Every breach has two beginnings. Only one is still winnable.
The date on the incident report — and the date weeks earlier when the behavior started. From Ashley Rose's keynote Start With the Why: a field guide to the 10 person-patterns behind preventable breaches, plus a 60-minute session to name yours. Nothing in either piece requires a purchase.
10 person-patterns — ransomware, help-desk resets, BEC, shadow AI — each with the signals that show up weeks early.
A 60-minute agenda your team can run this week — five steps, printable worksheets, no vendor talk.
A signal inventory that answers one honest question: can you name your 10% today, from data you already own?
Get both pieces of the kit
One form, both PDFs — the field guide and the working session.
Both PDFs, no gate after this one.
Attacker hand-off after initial access — down from 8+ hours in 2022. Mandiant M-Trends 2026
of risky behavior comes from roughly 10% of the workforce — across 100+ enterprises. Living Security × Cyentia, 2025
Median phishing-simulation click rate — a floor years of blanket training haven't moved. Verizon DBIR
Two pieces. One is a diagnosis, one is a decision.
Read the field guide to find the pattern that makes your room uncomfortable. Then run the session against that one — with your SOC in the chair.
The Top 10 Avoidable Incidents
A field guide to the person-patterns behind the breaches you can still prevent — and the early signals already sitting in your logs.
The Named-Breach Working Session
A 60-minute working session to answer one question — what breach do we refuse to accept? — and leave with a named target, an identified cohort, and a number that proves it isn't forming.
The problem you thought was everyone is actually someone.
Each pattern is a small, findable group behaving their way toward a specific breach — visibly, over weeks, in signals your identity, email, endpoint, SaaS, and HR systems already capture.
The Backup Keyholders
Becomes: Ransomware-driven intrusionThe Gatekeepers
Becomes: Help-desk social engineering & account takeoverThe Patch Deferrers
Becomes: Exploitation of a known, unpatched vulnerabilityThe Shadow Adopters
Becomes: Data leaking through unmanaged AI & appsThe Authorized Approvers
Becomes: Business email compromise & payment fraudThe Recyclers
Becomes: Credential stuffing that feeds ransomwareThe Power Connectors
Becomes: Over-scoped third-party & OAuth compromiseThe Expedient Fixers
Becomes: Exposure through workarounds & shortcutsThe Quiet Exit
Becomes: Insider data mishandling before departureThe Standing Privileged
Becomes: Privilege abuse & blast-radius amplificationYour workforce isn't the weakest link. It's the largest sensor network you never turned on.
A named breach beats a category.
A doctor who says "we treat illness" gets a shrug. One who says "you are trending toward a cardiac event, and here's the marker" gets action. This session gets your named breach on paper — and tests, honestly, whether you could see it forming in your own data today.
1 · Name it
One sentence: the breach you refuse to accept.
2 · Ask the SOC
The three behaviors that would empty the queue.
3 · Find the few
A signal inventory — and an honest yes/no: can we see our 10%?
4 · Act
The levers chosen for that cohort, with owners.
5 · Prove it
The metric, its baseline, and a 90-day check-in on the calendar.
Let the incident choose the lever.
Engage the workforce
Targeted training — for the cohort, on the behavior. Not one-size-fits-all.
Testing — simulate the actual lure: the vishing call, the exec impersonation.
Nudging — correction and reinforcement at the moment of behavior.
Reporting — scorecards that put risk in front of the people who own it.
Protect the environment
Access restriction — step-down, just-in-time elevation, revoke the dormant.
Orchestrated controls — step-up verification, rotation, isolation.
Governance — spanning both paths, for humans and the agents acting on their credentials.
Celebrate the 90% who don't need intervention. That's not softer security — it's sharper.
Don't start with the tool. Start with the breach you refuse to accept.
Run the session with your SOC. If you can't name your 10% from your own data — you just found the gap, and we should talk.

