Skip to content
Get Started
Blog

How Attackers Get Into Your Network

Five common entry points that attackers use. Most breaches combine several of these tactics.

Practical
Guidance
Vendor
Neutral
No
Jargon
Cybersecurity
Threat landscape updates
Current risks facing Northern BC businesses and how to stay ahead of them.
Best Practices
IT management insights
Practical guidance on M365, backups, compliance, and infrastructure from senior engineers.
Compliance
Regulatory readiness
PIPEDA, CIS Controls, and cyber insurance guidance for Canadian SMBs.

Written by senior engineers with decades of experience managing IT and cybersecurity for Northern BC businesses.

Attackers rarely use a single method to break into a business. Instead, they chain together multiple weaknesses to gain access. A stolen password alone might not be enough. An unpatched application alone might go unnoticed. But combine a stolen password with no multi-factor authentication, or an unpatched system with no monitoring, and you have a breach. Understanding these entry points helps you close them.

Phishing Email With Credential Harvest

An employee receives a convincing email that looks like it comes from Microsoft, PayPal, or their bank. It asks them to click a link and verify their password. The link leads to a fake login page that records the credentials. Within minutes, the attacker has a real business email address and password. This is the most common starting point for breaches. No malware needed, no sophisticated code, just social engineering. If that account has access to shared files, email archives, or administrative systems, the attacker is already inside.

Stolen or Reused Passwords From Data Breaches

Attackers purchase databases of compromised credentials from previous breaches. If your employees reuse passwords across sites (the same password for their email, cloud storage, and a hobby website) and that hobby website gets hacked, attackers now have a business credential. They try it against your email system, Microsoft 365, or VPN. Many breaches start here. Attackers don't know which password belongs to whom; they simply test thousands of credentials automatically until one works.

Unpatched Software With A Known Vulnerability

Every software application (Windows, Adobe Reader, web browsers, server applications) receives security updates regularly. These updates fix vulnerabilities that attackers can exploit. If you run software with a known, unpatched vulnerability, attackers can weaponize it. Remote access becomes possible without credentials. System files become modifiable. Attackers don't need to trick users; they simply execute code against the vulnerability. The longer you delay patching, the higher your risk.

Remote Desktop Exposed To The Internet

Some businesses expose Remote Desktop Protocol (RDP) directly to the internet to allow staff to work from home. Without proper controls, this becomes an open door. Attackers run automated tools that scan the internet for open RDP ports, then attempt thousands of password combinations until access is gained. Once inside via RDP, an attacker has a direct connection to your network, just like a legitimate employee. They can move laterally to other systems, access file shares, and establish persistence. RDP should never be publicly exposed without additional authentication layers.

Compromised Vendor With Access To Your Systems

You trust certain vendors with access to your network (software companies for support, backup vendors, security monitoring services). If that vendor is compromised, attackers gain the same access. This is less common but serious, because the attacker arrives with legitimate credentials and expected network traffic patterns. Your monitoring might not flag it as suspicious.

The Chain Reaction

Individual weaknesses become dangerous when combined. A stolen password plus no multi-factor authentication equals immediate access. An unpatched vulnerability plus no network monitoring equals an attacker operating undetected for weeks. This is why a layered approach matters: strong passwords plus MFA plus patching plus monitoring plus endpoint protection creates multiple barriers. No single barrier stops all attacks, but together they force attackers to overcome significant obstacles, making your business a harder target than easier targets nearby.

To protect your network, work with a managed cybersecurity provider who monitors these entry points continuously and maintains defences across all of them.