The Anatomy of a Cyberattack (Updated 2026)
The Anatomy of a Cyberattack (Updated 2026)
A stage-by-stage breakdown of the cyber attack lifecycle, plus the defenses Central Florida businesses can actually deploy at each step.
Quick Answer
The anatomy of a cyberattack follows a predictable sequence: reconnaissance, weaponization, delivery, exploitation, installation, command and control, then actions on objectives. Attackers have to clear every stage to win. Defenders only have to break the chain once, which is why layered detection beats a single perimeter firewall every time.
Why the Anatomy of a Cyberattack Matters to Your Business
Most business owners picture a breach as one dramatic moment. A screen goes red. A ransom note appears. Payroll stops.
Reality is slower and quieter. The anatomy of a cyberattack is a chain of small steps, and each one leaves fingerprints. Attackers research your staff, build a lure, get it in front of somebody, run code, dig in, phone home, and finally take what they came for. Every step is a chance to catch them.
So why do so many attacks succeed? Because most small and mid-sized companies watch only one link in the chain. They buy a firewall, call it a day, and never look at what happens after somebody clicks.
We wrote this walkthrough for owners and operations leads in Daytona Beach, Ormond Beach, Port Orange, and the greater Orlando corridor. No jargon wall. Just the sequence, real incidents, and what to do about each phase.
- The seven stages, in plain English, with a real breach attached to each
- Current numbers on cost, dwell time, and how attackers get in
- A stage-by-stage table of defenses and roughly what they cost
- The blind spots we find most often in Florida offices
- Honest caveats about where this model breaks down
What a Breach Costs Right Now
Numbers move the conversation faster than theory. Here are the figures we point to most often when a client asks whether any of this is worth budgeting for.
Average cost of a data breach for U.S. organizations in 2025, an all-time high and a 9 percent jump year over year. The global average moved the other way, falling to $4.44 million.
Source: IBM Cost of a Data Breach Report 2025
Worth a caveat: those averages skew high because large enterprise incidents pull the mean up. A twelve-person insurance office in Holly Hill is not losing ten million dollars. But the direction matters, and the U.S. number rising while the global number falls says something uncomfortable about regulatory exposure here.
Share of small and mid-sized business breaches with a ransomware component, versus 39 percent for large enterprises. Ransomware showed up in 44 percent of breaches overall.
Source: Verizon 2025 Data Breach Investigations Report
Read the second stat again. Big companies get breached for data. Small companies get breached for pressure. Attackers know a 30-person firm cannot survive four days offline, so they skip the quiet data theft and go straight for encryption.
Three more figures worth keeping in your head:
- 60 percent of breaches involved a human element in 2025: error, manipulation, or misuse (Verizon DBIR 2025)
- 11 days was the global median dwell time, meaning how long attackers sat inside before anyone noticed (Mandiant M-Trends 2025)
- $20.9 billion in reported U.S. cybercrime losses across roughly one million complaints in 2025, up 26 percent (FBI Internet Crime Complaint Center)
Eleven days is the one to sit with. Not a break-in, really. More of a houseguest.
Figures reflect the most recent published editions of each report as of mid-2026. Report methodologies differ, so treat cross-report comparisons loosely and check the primary source before quoting a number in a board deck.
Reconnaissance: They Study You First
Before anything touches your network, somebody does homework. Recon is patient, cheap, and almost entirely invisible.
What are they after? Names, roles, email format, vendor relationships, and whatever you have exposed to the open internet. LinkedIn hands over your org chart for free. Job postings advertise your tech stack. A quick port scan shows which services face the web.
Nothing here is illegal. Nothing here trips an alarm. And that is exactly the problem.
Real-world example
Search “network administrator” plus your city on any professional network. You will find titles, tenure, and often the software they manage. Attackers pair that with a leaked credential dump and they have a starting point before lunch.
What actually helps
- Run a dark web scan on your domain so you know which staff credentials are already circulating
- Trim job postings; describe the role, not the exact firewall model and version
- Inventory what faces the internet, then close what does not need to be open
- Set a policy on what employees share publicly about internal systems
Smart Technologies starts most engagements here, because you cannot defend an attack surface you have never measured. Our free dark web scan takes about ten minutes to request and usually surprises people.
Weaponization: Building the Lure
Now the attacker builds something. Weaponization pairs a payload with a delivery method, tuned to whatever recon turned up.
A generic phishing blast is easy to spot. A message referencing your actual controller, your actual bank, and an invoice number in your actual format is not. That difference is weaponization.
Common builds include a malicious Office macro, a credential-harvesting page cloned from your Microsoft 365 login, a poisoned PDF, or a remote access trojan bundled into something that looks like a driver update.
The AI wrinkle
Generative tools removed the last easy tell. Broken grammar used to flag a phish. Now the copy is clean, on-brand, and written in your vendor’s tone. Training that teaches “look for typos” is training your team to fail.
What actually helps
- Block macros from internet-sourced documents by policy, not by asking nicely
- Run phishing simulations that mimic your real vendors and your real invoice flow
- Teach verification habits: call the known number, never the number in the email
- Flag external senders visually so a spoofed internal name looks wrong immediately
Verizon found user reporting jumped roughly fourfold after training. Training is not a cure. But it is the cheapest lever on this list.
Delivery: Getting It Through the Door
Delivery is the handoff. The weapon reaches a person or a system.
Email carries most of it. Some arrives through a compromised supplier, some through an unpatched web app, some on a USB stick somebody found in a parking lot. Third-party involvement in breaches has climbed to roughly 30 percent, so your vendor’s security is now your security.
Real-world example
The Colonial Pipeline incident in May 2021 needed no phishing at all. Attackers logged into a VPN account with a password that had leaked elsewhere. The account was dormant. It also still worked, and it had no multi-factor authentication in front of it.
Dormant accounts are the unlocked back door of small business IT. We find them constantly.
What actually helps
- Multi-factor authentication on every remote entry point, no exceptions for executives
- A real offboarding checklist so departed staff lose access the same day
- Email filtering that detonates attachments in a sandbox before delivery
- Quarterly review of vendor access; most of it is broader than anyone remembers
Exploitation: The Payload Fires
Something runs. A macro executes, an unpatched service takes a crafted request, or a user types credentials into a page wearing your logo.
Verizon’s 2025 data puts stolen credentials at 22 percent of initial access and exploited vulnerabilities at 20 percent. Together they account for well over a third of breaches. Neither one requires a genius.
Patching is boring. It is also the single highest-return activity most offices skip.
The device nobody patches
Here is the gap we find in Central Florida offices more than any other: the copier. A modern multifunction printer is a networked computer with a hard drive, a web server, and firmware. It scans to email, it holds credentials, and it stores images of everything it copies.
When was your MFP firmware last updated? For most offices the honest answer is never. The National Institute of Standards and Technology treats networked imaging devices as full endpoints, and so should you.
What actually helps
- Patch on a schedule you can prove, with a documented emergency path for critical CVEs
- Include printers, copiers, cameras, and door controllers in the patch inventory
- Change default admin passwords on every networked device, including the office copier
- Segment guest wifi and IoT away from anything holding customer data
Installation: Digging In
Access is fragile. Attackers know it. So the next move is persistence.
They plant a backdoor, a web shell, or a scheduled task. A new service account appears with an unremarkable name. Then comes the quiet one: enrolling their own MFA device on a stolen account, which survives a password reset and burns people weeks later.
Goal: survive a reboot, a patch, and a password change.
Real-world example
The SolarWinds Orion campaign disclosed in December 2020 showed what patience buys. Investigators traced access back to 2019, with the malicious code riding a legitimate signed software update into thousands of environments. Perimeter defense is meaningless when the threat arrives through your own update channel.
What actually helps
- Endpoint detection and response that watches behavior, not just file signatures
- Alerts on new admin accounts, new scheduled tasks, and new MFA enrollments
- Application allowlisting on servers and finance workstations
- Immutable backups that an attacker with domain admin cannot delete
That last bullet decides whether ransomware is a bad week or a closed business.
Command and Control: Phoning Home
Now the compromised machine calls out. C2 gives the attacker a steering wheel.
Traffic hides in plain sight. It rides HTTPS to a domain registered last week, or tunnels through DNS queries, or blends into a cloud storage service your team already uses. To a firewall watching only inbound traffic, it looks like an employee browsing.
Most small networks watch what comes in. Almost none watch what goes out. Attackers count on it.
What actually helps
- Egress filtering; decide what your network is allowed to talk to, then enforce it
- DNS filtering that blocks newly registered and low-reputation domains
- Network segmentation so a compromised front desk PC cannot reach the server room
- Someone actually reading the alerts, which is the part nobody budgets for
Tools without eyes are shelfware. That is the honest case for co-managed IT: not the software, the humans watching it at 2 a.m.
Actions on Objectives: Payday
Everything before this was setup. Now they cash out.
Data walks out the door, encrypted and chunked to look like backup traffic. Or files get locked and a countdown appears. Increasingly it is both, because double extortion pays twice: once for the key, once for silence.
Real-world example
The Accellion FTA compromise in late 2020 hit a file transfer appliance and spilled records from organizations across healthcare, education, and government. Accellion eventually retired the product. One aging appliance, sitting quietly at the network edge, opened the door.
Got anything like that on your network? Most offices do. It is usually the box nobody wants to touch because nobody remembers how it was configured.
And then the cleanup
Good operators sanitize on the way out. Logs get wiped, temp files get cleared, and a rootkit stays behind for the return trip. If your logs live only on the compromised machine, your forensics vanish with them.
- Ship logs off-box to a separate system the attacker cannot reach
- Alert on large or unusual outbound transfers, especially after hours
- Write the incident response plan now; nobody thinks clearly at 3 a.m.
- Confirm your cyber insurance covers what you assume it covers
CISA publishes free guidance and alerts for exactly this planning work. Their StopRansomware resources are practical and cost nothing.
Defenses and Rough Costs by Attack Stage
Clients ask what each layer costs. Fair question. Ranges below reflect what we typically see quoted for small and mid-sized Florida offices in the 10 to 100 seat range, and your actual numbers will vary by vendor, seat count, and contract term.
| Attack Stage | Primary Defense | Typical Cost Range | Effort to Deploy |
|---|---|---|---|
| Reconnaissance | Attack surface review, dark web monitoring | Often free to about $5 per user monthly | Low |
| Weaponization | Security awareness training, phishing simulation | Roughly $2 to $6 per user monthly | Low |
| Delivery | Advanced email filtering, MFA everywhere | Roughly $3 to $10 per user monthly | Low to medium |
| Exploitation | Patch management, device hardening | Bundled in most managed IT plans | Medium |
| Installation | EDR or MDR, immutable backup | Roughly $8 to $25 per endpoint monthly | Medium |
| Command and Control | DNS and egress filtering, segmentation | Roughly $2 to $8 per user monthly | Medium to high |
| Actions on Objectives | Log retention, incident response plan, insurance | Highly variable; plan on four figures annually | High |
Notice the pattern. The cheap controls sit early in the chain, and the expensive ones sit late. Every dollar you spend at reconnaissance and delivery saves several at installation and exfiltration.
Notice something else. No single row stops an attack by itself.
Where the Kill Chain Model Falls Short
Lockheed Martin published this framework in 2011. It has aged reasonably well, and it is still the clearest teaching tool available. It is not gospel.
Three honest limitations:
- Attacks are not always linear. Skilled groups loop back, skip phases, and run several chains at once across your infrastructure.
- Insiders skip the front half entirely. A disgruntled employee already has credentials and a badge. Reconnaissance and delivery simply do not apply.
- It nudges you toward prevention. Teams read seven stages, fixate on stopping stage one, and underfund detection and response. Then something gets through, and nobody is watching.
MITRE ATT&CK covers the same ground in far more detail: fourteen tactic categories, hundreds of documented techniques, updated continuously against real intrusions. It also adds lateral movement and exfiltration as distinct phases.
| Comparison | Cyber Kill Chain | MITRE ATT&CK |
|---|---|---|
| Origin | Lockheed Martin, 2011 | MITRE Corporation, 2013 |
| Structure | Seven linear phases | Fourteen tactics, hundreds of techniques |
| Attack flow | Sequential | Non-linear and flexible |
| Detail level | High-level overview | Granular tactics and procedures |
| Updates | Largely static since 2011 | Continuously updated |
| Best for | Explaining risk, strategic planning | Detection engineering and threat hunting |
Our take: use the kill chain to explain risk to a board or an owner. Use ATT&CK when you are actually building detections. They answer different questions.
What This Looks Like in Central Florida
Florida businesses carry a specific risk profile, and geography is part of it.
Hurricane season forces a conversation about continuity every June. Good. But most Daytona Beach continuity plans assume the threat is water and wind, not encryption. A generator does not help when your files are locked, and a ransomware event during an evacuation is a genuinely bad week.
Then there is the industry mix along the I-4 corridor. Hospitality, healthcare, construction, marine services, professional firms. Seasonal staffing means constant onboarding and, more importantly, sloppy offboarding. Every spring we find accounts still active for people who left in November.
Cybercrime losses reported to the FBI topped $20.9 billion nationally in 2025, up 26 percent year over year, and Florida sits near the top of the state rankings for reported losses. We would not lean on any single state figure without checking the current IC3 report directly; methodology and reporting rates vary. The direction, though, is not in dispute.
Smart Technologies of Florida has worked out of Daytona Beach since 1999. We have watched the local threat picture shift from opportunistic spam to targeted, patient, financially motivated operations. Same seven stages. Better execution.
How Smart Technologies Helps
We are not only a copier company. Our team runs managed network and security services for businesses across Volusia, Flagler, and the Orlando metro. Here is where we plug into the chain.
Risk Assessment
We map your exposure the way an attacker would, then hand you a prioritized list instead of a scare report.
Dark Web Monitoring
Your credentials are probably out there already. We find out which ones, and how old they are.
Managed Detection
EDR paired with people who read the alerts. Tools alone catch nothing at 2 a.m.
Patch and Harden
Workstations, servers, firewalls, and yes, the copier nobody has updated since install.
Backup and Recovery
Immutable, tested, and restorable. An untested backup is a rumor, not a plan.
Response Planning
Who calls whom, in what order, with which phone. Written down before you need it.
Curious what downtime actually costs your operation? Our business system downtime calculator runs the math in about two minutes. Most owners guess low by a wide margin.
You can also read more about Smart Technologies and how we work, or jump straight to our managed IT solutions.
Frequently Asked Questions
What is the anatomy of a cyberattack?
It is the sequence of stages an attacker moves through to compromise a target: reconnaissance, weaponization, delivery, exploitation, installation, command and control, and actions on objectives. Each stage has its own signals and its own countermeasures.
What are the 7 stages of a cyberattack?
Reconnaissance, weaponization, delivery, exploitation, installation, command and control, and actions on objectives. Lockheed Martin published this model, called the Cyber Kill Chain, in 2011. It remains the most widely taught framework for explaining how intrusions unfold.
How long do attackers stay in a network before detection?
Mandiant reported a global median dwell time of 11 days in its M-Trends 2025 report. Detection method changes the picture a lot: about 26 days when an outside party raised the alarm, roughly 10 days when the organization found it internally, and around 5 days when the attacker announced themselves, which usually means ransomware.
What does a data breach cost a business?
IBM put the 2025 U.S. average at $10.22 million, an all-time high, against a global average of $4.44 million. Those figures are pulled upward by large enterprise incidents, so a small business will see far smaller absolute numbers. Downtime, legal fees, and lost customers still hurt disproportionately at small scale.
Are small businesses really targeted by cyberattacks?
Yes, and the shape of the attack differs. Verizon found 88 percent of small and mid-sized business breaches included ransomware, versus 39 percent at large enterprises. Attackers assume a smaller company cannot absorb extended downtime, which makes encryption a faster route to payment.
Can a copier or printer be part of a cyberattack?
Absolutely. A networked multifunction printer has firmware, storage, an embedded web server, and often saved scan-to-email credentials. Default passwords and unpatched firmware make it an easy foothold, and it sits on the same network as everything else. Most offices have never updated theirs.
What is the difference between the Cyber Kill Chain and MITRE ATT&CK?
The kill chain gives you seven linear phases and works well for explaining risk to non-technical stakeholders. MITRE ATT&CK offers fourteen tactic categories and hundreds of specific techniques, updated continuously from real-world intrusion data, and suits detection engineering better. Many teams use both.
Which stage is easiest to defend?
Delivery, usually. Multi-factor authentication plus decent email filtering blocks a large share of attempts for a few dollars per user each month. Stolen credentials accounted for 22 percent of initial access in Verizon’s 2025 data, and MFA neutralizes most of that.
Does employee training actually work?
It helps, though it is not a shield. Verizon observed user reporting rising roughly fourfold after training programs. Faster reporting means faster containment. Human error still factored into 60 percent of breaches, so training belongs alongside technical controls rather than in place of them.
What should I do first if I suspect a breach?
Isolate the affected machine from the network but leave it powered on, because shutting down destroys memory-resident evidence. Call your IT provider and your cyber insurance carrier before touching anything else. Do not wipe and reimage until somebody has captured forensics, and do not communicate about the incident on the systems you think are compromised.
How often should we test our backups?
Quarterly at minimum, with a full restore, not a green checkmark in a dashboard. Backups fail silently more often than anyone expects. And if your backup is reachable with domain admin credentials, ransomware will delete it before encrypting anything.
Is cyber insurance worth it for a small Florida business?
For most, yes, though the fine print decides everything. Carriers increasingly require MFA, EDR, and tested backups as conditions of coverage, and claims get denied when those attestations turn out to be wrong. We are not insurance advisors, so review any policy with your broker and your legal counsel before relying on it.
Find Your Gaps Before Someone Else Does
Smart Technologies offers Central Florida businesses a free IT risk assessment. We map your exposure across all seven stages and give you a prioritized fix list, not a sales pitch.
Business Transformation Agency





