The Command Kit · Two pieces, free

Every breach has two beginnings. Only one is still winnable.

The date on the incident report — and the date weeks earlier when the behavior started. From Ashley Rose's keynote Start With the Why: a field guide to the 10 person-patterns behind preventable breaches, plus a 60-minute session to name yours. Nothing in either piece requires a purchase.

10 person-patterns — ransomware, help-desk resets, BEC, shadow AI — each with the signals that show up weeks early.

A 60-minute agenda your team can run this week — five steps, printable worksheets, no vendor talk.

A signal inventory that answers one honest question: can you name your 10% today, from data you already own?

Instant access

Get both pieces of the kit

One form, both PDFs — the field guide and the working session.

Both PDFs, no gate after this one.

22s

Attacker hand-off after initial access — down from 8+ hours in 2022. Mandiant M-Trends 2026

73%

of risky behavior comes from roughly 10% of the workforce — across 100+ enterprises. Living Security × Cyentia, 2025

~1.5%

Median phishing-simulation click rate — a floor years of blanket training haven't moved. Verizon DBIR

What's inside

Two pieces. One is a diagnosis, one is a decision.

Read the field guide to find the pattern that makes your room uncomfortable. Then run the session against that one — with your SOC in the chair.

No. 1 of 2 · 9 pages

The Top 10 Avoidable Incidents

A field guide to the person-patterns behind the breaches you can still prevent — and the early signals already sitting in your logs.

10 named patterns, each with what it becomes The second-clock signals for each, by system Two plays per pattern: engage, or protect Sourced evidence — DBIR, M-Trends, IC3, SpyCloud
No. 2 of 2 · 60 minutes

The Named-Breach Working Session

A 60-minute working session to answer one question — what breach do we refuse to accept? — and leave with a named target, an identified cohort, and a number that proves it isn't forming.

Five timed steps, 4–8 people, one room The one question to ask your SOC lead, verbatim A nine-signal inventory to fill in live Printable worksheets — the artifact is the output
The 10 person-patterns

The problem you thought was everyone is actually someone.

Each pattern is a small, findable group behaving their way toward a specific breach — visibly, over weeks, in signals your identity, email, endpoint, SaaS, and HR systems already capture.

01

The Backup Keyholders

Becomes: Ransomware-driven intrusion
02

The Gatekeepers

Becomes: Help-desk social engineering & account takeover
03

The Patch Deferrers

Becomes: Exploitation of a known, unpatched vulnerability
04

The Shadow Adopters

Becomes: Data leaking through unmanaged AI & apps
05

The Authorized Approvers

Becomes: Business email compromise & payment fraud
06

The Recyclers

Becomes: Credential stuffing that feeds ransomware
07

The Power Connectors

Becomes: Over-scoped third-party & OAuth compromise
08

The Expedient Fixers

Becomes: Exposure through workarounds & shortcuts
09

The Quiet Exit

Becomes: Insider data mishandling before departure
10

The Standing Privileged

Becomes: Privilege abuse & blast-radius amplification

Your workforce isn't the weakest link. It's the largest sensor network you never turned on.

60 minutes, five steps

A named breach beats a category.

A doctor who says "we treat illness" gets a shrug. One who says "you are trending toward a cardiac event, and here's the marker" gets action. This session gets your named breach on paper — and tests, honestly, whether you could see it forming in your own data today.

Ground rules No vendor talk — every question answerable with what you own. One breach. The instinct will be to name three. No moving goalposts — the metric is set in the room.
15 min

1 · Name it

One sentence: the breach you refuse to accept.

10 min

2 · Ask the SOC

The three behaviors that would empty the queue.

15 min

3 · Find the few

A signal inventory — and an honest yes/no: can we see our 10%?

10 min

4 · Act

The levers chosen for that cohort, with owners.

10 min

5 · Prove it

The metric, its baseline, and a 90-day check-in on the calendar.

Two ways risk comes down

Let the incident choose the lever.

Path one

Engage the workforce

Targeted training — for the cohort, on the behavior. Not one-size-fits-all.

Testing — simulate the actual lure: the vishing call, the exec impersonation.

Nudging — correction and reinforcement at the moment of behavior.

Reporting — scorecards that put risk in front of the people who own it.

Path two

Protect the environment

Access restriction — step-down, just-in-time elevation, revoke the dormant.

Orchestrated controls — step-up verification, rotation, isolation.

Governance — spanning both paths, for humans and the agents acting on their credentials.

Celebrate the 90% who don't need intervention. That's not softer security — it's sharper.

Start with the why

Don't start with the tool. Start with the breach you refuse to accept.

Run the session with your SOC. If you can't name your 10% from your own data — you just found the gap, and we should talk.