Attack Chain
An attack chain describes the sequence of stages an attacker moves through to carry out a successful cyberattack, from early reconnaissance to breaching systems and ultimately achieving their goal, such as stealing data. Understanding these stages helps defenders identify and interrupt an attack before it succeeds. This is a security concept, not an insurance coverage term.
The attack chain (also referred to as an attack path, and closely associated with the Cyber Kill Chain framework) is a model describing the ordered stages a threat actor executes to complete an intrusion. As articulated in frameworks such as Lockheed Martin's Cyber Kill Chain, adapted from the military concept of a kill chain and applied within an intelligence-driven defense model, these stages span activities from initial reconnaissance through breach and data exfiltration. The framework is used to identify, prevent, and disrupt intrusion activity by breaking an attack into discrete phases at which defensive controls can be applied. Note that 'attack chain' and 'attack path' are used broadly across cybersecurity contexts (including in environments such as Kubernetes), while 'Cyber Kill Chain' refers specifically to the Lockheed Martin framework; usage and stage definitions may vary by source. This is a security and threat-analysis concept and is distinct from insurance policy terms such as coverage triggers, exclusions, or retentions.
Why it matters
The attack chain concept matters because it reframes a cyberattack not as a single event but as a sequence of stages, each of which presents an opportunity for defenders to detect, disrupt, or halt the intrusion before the attacker achieves their objective. By breaking an attack into discrete phases, from early reconnaissance through breach and data exfiltration, security teams can map defensive controls to specific points in the sequence rather than relying on a single point of protection. Interrupting the chain at an earlier stage generally limits the damage that ultimately materializes.
For those working at the intersection of cybersecurity and insurance, the attack chain is a useful analytical lens but an important boundary must be kept in view: it is a security and threat-analysis concept, not an insurance coverage term. Understanding how an attacker progressed through the stages of an intrusion can inform incident investigation, root-cause analysis, and post-incident remediation, all of which may become relevant to a claim. However, whether any resulting loss is covered depends on the specific policy wording, endorsements, exclusions, and conditions, not on the attack chain model itself. The framework describes how an attack unfolds; it does not determine coverage.
Because the attack chain describes the mechanics of an intrusion, it also underscores a limitation of risk transfer: insurance does not reduce the likelihood that an attacker moves through these stages and does not, by itself, disrupt any phase of an attack. Mapping and interrupting the attack chain is a mitigation activity, distinct from transferring residual financial risk through a policy. Both may form part of an organization's overall approach, but they operate on different parts of the risk equation.
Who it's relevant to
Inside Attack Chain
Common questions
Answers to the questions practitioners most commonly ask about Attack Chain.
