Sentinel Vault
← All field notes
Cyber Leadership & Risk · January 10, 2026

Why You Will Get Hacked

The uncomfortable questions most organizations never ask until it’s too late

Not if.
When.

Before you get defensive, let’s start with questions. Real ones. The kind that don’t show up on vendor sales decks or compliance checklists.

Let’s Start With You

  • Do you believe hackers only go after big companies?
  • Do you assume your business is “too small,” “too boring,” or “not worth the effort”?
  • Do you think security is mostly an IT problem, not a leadership one?
  • Have you ever said, “We haven’t had any issues so far”?

If you answered yes to any of those, you’re already standing on the trapdoor.

Who Do You Think Hackers Are Actually Targeting?

Do you imagine hoodie-wearing geniuses manually picking victims one by one?

Or have you considered this instead:

  • Automated scanners don’t care who you are.
  • Phishing campaigns don’t know your company name.
  • Credential-stuffing attacks don’t ask how many employees you have.
  • Ransomware operators don’t verify your revenue before detonating.

So ask yourself:

  • Why would automation skip you?
  • Why would scale protect you instead of expose you?
  • Why would attackers ignore an easy target?

They won’t.

How Many Ways Could Someone Get In Right Now?

Not hypothetically. Right now.

  • How many employees reuse passwords?
  • How many inboxes have never had phishing training?
  • How many systems are one missed update away from exposure?
  • How many vendors have access you forgot about?
  • How many former employees still do?

If you don’t know the answers, attackers already have a head start.

What Are You Actually Protecting?

Let’s flip the question.

  • Is it customer data?
  • Financial records?
  • Employee information?
  • Operational continuity?
  • Your reputation?
  • Your ability to function on Monday morning?

Now ask the harder follow-up:

  • What happens if that’s gone?
  • Who calls who first?
  • Who explains it to customers?
  • Who explains it to regulators?
  • Who explains it to the board?

Silence is not a strategy.

Why “Compliance” Won’t Save You

Are you relying on:

  • A checklist?
  • An audit report?
  • A policy no one reads?
  • A cyber insurance policy you haven’t tested?

Compliance answers the question: “Did you meet the minimum?”

Attackers ask a different one: “Is this exploitable?”

Those questions rarely overlap.

When Was the Last Time You Tested Reality?

Not a tabletop exercise with polite assumptions. Reality.

  • Has anyone tried to phish your executives?
  • Has anyone attempted lateral movement inside your network?
  • Has anyone tested how fast you can actually respond?
  • Has anyone verified backups work under pressure?

If the answer is “no,” then your incident response plan is theoretical fiction.

The Uncomfortable Truth

You will get hacked because:

  • Technology changes faster than habits.
  • Humans are predictable under stress.
  • Attackers don’t need perfection, only opportunity.
  • Defense is optional. Attacks are not.

Because doing nothing feels safe right up until it isn’t.

The Better Question

“How do we stop every attack?”

It’s:

  • How quickly can we detect?
  • How decisively can we respond?
  • How much damage are we willing to tolerate?
  • How prepared are we to lead when it happens?

Because the breach isn’t the failure.
Being unprepared is.


What Law Enforcement Sees After the Breach

By the time law enforcement gets involved, the breach is no longer theoretical. It’s an aftermath.

The First Question Everyone Asks

“How did this happen?”
“We don’t know.”

And almost every time, the answer (when it’s discovered) starts with one of these:

  • A phishing email that “looked legitimate”
  • A reused password found in a breach dump
  • A forgotten remote access account
  • A system that “was scheduled to be patched”
  • A vendor connection no one remembered approving

The attack itself is rarely sophisticated.
The environment usually is.

The Quiet Conclusion No One Says Out Loud

When law enforcement arrives, the question is no longer why the attack happened.

It’s why it wasn’t harder.

Frequently asked
Are hackers only a threat to big companies?
No, and assuming otherwise is the trap. Automated scanners, phishing campaigns, credential-stuffing tools, and ransomware do not check your company name, headcount, or revenue before they hit you. Scale does not protect small targets, it exposes them, because automation looks for anything easy rather than picking victims by hand. Too small or too boring is not a defense.
Is 'we haven't had any issues so far' a sign we are secure?
No, it is a sign you may not have looked. Not having noticed a problem is different from not having one, and it often means no one has tested reality: whether executives can be phished, whether an attacker could move laterally, how fast you could actually respond, and whether your backups work under pressure. If those have never been tested, your incident response plan is theoretical.
Doesn't compliance mean we are protected?
Compliance answers a different question than an attacker asks. A checklist or audit confirms whether you met the minimum, while an attacker asks whether this is exploitable. Those rarely overlap. A policy no one reads and an untested cyber-insurance policy do not stop an intrusion. Compliance is a floor, not a defense.
What questions should a leader actually be asking about cyber risk?
How many ways could someone get in right now: how many employees reuse passwords, how many inboxes have never had phishing training, how many systems are one missed update from exposure, and how many vendors or former employees still have access. Then: what are you actually protecting, and what happens if it is gone on Monday morning, and who calls whom first. If you cannot answer, attackers already have a head start.
About the author
Pete Hish, Sentinel Vault founder
Taught by Pete Hish · Founder

A working cyber-fraud supervisor, not a vendor consultant.

US Army veteran. Active sergeant supervising a cyber and fraud investigations team at a large Southern California law-enforcement agency. Ten-plus years inside the cases that hit small businesses, families, and public-sector agencies first. The training is shaped by what actually goes wrong, not what vendor decks predict.

Certified Cybersecurity SpecialistCertified Cyber Fraud SpecialistCalifornia POST Certified Instructor
Hacked or Hardened? book cover
Prefer the long-form version?

Hacked or Hardened? covers these patterns end-to-end: the four ways small businesses get hit, what to fix first, and how to lead through an incident.

Keep pulling the thread
The fiction version

Fleeced Nation is a crime series about industrialized fraud, from the elder-fraud call centers to the quiet machinery that turns dirty cash clean. Same terrain as the case files, minus the parts a report will not hold. I started it as fiction. The case files keep publishing the sequel.

fleecednation.com ↗
Related field notes
Next step

Want this kind of analysis for your team?

A 2–4 hour cyber risk briefing: the threats specific to your business, the controls that actually pull their weight, and a 90-day action plan.