduled tasks, malicious services, account creation, or remote administration tools. Attackers also begin escalating privileges to gain broader access across systems and accounts.
  • Lateral movement and internal expansion: Attackers rarely remain on a single compromised device. After establishing persistence, they move across systems, servers, identities, and cloud environments to locate sensitive data and critical infrastructure. This phase often includes credential dumping, privilege escalation, remote execution, and segmentation bypass attempts.
  • Command-and-control activity: At this stage, compromised systems communicate with attacker-controlled infrastructure to receive instructions, transfer data, or maintain remote access. Command-and-control channels may use encrypted traffic, cloud services, or legitimate administrative tools to avoid detection.
  • Actions on objectives: The final stage involves carrying out the attacker’s primary objective. Depending on the intrusion, this may include ransomware deployment, operational disruption, financial fraud, espionage, or data exfiltration. In many modern attacks, the operational impact only becomes visible once attackers have already maintained access for an extended period.

» Did you know? Ransomware groups are selling network access directly

Cyber Threat Intelligence

Gain unified visibility across the full attacker lifecycle to identify exposure earlier and disrupt attacks before they reach execution.

Contact Us

Where Compliance Frameworks Focus

Modern compliance frameworks prioritize different areas of cybersecurity operations, governance, and recovery. They generally map across the attack lifecycle in three distinct phases:

Phase

Operational Focus

Key Frameworks

Pre-Breach

Reducing exposure, vulnerability management, access control, and attack surface visibility.

ISO 27001 (ISMS governance), PCI DSS (Cardholder data environment controls)

During-Breach

Detection, investigation, containment, and isolating compromised systems.

NIST CSF (Detect/Respond functions), DORA (Incident reporting)

Post-Breach

Eradication, recovery, forensics, regulatory reporting, and operational restoration.

ISO 22301 (Business Continuity), NIS2 (Essential sector resilience)

» Looking for a EU DORA or NIS2 aligned solution? KELA provides the comprehensive support you need

Gaps and Required Solutions Across the Attack Lifecycle

The main issue across modern security frameworks is that attacker models, compliance standards, and operational security programs are not fully aligned. Most frameworks describe how attacks happen or how organizations should respond, but they do not turn the pre-breach phase into a continuous, operational workflow.

As a result, exposure before exploitation is fragmented across multiple security functions with no single execution layer.

Why Current Attacker-Lifecycle Models Fail to Treat Pre-Breach as an Operational Workflow

Current attacker-lifecycle models are built around attacker behavior after compromise rather than defender execution before compromise. This creates a structural gap where pre-breach activity is understood but not operationalized.

In practice, pre-breach work is split across disconnected functions:

  • Governance defines security requirements but does not monitor live exposure.
  • Vulnerability management identifies weaknesses but does not reflect attacker targeting or chaining.
  • SOC operations typically begin only after detection, meaning early reconnaissance and preparation are not operationally visible.
  • Threat intelligence describes external activity but is not fully embedded into remediation workflows.

Even widely used models like MITRE ATT&CK are primarily focused on post-compromise behavior, which reinforces a reactive security structure rather than a continuous prevention workflow.

» Here are the reasons you need cyber threat intelligence

What Exists Today to Address the Pre-Breach Gap

Some frameworks extend visibility earlier in the lifecycle, but they are not unified into operational defense.

While these approaches improve visibility, they are still not consistently integrated into SOC operations or day-to-day security execution.

» Here's everything you need to know about leveraging the MITRE framework

Why Compliance Frameworks Fail to Provide Early-Stage Visibility

Compliance frameworks such as ISO/IEC 27001 and NIST CSF focus on governance, control existence, and auditability rather than continuous attacker visibility.

This creates key limitations:

  • Controls are validated periodically rather than continuously.
  • Early attacker activity such as scanning or reconnaissance is not explicitly addressed.
  • Compliance confirms that controls exist, not whether they are effective in real conditions.
  • Organizations can remain compliant while still being exposed to active attack paths.

As a result, compliance provides structure, but not operational visibility into pre-breach risk.

How Organizations Close Pre-Breach and Regulatory Blind Spots

Closing these gaps requires moving from static compliance to continuous exposure-driven operations. Key operational shifts include:

  • CTEM to connect assets, vulnerabilities, and attack paths into a single workflow.
  • Continuous validation of exposure instead of periodic assessments.
  • Prioritizing remediation based on attacker pathways rather than isolated vulnerabilities.
  • Reducing external exposure by removing unnecessary services and access paths.
  • Strengthening identity security through phishing-resistant authentication and least privilege.
  • Applying segmentation to limit lateral movement after initial access.

This shifts security from compliance-driven activity to continuous prevention of exploitation conditions.

» Learn how to prevent phishing attacks before they catch you

The Regulatory Gap Between Compliance and Prevention

Most regulatory frameworks focus on resilience after compromise rather than preventing compromise itself. This creates a gap between compliance expectations and actual attack exposure. Key issues include:

  • Security controls exist but are not continuously validated.
  • Configuration drift creates hidden exposure not captured in audits.
  • Compliance measures control presence, not attack-path resistance.
  • Organizations can be compliant while still exposed to exploitation. This creates a regulatory framework, that works for both the compliance and Gap between compliance and prevention.

Compliance therefore does not always reflect real-world security posture.

Required Paradigm Shifts Toward Pre-Execution Prevention

The solution to the pre-breach gap is a shift in how security frameworks are operationalized. Instead of focusing on reacting to attacks after detection, organizations need to move toward continuous prevention of exploit conditions before execution occurs. This requires rethinking security as an ongoing exposure management process rather than a set of periodic controls.

  • Move from detect-and-respond models to continuous exposure prevention, where risk is continuously identified and reduced before attackers can execute.
  • Replace periodic audits with continuous validation of controls to ensure security effectiveness is measured in real operating conditions, not point-in-time compliance checks.
  • Shift from perimeter-based security to identity- and data-centric enforcement using Zero Trust principles, reducing reliance on network boundaries as the primary defense layer.
  • Focus on disrupting attacker pathways rather than only detecting malicious activity, prioritizing the removal of routes that enable privilege escalation and lateral movement.
  • Treat exposure as a continuously managed operational risk, with ongoing measurement, prioritization, and remediation embedded into daily security operations.
These changes align security operations with how attacks actually progress, shifting the defense model from post-compromise response to pre-execution prevention.

» Read more about protecting your organization from future cybercrime

Beyond Compliance

KELA Cyber helps to close the gap between compliance and real-world exposure with continuous attack visibility beyond audits

Start for FREE
Learn More

From Static Compliance to Continuous Prevention

Cyber attacks don’t follow neat stages in practice. They move from preparation to access, then lateral movement and monetization, often without clear visibility until damage is already done. Most lifecycle models and compliance frameworks still focus on isolated parts of this process, which leaves gaps in pre-breach visibility and slows down response.

KELA Cyber addresses this by bringing the full attacker process into one view. It connects identity risk through compromised credentials, maps threat actors and APT behavior using MITRE ATT&CK, and extends visibility into third-party exposure through its risk modules. With intelligence drawn from large-scale criminal data sources, it helps identify attacker preparation earlier, not just activity after compromise.

» Contact us to improve visibility across the attacker process before compromise happens

FAQs

Why isn't being "compliant" enough to stop a cyber attack?

Compliance frameworks like ISO 27001 or NIST CSF ensure that security controls exist and are documented, but they often lack real-time validation.

An organization can pass an audit while still possessing "hidden" exposure, such as unpatched vulnerabilities or configuration drift, that attackers can exploit between audit cycles.

How does the "During-Breach" phase differ from "Post-Breach" operations?

The During-Breach phase is about active containment—stopping the attacker’s lateral movement and preventing them from reaching their objectives.

The Post-Breach phase begins once the threat is neutralized; its focus shifts to root cause analysis, legal/regulatory reporting, and restoring systems from backups.

How do regulations like DORA and NIS2 change incident reporting?

These modern regulations shift the focus toward operational resilience. They mandate much stricter, time-sensitive incident reporting (often within 24–72 hours) and require organizations to prove they have oversight of third-party ICT risks, moving security from a "siloed IT issue" to a board-level governance requirement.

What is the pre-breach gap in cybersecurity?

It's the stretch of attacker activity (reconnaissance, weaponization, target preparation) that happens before any breach is detected. Most attacker models and compliance frameworks describe this phase but don't turn it into a live, operational workflow, so exposure is understood in theory but not actively monitored or reduced.

Why isn't compliance enough to prevent a breach?

Compliance confirms that controls exist and are documented, usually checked at a point in time. It doesn't confirm those controls hold up against a real attack path. Configuration drift and unaddressed exposure mean an organization can stay fully compliant while still being exploitable.

Does MITRE ATT&CK cover the pre-breach phase?

Mostly it doesn't. Core ATT&CK is built around post-compromise behaviour. MITRE PRE-ATT&CK maps earlier adversary preparation like targeting and resource development, but it isn't consistently integrated into day-to-day SOC operations, so pre-breach activity stays under-operationalized.

How does CTEM help close the pre-breach gap?

Continuous Threat Exposure Management connects assets, vulnerabilities and attack paths into one workflow, then validates exposure continuously instead of in periodic audits. It prioritizes remediation by attacker pathway rather than isolated CVEs, which moves security from confirming controls exist to reducing the conditions an attacker needs.

What's the difference between detect-and-respond and continuous exposure prevention?

Detect-and-respond waits for malicious activity, then reacts. Continuous exposure prevention identifies and removes exploitable conditions (open paths, weak identity controls, unnecessary external services) before an attacker can use them, shifting effort earlier in the lifecycle.



Related Articles

How Banks Use Threat Intelligence

How Banks Use Threat Intelligence

KELA Cyber Intelligence Center

August 29, 2025