Illumio Exec: Predictable Attacks, Unpredictable Defenses Highlight Observability Gap
Most cyberattacks are predictable, but defenses aren't due to observability gaps, says Illumio exec.
Legacy detection tools are part of the problem. Firewalls were never designed for application and network dependency mapping, so security strategies are built around individual systems assessed in isolation, the article states. Teams may secure each system effectively while remaining blind to how an attacker could move between them. Attackers actively exploit those boundaries, targeting a weakness in one area to move toward what matters most.
The gap between detection and containment is growing. Illumio's research found that 95% of security professionals are confident they can detect unauthorized lateral movement, yet only 17% can isolate a compromised workload in near real-time. Most (51%) still take a few hours or longer to contain an incident. CrowdStrike found the average time to achieve lateral movement is now just 29 minutes, so by the time organizations act, the attacker has already moved.
AI is accelerating this asymmetry. Tools such as Claude Mythos and GPT-5.5 are increasing attackers' ability to detect vulnerabilities, develop targeted exploits, and chain them together, the VP writes. This further widens the gap between detection and action, as attacks that once required manual effort can now be executed at machine speed.
To address this, the article calls for a fundamental shift toward proactive containment. It argues organizations should acknowledge that compromise is inevitable and act on that assumption before an incident occurs. That means understanding connectivity risks, removing unnecessary pathways, enforcing boundaries between systems, and limiting how far an attacker can move.