Skip to Main Content
Blog

What happens after a security breach? Minimising impact with zero trust

3 minute read

Ricky Phillips

April 16th, 2026

What happens after a security breach? Minimising impact with zero trust

3 minute read

Ricky Phillips

April 16th, 2026

No organisation wants to experience a cyber breach. But the uncomfortable reality is that breaches are no longer rare events, they are expected. 

According to the UK Government’s Cyber Security Breaches Survey, 43% of UK businesses and 30% of charities reported experiencing a cyber security breach or attack in the last 12 months.  

Cyber criminals are more sophisticated, environments are more complex, and employees are working across hybrid networks and cloud platforms. The question many organisations now face isn’t “Will we experience a breach?” but rather “What happens if one occurs?” 

This is where the “assume breach” mindset becomes critical. Instead of focusing solely on preventing attacks, modern security strategies also focus on limiting the damage if an attacker gets in. In security terms, this is about reducing the blast radius; a core principle behind zero trust security. 

 

Why breaches are inevitable 

Modern IT environments are far more open and interconnected than they were a decade ago. Organisations now rely on cloud services, remote access, mobile devices, and third-party integrations to operate efficiently. 

While this flexibility supports productivity, it also expands the number of potential entry points attackers can exploit. Many cyber incidents begin with something relatively simple: a compromised password, a phishing email, or a misconfigured system. 

Research referenced in our whitepaper shows that compromised identities are responsible for more than 80% of breaches, highlighting how attackers increasingly target user credentials rather than infrastructure vulnerabilities.  

Even organisations with strong cyber security controls cannot guarantee that every threat will be blocked. This is why the focus of modern security strategies has shifted. Instead of relying solely on prevention, organisations need to assume attackers may eventually gain access and prepare for how to contain them quickly. 

How attackers move laterally 

Once attackers gain an initial foothold, their next objective is usually to expand their access. This process is known as lateral movement. 

Imagine an attacker successfully logging into an employee account using stolen credentials. In many traditional security environments, that single login may allow them to explore multiple systems without further verification. They might search for sensitive files, attempt to access additional applications, or look for ways to escalate privileges. 

If the compromised account has broad access rights, the attacker can gradually move deeper into the environment. By the time suspicious activity is detected, valuable data may already have been accessed or exfiltrated. 

What “blast radius” really means

The concept of blast radius helps explain how far the damage from a breach can spread. 

Borrowed from engineering and disaster planning, the term describes how much of an environment is affected by an initial incident. In cyber security, it refers to how many systems, applications, or data sets an attacker can reach after gaining access. 

In environments with minimal access controls, the blast radius can be significant. A compromised user account may provide access to multiple applications, internal networks, or sensitive databases. 

In contrast, a well-designed security model restricts that access. Even if an attacker manages to log in, they encounter multiple barriers that limit how far they can move. The breach is contained before it can escalate. 

Reducing this blast radius is one of the key goals of zero trust security architecture. 

How least privilege and segmentation limit damage 

Zero trust approaches security differently from traditional perimeter models. Instead of assuming users inside the network can be trusted, every access request is verified and evaluated continuously. 

  • Least privilege access ensures that users only receive the minimum level of access required to perform their role. This prevents accounts from having unnecessary permissions that attackers could exploit 
  • Segmentation divides systems into smaller controlled zones. Rather than allowing unrestricted internal access, security policies control how systems communicate with each other 

Together, these measures significantly reduce the ability of attackers to move laterally. If a single account becomes compromised, the attacker cannot easily reach other parts of the environment. 

Why the “assume breach” mindset matters 

Traditional cyber security models focused heavily on keeping attackers out. But in today’s hybrid and cloud-first environments, those boundaries are far less clear. 

Zero trust follows a different philosophy: organisations should operate with the assumption that breaches may already have occurred. This mindset changes how security controls are designed. Rather than trusting users after a single login, access is continuously evaluated using signals such as identity, device health, and behavioural patterns. 

Strengthening security with zero trust 

Limiting the impact of a breach requires coordinated security controls across identity, devices, networks, and applications. Organisations that adopt zero trust typically focus on strengthening a number of key areas: 

  • Implementing multi-factor authentication (MFA) across all users  
  • Enforcing identity-based access policies  
  • Monitoring for unusual login behaviour or risk signals  
  • Segmenting networks and critical workloads  
  • Continuously verifying user and device context  

These measures ensure that even if attackers manage to gain access, they face multiple layers of verification and restriction. 

Learn more in our zero trust whitepaper 

Implementing zero trust isn’t about deploying a single tool. It’s about building a security strategy that assumes attackers may eventually gain access and focuses on limiting the damage they can cause. 

Our whitepaper explores the current threat landscape and outlines a practical roadmap for organisations looking to strengthen their security posture. 

Read the whitepaper
person on tablet
Headshot of Ricky Phillips

About the author

Ricky Phillips, Cyber Security Solutions Manager

Ricky joined Phoenix in 2018 to focus on the Mimecast potfolio, later moving into a broader security role sitting in the Alliances Team. Ricky now manages a team of seven Security Specialists tasked to ensure our customers get the right solutions for their issues. Ricky is passionate about ensuring we advise customers on what is the best fit for them as an organisation, taking into account the multitude of factors involved in choosing a solution, Ricky is commited to make sure that Phoenix is seen as a trusted partner in the cyber security space.

Connect with Ricky on LinkedIn.