← All posts post

The Click Is Just the Surface

Root CauseOctober 2026 · 1 min read

"The user clicked a phishing link" is a symptom, not a root cause.

Walk a typical account compromise backward and the real questions show up:

  • Why did the email get delivered? Auth results, filtering verdict, policy exceptions
  • Why did the credentials work? MFA coverage, legacy protocols, session handling
  • Why did nobody notice? Forwarding rules, sign-in anomalies, alerts that fired and got ignored
  • Why was the damage possible? Permissions, payment processes, approval steps

Each answer is a different fix. Training the user fixes one of them, maybe.

Root cause analysis is how you turn one bad day into a control that keeps working. Stop at the click and you'll be investigating the same incident again next quarter.