Skip to main content
Zero Trust

What I Learned Watching a Contractor Laptop Nearly Hand Over the Warehouse

Notes from the messy reality of endpoint Zero Trust: why your green antivirus dashboard means nothing, what actually stops a 29-minute breakout, and the five things I'd do first if I inherited your security budget.

Twenty-nine minutes. That's the current record for an attacker to go from first foothold to lateral movement once they're in. Last year it was 48. I keep that number taped above my desk because it's the only deadline that actually matters in this job.

If your endpoint strategy is still "run the nightly scan and hope," you are not behind by a little. You are behind by the entire length of a lunch break. The scan finishes after the intruder has already found the domain controller.

I don't say "Zero Trust" much in meetings anymore. People nod and then go buy another dashboard. What I mean when I say it is simpler: stop assuming a device is trustworthy just because it logged in yesterday.

Your green dashboard is not evidence of anything

Let me tell you about a company I worked with — a regional freight broker, about 300 people, two IT staff, one of whom was also the facilities guy. Antivirus on every laptop. Console showed all green for eleven months straight.

Then a broker clicked a link in what looked like a carrier rate confirmation. No file downloaded. No alert fired. Forty minutes later someone was logged into their TMS with valid credentials, pulling customer manifests. The antivirus did its job perfectly. There was nothing for it to catch.

This is not bad luck. Roughly four out of five detections in the past year involved no malware file at all — stolen tokens, living-off-the-land binaries, that kind of thing. Signature engines match known bad files. They do not match a guy typing your own admin credentials into your own portal.

EDR is the obvious next step and it's a real one. Behavioral detection, process kill, endpoint isolation, rollback. If you're not running it yet, stop reading and go fix that. But be honest about what EDR is: it's a smoke alarm. A very good smoke alarm. It tells you the kitchen is on fire. It does not stop the match from being struck.

Zero Trust is the part where you stop leaving matches on the counter. Default deny. Grant per session, per resource, minimum necessary. That's the whole idea. Everything else is implementation.

Same broker, six months later

We rebuilt the contractor access path. Here's what it looked like in practice, because the architecture diagrams never show this part.

The broker's laptop ran an EDR agent that covered Windows, macOS, and the two Linux boxes the ops team refused to give up. That gave us detection, attack surface reduction rules, and a vulnerability inventory without adding a second agent nobody would maintain.

Then the important change. Authentication stopped being a one-time event. Every time that laptop tried to reach the TMS, its posture got checked first — patch level, sensor health, disk encryption status. Miss a critical patch and you don't get the TMS. You get a page that says "update your machine," with a link. That's it. No help desk call, no exception form.

The contractor's account had read access to shipping manifests and nothing else. Not the finance VLAN. Not a persistent VPN. Four hours of access, then it expired and they re-authenticated. Annoying? Slightly. Also the reason the second incident — and there was a second incident, there always is — ended with a locked account and a two-line ticket instead of a ransom note.

Three things had to work together for that to hold:

  • Behavioral EDR on anything that touches the network. Laptops, phones, the internet-facing web server nobody remembers owning. Many platforms bundle antivirus, which is nice because you're not stacking agents.
  • MFA that a fake login page can't beat. Hardware keys or platform authenticators. SMS codes and push prompts are better than nothing and worse than you think — a tired user will approve a push at 11pm because they assume it's the VPN again.
  • Patching aimed at what's actually being exploited. Not every CVE. The CISA KEV list is the one that matters. Roughly 1,700 entries as of last August, and it's a much shorter reading list than your vendor's severity feed.

The numbers that should change your budget conversation

I hate fear-based selling, so I'll just put the figures on the table and let you draw your own conclusions.

Average breach cost broke five million dollars last year. Record high, twelve percent jump. That's an average, which means half of the organizations did worse. For a 300-person freight broker, one week of downed warehouse operations isn't a line item — it's an existential event.

The interesting counterpoint: companies that leaned hard on automation in their security operations saved close to two million per breach compared to companies that didn't. Not because they bought an AI product. Because they automated the boring parts — isolating an endpoint, killing a session, verifying a patch actually installed — so two people could respond in seconds instead of hours.

Here's a number I don't see quoted enough, and it's the one that changed how I think about this: the median time from an employee's first day to their first phishing click is roughly 21 minutes. Twenty-one. That's not a typo and it's not a worst-case figure. New hires click fast because they're trying to be helpful and they haven't learned your culture's suspicions yet. If your onboarding checklist doesn't include a phishing simulation in week one, you are running an experiment on your own network.

Meanwhile dwell time — the gap between intrusion and discovery — is still measured in months, not days. Two hundred and fifty-ish days on average. Imagine a stranger in your house for eight months, and you only find out because the water bill looked weird.

Zero Trust doesn't make that stranger disappear. It makes the rooms smaller. If every session expires and every privilege is temporary, the stranger has to keep re-introducing himself, and eventually somebody notices.

One more shift worth flagging: more breaches now start with exploitation of a software vulnerability than with a stolen password. That flips the priority order for a lot of teams. Your patch posture is no longer maintenance. It's access control.

Five things I'd do first

If I inherited your environment tomorrow, with whatever licenses you already own:

1. Get EDR on everything that matters. Not just servers. Every laptop, every phone with corporate mail, every internet-facing box. If your tool doesn't cover an OS you run, that's a hole and you know it.

2. Hardware-backed MFA for privileged accounts this quarter. Not SMS. Not push. Start with the ten accounts that could end your week, then work outward.

3. Rebuild the patch queue around KEV. A 9.8 nobody exploits can wait behind a 7.5 that's being used in the wild right now. Automate the verification step — the part where you confirm the patch actually applied, which is where most patch programs quietly fail.

4. Restore something from backup, on a timer, every quarter. Not a file share. A critical system, from bare metal, while somebody watches the clock. If it takes three days, you just learned something worth more than the test cost.

5. Write the IR plan when nothing is on fire. Who isolates the endpoint. Who calls legal. Who decides whether to pay. Decide now, while you're calm and nobody's shouting in a conference room.

None of this is a product you buy. It's a posture you enforce, session by session, device by device, until the default answer to "can I get in?" is no and the requester has to earn it back.

The clock is 29 minutes. Spend your budget on things that actually say no, not on another dashboard that tells you yes, you were breached, about eight months ago.

Share this article:

Comments (0)

No comments yet. Be the first to comment!