Initial access
Every intrusion starts somewhere, and the routes are a short and stable list.
Phishing, stolen credentials, an unpatched internet-facing service, a supplier, or something exposed that should not have been. The list barely changes year to year, which is unusually useful: a small number of defences cover most of the ways anybody gets in at all.
Checked against the primary source.
