4 MIN READ
The platform org has bought the platform that promises to automate the attack path map, paid the licence, sat through the demo, and then watched the engineering lead open the produced map exactly once, take a screenshot for the slide deck, and never look at it again. The vendor calls this customer success. The honest version sits as the map the security org builds with a whiteboard, and the work that comes out of that map runs as the work that closes the gap.
Attack path mapping amounts to the discipline of drawing the route an adversary would actually take through the environment, then fixing the parts of the route that are stupid. The vendors (XM Cyber, AttackIQ, SafeBreach) sell the platform that promises to automate the mapping. The security org in a small company knows the environment better than the vendor ever will. The honest version sits as the version that produces the fixes, not the version that produces the slide deck. The map that lands in the slide deck is the map nobody opens again. The map that lands in the ticket queue amounts to the map that closes the gap.
What the map actually covers
Three layers, in the order they matter when the conversation gets serious. The entry point layer shows the public facing systems, the exposed services, the phishing surface, the supply chain dependency, the place the adversary lands inside the network. This part of the map tells the security org where the intrusion gets in.
The privilege layer shows the identity tier, the service accounts, the lateral movement path, the escalation path, the route used to move from the entry point to the crown jewel. Reading this layer tells the security org how movement happens once the perimeter has been crossed.
The data layer shows the data store, the backup, the exfiltration target, the thing that actually gets taken. This layer is what the breach monetises. Most real maps compress to a single page. The compression sits as the point. If the map takes ten slides to explain, the map will not survive the quarter.
How to build one without a vendor
Start with a manual mapping exercise. The engineering lead, the detection lead, the cloud architect, whoever knows the environment, in a room with a whiteboard for two hours. Draw the entry points, the privilege paths, the data stores. Run the exercise once a quarter. The whiteboard map amounts to the map the people in the room actually understand, and the map the people understand sits as the map the company will defend when the incident hits.
Then layer the graph database query on top. The graph already exists, scattered across Active Directory, the cloud IAM, the CMDB, the network sensor. Query it for the paths from the external entry point to the crown jewel, the way a BloodHound or a Cartography query does. The graph query produces the map that updates as the environment changes, which counts as the difference between a map that goes stale in a week and a map the company can actually trust.
Finally, run the adversary emulation. The red team, the purple team, the breach and attack simulation, run quarterly, run against the same map, and produce the delta between the predicted path and the actual path. The emulation exposes the gap between what the security org thinks the map looks like and what the map actually looks like to an outside adversary. The emulated delta amounts to the work the security org has to do next.
How the map produces fixes
Three things the map actually does once the security org has it. Choke point identification comes first. Look for the three or four nodes that every path passes through. Harden those nodes, and the intrusion turns a free walk into a forced climb. Most enterprise maps compress to a handful of choke points, and the choke point sits as the highest use fix available in a quarter.
Dependency removal comes second. The map exposes dependencies that do not need to exist, the legacy service account that the new platform replaced, the network path that nobody remembers opening, the firewall rule that was added for a project that ended in 2022. Remove what no longer needs to be there, and the map shrinks. The shrunk map sits as the map the company can defend.
Detection gap exposure comes third. The map shows the step on the path that the detection stack does not cover, the alert that does not fire, the log that does not get retained. Hand the gap to the detection engineering org, and the gap closes. The company that does all three with a quarterly cadence holds the line. The one that buys the platform and skips the mapping does not.

The bottom line
Whiteboard, graph query, quarterly emulation, three moves and a quarterly cadence. The company that does the three moves holds the line. The one that buys the platform and skips the mapping does not.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



