Skip to content

6 min read

American Corners

Where weak spots cluster

Weaknesses are not spread evenly

If you had to guess where an incident is most likely to begin, you might imagine a clever, technical break-in. In reality, the same few weak spots turn up again and again. A vulnerability, a gap that could be taken advantage of, is far more likely to be one of a handful of ordinary ones than something exotic.

That is good news, because it tells you where to look first. Instead of watching everywhere equally, you can check the places weaknesses genuinely cluster. There are four.

The four clusters

People

The most reliable way into a system is often to ask a person, not to defeat a machine. Most incidents begin with someone being tricked, rushed, or trusted into doing something they should not: clicking a link, approving a payment, sharing a code, letting a stranger through a door.

This is not because people are careless. It is because attackers are good at applying pressure, and our instincts around urgency, authority, fear and helpfulness are all easy to exploit. So the first place to look is the everyday moments where a person is asked to act quickly on someone else's say-so.

Reused passwords

A password reused across several accounts is a single weakness that quietly multiplies. When any one of those sites is breached, and breaches are common, attackers take the leaked email-and-password pairs and try them everywhere else. One old leak can unlock your email, your shopping, and your work account, all without any new "hack".

Reuse is so widespread, and so easy to exploit at scale, that it is one of the densest clusters of risk there is. Unique passwords, kept in a password manager, break the chain.

Unpatched software

Every device and app carries known weaknesses that its makers have already fixed in an update. A weakness stops being dangerous the moment you install the patch, and stays dangerous for exactly as long as you do not. Attackers scan the internet for devices still running the old, vulnerable version, because it is easy and it works.

The cluster here is anything left un-updated: the phone a few versions behind, the app that keeps asking to restart, the home router no one has touched in years, the old computer still running software that no longer receives fixes at all.

Third parties

You are not only as secure as your own habits. You also depend on the suppliers, apps, and services you connect to. A weakness in one of them can become your problem: a breach at a company you gave your data to, a compromised supplier used to reach its customers, an app with more access to your accounts than it needs.

You cannot audit every third party, but you can reduce the exposure: share data only with services you have reason to trust, remove access for apps and accounts you no longer use, and pay attention when a supplier reports a breach that touches you.

Look here first

None of these clusters is a rare, advanced threat. They are the ordinary, well worn paths that most incidents actually take. When you are deciding where to spend limited attention, start with the four: are people being set up to act too quickly, are passwords reused, is software out of date, and who else has access to what matters? Looking hard at those beats worrying evenly about everything.

Where this lesson comes from

Built from

  • Workshop 1: Cybersecurity Essentials (participant guide V3.0): common sources of weakness

alphaPlan courses are built from taught programmes rather than invented for the web. Where a claim rests on an outside standard or a reported case, it is named above so you can check it rather than take our word for it.

shënim: ky material u krijua në kuadër të projektit 'U.S. Cybersecurity Leadership in AI for Albania', financuar nga departamenti i shtetit i shteteve të bashkuara. mendimet, gjetjet dhe përfundimet e paraqitura këtu janë të autorit(ëve) dhe nuk pasqyrojnë domosdoshmërisht ato të departamentit të shtetit të shteteve të bashkuara.

Disclaimer: This material was created on behalf of the 'U.S. Cybersecurity Leadership in AI for Albania' project, funded by the United States Department of State. The opinions, findings, and conclusions stated herein are those of the author(s) and do not necessarily reflect those of the United States Department of State.

Disclaimer

Found something unclear, outdated or improvable? Suggest an improvement