What Firefighting Drills Taught Me About Breach Readiness

table of contents

On Friday, I was in the office planning to write a new blog on breach readiness. It was a nice day. Comfortable weather, blue skies, the hills at a distance, the hum of dense discussions in conference rooms, and two hours at hand. I was sipping a hot cup of single-origin traditional Earl Grey with perfect, aromatic notes and sharp bergamot flavor when the alarm went off.

Good thing I travel light. Bad thing I had to leave the tea half done. As we gathered down below at the safe assembly spot, I listened in rapt attention to the lecture about dealing with fires.

And then it dawned on me.

A fire spreads only when there is nothing designed to stop it. So does a cyberattack.

When the alarm went off, people started moving. Some knew exactly where to go. Others looked around first. Fire wardens started directing people. Doors opened. Staircases filled. Everyone eventually gathered at the designated assembly point.

One of the fire wardens quipped, “Thank God it was a drill. Otherwise we would have a problem on our hands. When will these guys pay attention?”

For me, the drill had already stopped being about fire.

It was about what happens when something goes wrong in a complex environment and whether that environment has been designed to prevent a small incident from becoming a catastrophe.

That is exactly the conversation we need to have about cyberattacks.

Every building is designed to be ready for a fire, assuming that a fire can occur any day.

If you think modern fire protection is all about a fire extinguisher, you are probably the board member who feels cybersecurity is all about the firewall.

Fire management begins much earlier. First come the business requirements. Then comes the building layout. In the digital world, we call this architecture.

Every building is built to the guidelines of the International Building Code, developed by the International Code Council, which sets overall structural requirements, fire resistance ratings, and passive fire safety features like compartmentalization, means of egress, active fire protection, and passive protection, among other measures.

Building designers determine where people can enter, where they can exit, how many egress routes exist, the width of each route, and more. They also consider fire-rated limitations, such as which areas need fire-rated construction, where people can exit, where combustible materials are stored, and where electrical equipment should be located.

Then they add layers. These layers modify risk. In ISO 27001, controls modify risk.

Smoke and heat detection, Fire alarms, Sprinklers, Fire extinguishers, Fire doors, Staircase lights, Emergency lighting, Emergency power.

Then they add procedures.

Evacuation plans.

Fire control rooms.

Change governance.

And, most importantly, exercises.

Containment by Architecture as the First Principle for Firefighting

The objective is to ensure the fire does not become catastrophic and is managed before it becomes unmanageable.

Most fires start small.

Maybe in a small electrical closet.

Because buildings are deliberately designed with many boundaries, like fire-rated walls or fire doors, fires find it difficult to spread.

And once detected, the controls kick in to eliminate the fire and ensure people’s safety, whether it’s an alarm, a sprinkler, an extinguisher, or an emergency evacuation route.

The fire becomes a stray incident.

Let us compare with how most enterprises view cyberattacks.

The similarity is uncanny. The readiness, not so much.

Most cyberattacks start small.

An attacker compromises one endpoint. Then another. Then a server. Then a privileged identity. Then an application. Then a database. Then backup infrastructure. Then operational technology.

By then it is a catastrophe. Most breach announcements read like an AI-generated script.

“We had an unprecedented cyberattack, and we have shut down operations to preserve stakeholder interests.”

The catastrophe happens because nothing stopped the attacker from moving.

Firefighting Is Also Built Upon a Predecided, Minimum Viable Business Model

When designing buildings to be fire-ready, designers ask the building owner how much of the building must remain standing when fires happen.

That determines the investment in the boundaries and controls they architect. That’s the core philosophy behind MVDE, or the Minimum Viable Digital Enterprise, the amount of digital business that must remain operational even when “unprecedented” cyberattacks happen.

For years, cybersecurity has focused enormously on detecting the attacker. EDR. SIEM. XDR. Threat intelligence. SOC analysts. Vulnerability management. Incident response. Today, each of these has the word AI in front of them too.

These are important.

But what happens when the cyberattack gets through?

It is very common to hear:

“We will detect it and then respond.”

And this suggests we may have designed the equivalent of a building where the fire alarm tells everyone there is a fire, but there are no fire doors, compartments, or sprinklers.

The reality is that cyberattacks are rising steeply despite massive, record-breaking investments in cybersecurity. The global cybersecurity market is projected to cross $248 billion, while the world has seen an 18% jump in annualized cyberattacks. The data highlights a “preparedness gap.”

The reality is that we are not prioritizing how to stop the next cyberattack. Roughly 30% to 35% of the global security budget goes to continuous observability, data ingestion, and rapid detection.

Detection tells you something is burning. It does not stop the fire from reaching the next room.

Cybersecurity needs its equivalent of compartmentation as the foundational element of breach-ready architecture.

Instead of letting the enterprise behave like one enormous connected floor, we must create breach-ready zones and microsegments interconnected by controlled conduits around business functions, identities, applications, workloads, critical digital systems, and operational technology.

That is exactly what a breach-ready microsegmentation platform delivers. Today, you can adopt a breach-ready posture in hours or days, instead of weeks or months. And if you are worried about policies best suited to your environment, your LLM can suggest the best ones in minutes.

Access Report: The Forrester Wave™: Microsegmentation Solutions, Q3 2026 — See why ColorTokens was named a Leader and recognized for deployment flexibility.

Fire Safety Is an Architectural Discipline First: Then It Is an Emergency Response

Another lesson from that fire drill. The building is architected to ensure that fires do not occur everywhere. Certain parts of the building that contain business-critical systems are fire-resistant and, in some cases, fireproof by design.

Extinguishers are put where fires are most likely to start. Near the electrical equipment. Near kitchens. Near specific industrial hazards.

And where an authorized person can access it on demand.

Cybersecurity must work the same way.

Most of the digital landscape must be designed to keep the attack surface as small as possible around critical digital systems. The critical digital systems must also be designed to ensure attackers cannot move from one system to another by exploiting existing connections.

Hardening the Digital Landscape is critical to reduce the elbow room for unauthorized identities to move unnoticed and spread the attack. This must be part of every foundational digital architecture an organization has.

If a manufacturing environment contains critical PLCs, HMIs, engineering workstations, and safety systems, make it impossible for an attacker to cross the enterprise by reducing lateral movement.

If a hospital has critical clinical systems, do not treat them like another collection of IP addresses. Establish mechanisms to detect behavioral anomalies in valid identities as they move from one clinical system to another.

If a financial institution has payment infrastructure, isolate the business function from its dependencies by allowing only the minimum access required, following least-privilege principles.

If an enterprise has legacy systems or old OT infrastructure, put them in a bubble so that only valid users and applications can connect to them. Create software-defined demilitarized zones that prevent any direct connections.

If suppliers connect to critical environments, their access paths must be part of the architecture. Create a breach-ready zone for suppliers, and microsegment it so each supplier can reach the systems it needs, but can’t connect to other areas.

Put controls where the consequences matter.

That is a very different philosophy from simply buying another security product and deploying it somewhere in the network.

And then there is the drill itself.

Management doesn’t run a fire drill because they believe there will be a fire at 11:00 AM on Thursday.

They run it because no one wants to discover risky procedural gaps that could have been addressed during the real emergency.

Does everybody know what to do? Do the alarms work? Are exits accessible? Would people be trapped behind locked doors? Can the fire team communicate? Does emergency lighting work? Can people who need medical assistance actually be evacuated? Does the organization know who is in charge?

The drill exposes assumptions.

Cybersecurity needs exactly the same discipline.

It’s not an assumption that the security team will handle the breach when it happens. The issue is not whether the SOC can detect ransomware. Or whether the EDR is the state-of-the-art technology, or whether your firewall is the best in class there is.

When you live through a breach, you realize these issues are inconsequential once the effects of the cyberattack are felt.

The question is almost always asked: Did we know and prepare for a situation where attackers might bypass them and get in? And what happens to the enterprise when ransomware is already inside?

Can we identify the affected zone?

Can we isolate it without shutting down the entire business?

Can identities be restricted?

Can critical systems continue communicating with the systems they actually need?

Can suppliers still access what they need, and nothing else?

Can critical OT systems operate unaffected by an IT breach?

Can the business identify its Minimum Viable Digital Enterprise?

Can we demonstrate that an attack against one business function does not automatically become an attack against everything?

And perhaps the most important question:

Have we actually tested it?

Not with a PowerPoint, or a compliance checklist, or with a document sitting in SharePoint.

But with the architecture designed to deny attackers any movement if they breached the existing defenses. And with the operational capability to contain the attack to the microsegment where it first started.


Watch: What Does Breach Readiness Look Like When Attackers Can Operate at AI Speed? — Former SolarWinds CISO Tim Brown on architecture, lateral movement, identity, and critical assets.


From Fire Readiness to Breach Readiness

This is what I mean by Breach Readiness.

Breach readiness is not the belief that we can prevent every attack. It is not the belief that our SOC will detect everything immediately. And it certainly is not having an incident response plan that starts with “assemble the response team” after the attacker has already moved through the environment.

Breach readiness starts with a different assumption:

It begins with the first principles of zero trust. Assume something will get through. Then design the enterprise accordingly. Understand the critical digital systems. Model how an attacker could reach them. Anticipate the attack.

Build zones and microsegments around those systems. Control identities and communication paths. Detect abnormal behavior. Create mechanisms to contain compromised areas. Protect the systems that keep the business alive.

Practice what happens when those controls are triggered. And measure the one thing the board ultimately cares about:

Can the business continue operating while the attack is happening?

That is the cyber equivalent of designing a building where a fire in one room doesn’t become a fire throughout the building.

Call to Action

In its Technology Trends Outlook for 2026, McKinsey famously mentions: “For decades, the cat-and-mouse game of cybersecurity played out over days and weeks, giving defenders time to find and fix vulnerabilities before attackers could fully exploit them. AI has eliminated that buffer. More than three-quarters of all cybersecurity vulnerabilities are currently classified as ‘zero-day,’ meaning that by the time they are publicly disclosed, an exploit has already been developed.”

This is the age of AI-powered attacks. AI cyberattacks can spread far faster than defenders can adapt. Extreme speed needs to be a defender’s signature.


Watch: See How ColorTokens Contains an AI-Assisted Attack — See containment in action as ColorTokens blocks reconnaissance and removes access paths.


The most important thing about the fire drill I watched was not how quickly people responded. Some people did not. Many did. The fire wardens went back to their register. They knew what they needed to do next.

I marveled at the preparation in place before the alarm went off. The exits had already been designed. The alarms had already been installed. The extinguishers were already positioned. The evacuation routes already existed. People had already been assigned responsibilities.

The drill simply tested whether the architecture and the people were ready.

Cybersecurity needs the same mindset.

Let us not wait for the breach to reduce attack surfaces. Let us not wait for ransomware to discover the blast radius. Let us not wait for an attacker to reach the crown jewels before deciding which systems should be allowed to communicate. Let us not wait for the crisis to discover that shutting down the network also shuts down the business.

Let us architect the digital systems so a breach in an enterprise does not automatically mean catastrophe.

The defenders react with preplanned capabilities and ensure that the Minimum Viable Digital business remains unaffected.

The objective of modern cybersecurity cannot simply be, “we stopped the attacker.” Because many times we might not. The objective should be that when an attacker gets in, the business’s critical digital systems remain unaffected, as much as practically possible.

That is the difference between having security controls and having a breach-ready architecture.

The next time you participate in a fire drill, look around.

Look at the doors. Look at the exits. Look at the fire extinguishers. Look at the compartmentation. Look at the people who know exactly what they are supposed to do.

Then ask yourself one uncomfortable question:

If this were a cyberattack instead of a fire, would our digital enterprise be designed this well?

If the answer is not an immediate yes, do not wait for the alarm.

Start designing the boundaries now. Build breach readiness into the architecture.

If you’re asking the same question about your own environment, contact us to discuss how the right boundaries can help contain an attack before it spreads.