Most people picture a cyberattack as a single dramatic moment: a hacker somewhere hits enter, and instantly a business is destroyed. The reality is stranger and, honestly, more useful to understand. A real attack is not a moment. It is a process, one that unfolds in stages over time, often quietly, with several distinct steps between the first foothold and the final damage. And here is the encouraging part hidden in that: because an attack has stages, it has multiple points where it can be stopped. You do not have to be perfect at every single one. You just have to break the chain somewhere.
So let me walk you through how an attack actually happens, step by step, using a common scenario. Follow it from the first click to the final payout, and you will understand cyber risk better than most business owners ever do. More importantly, at each stage, I will show you exactly where the right protection breaks the chain and ends the attack. By the end, the whole thing will feel less like a mysterious catastrophe and more like a series of doors you can lock.
Stage 1: The way in
Almost every attack begins not with some technical wizardry, but with a way in, and the most common way in is a person. Let me set the scene. An employee at a busy small business, let us call her the bookkeeper, receives an email. It looks like it is from a vendor the company works with, or maybe from a delivery service, or the bank. It is well written, it looks legitimate, and it asks her to click a link to view an invoice, confirm a detail, or log into an account. This is phishing, and it is the front door for a huge share of all attacks.
She clicks. The link takes her to a page that looks exactly like a real login screen, and she enters her username and password, believing she is signing into a legitimate service. In that instant, she has handed her credentials to a criminal. No alarms sound. Nothing appears to go wrong. She may not even remember the moment later. But the attacker now has a working login.
Where this chain breaks: This first stage has several locks. Email security that filters out the phishing message means it never reaches her inbox to be clicked. A trained, aware team means she recognizes the warning signs and does not click, or does not enter her password on a suspicious page. And crucially, even if she does enter her password, multi-factor authentication means that stolen password alone is not enough to get in, the attacker is stopped at the door because they do not have the code on her phone. Any one of these three, on its own, can end the attack right here, at the very beginning, before it becomes anything at all.
Stage 2: The quiet foothold
Suppose those locks were not in place, and the attacker now has a working login. Here is what surprises people: they usually do not do anything dramatic yet. A smart attacker goes quiet. They log in and simply look around. They read email. They learn how the business works, who pays whom, which vendors are real, when big payments happen, how people talk to each other. They may set up a hidden email forwarding rule so they can keep reading even if the password changes later. They are patient, because patience makes the eventual attack far more convincing.
This lurking phase can last days or weeks, and it is precisely why so many breaches are discovered long after they began. Everything on the surface looks normal. The business runs as usual. Underneath, someone is watching and learning.
Where this chain breaks: This stage is all about detection. Monitoring that watches for unusual activity, a login from a strange location, a new forwarding rule, access at odd hours, can catch the intruder during this quiet period, when they are inside but have not yet done damage. This is the window where an alert turns a potential catastrophe into a contained incident. A business that is watching finds them here. A business that is not gives them all the time they need. It is also why simply knowing the warning signs, and checking your email rules and login activity, matters so much.
Stage 3: Expanding the reach
Having learned the lay of the land, the attacker works to expand. One compromised account is useful, but more access is better. They may use what they have learned to reach other accounts, try the stolen password on other systems (which works if passwords were reused), or use the trusted position of the hijacked account to trick other employees into giving up more access. The goal is to get closer to what they are really after: the money, the valuable data, or control of critical systems.
This is where the damage a single foothold can do multiplies. An attacker who gets into one email account and from there reaches the systems that move money or hold customer data has turned a small opening into a serious breach.
Where this chain breaks: Two protections matter most here. Limited access, the principle that each account can only reach what it genuinely needs, means a single compromised account is contained rather than a master key to everything. And unique passwords, ideally through a password manager, mean the stolen password does not work anywhere else, so the attacker cannot simply reuse it to spread. Together, these keep one foothold from becoming total access. The attacker hits walls instead of open doors.
Stage 4: The payoff
Finally, the attacker acts on their goal, and this is the part businesses actually notice. Depending on what they were after, the payoff takes different forms. It might be financial fraud: using everything they learned to send a perfectly timed fake invoice or a fraudulent wire request that looks completely legitimate, redirecting a real payment to themselves. It might be ransomware: locking up the company's files and systems and demanding payment. It might be data theft: stealing customer or financial records to sell or exploit. Whatever the form, this is the moment the quiet process becomes a loud crisis.
By now the attacker has often been inside for a while, which is exactly why the final blow is so effective. The fake invoice references a real deal. The ransomware hits the systems that matter most. The theft targets the valuable data. Preparation made the payoff precise.
Where this chain breaks: Even here, at the last stage, there are locks. The verify-by-phone habit, confirming any payment or banking change through a known number, defeats the fraudulent invoice or wire even if everything else failed. Tested backups mean ransomware loses most of its power, because you can restore rather than pay. And an incident response plan means that when the crisis hits, you contain and recover in a controlled way instead of a panic. Protection does not stop at prevention. It reaches all the way to the final moment.
The real lesson: you only have to break the chain once
Step back and look at the whole story, and the most important insight appears. An attack is a chain of stages, and it only succeeds if it makes it through all of them. That means you do not need perfect security at every single point. You need to break the chain somewhere, and there are locks at every stage.
Notice how many chances there were to stop this one attack. Email security could have blocked the phishing message. Awareness could have stopped the click. Multi-factor authentication could have made the stolen password useless. Monitoring could have caught the quiet intruder. Limited access and unique passwords could have contained the spread. The verify-by-phone rule, tested backups, and a response plan could have blunted the payoff. That is eight distinct places a single attack could have been stopped, and the business only needed one of them to hold.
This is why the layered approach to security works, and why no single protection has to be perfect. Each layer catches what the others might miss. An attacker has to get through every layer. You only have to stop them at one. That is a far more winnable fight than the "one mistake and it is over" story most people believe, and it is the reason the fundamentals matter so much: each one is another link where the chain can break.
How we think about it
Understanding an attack as a breakable chain is the entire philosophy behind how we protect businesses at Red Door Shield, through a simple framework we call KIT: Keep, Inspect, Trust. Keep what is valuable secure, the strong logins, multi-factor authentication, limited access, and tested backups that lock stages one, three, and four. Inspect what is coming in, the email security and around-the-clock monitoring that catch stages one and two, including the quiet lurking phase where an attack is most catchable and most invisible to a business not watching. And trust through validation, the verify-before-you-act habit that breaks the chain even at the final payoff. We layer these deliberately, because an attacker needs every stage to work, and we only need one solid link to stop them cold.
What ready looks like
Picture that same attack arriving at your business. The phishing email is filtered, or your aware team does not click, or the stolen password is stopped by multi-factor authentication. If somehow an attacker got a foothold, monitoring spots the unusual activity and you are alerted while they are still just looking around. Limited access keeps them boxed in, unique passwords keep them from spreading, and even at the end, the verify-by-phone rule and your tested backups leave them with nothing. The attack that would have devastated an unprepared business runs into wall after wall and simply fails.
That is what ready feels like. Not the impossible standard of never facing an attack, but the achievable confidence of knowing that when one comes, the chain breaks long before it reaches you.
An attack is a process, not a moment, and that is genuinely good news, because a process can be interrupted at many points. You do not have to be perfect. You have to have enough layers that the chain breaks somewhere, every time. If you want to know which links in that chain are strong in your business and which need shoring up, that is exactly what a Business Security Assessment is for, and it is a conversation worth having today.
Learn about multi-factor authentication, read about incident response, or see our guide on using password managers.
Know Where Your Business Stands
Our free Business Security Assessment gives you a clear picture of your current security posture in less than 10 minutes. No technical knowledge required.
Not sure where your business actually stands?
Take our free Business Security Assessment. In under 10 minutes, you will know exactly where your gaps are and what it would take to close them.
Get My Free Security Assessment

