What does the Cyber Kill Chain's break-one-link claim actually assert?
answer
- an argument, not a diagram
- seven things must all be true
- which side needs to win every step
- one broken link defeats the attempt
- the premise: the path starts at the start
basics
~20 sThat an intrusion succeeds only if it completes all seven stages in order, so removing any one stage defeats the whole attempt. It inverts the usual asymmetry: the intruder must win every link, not just one.
solid answer
~50 sThe Cyber Kill Chain, published by Lockheed Martin in 2011, describes an intrusion as seven ordered stages: Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command and Control, and Actions on Objectives. The model's real content is not the list, it is an **interdiction argument**: because the intruder has to traverse every stage in sequence to reach their objective, making any single stage fail is enough to defeat that attempt. That was the novel part in 2011 — it inverted the folk asymmetry that "the attacker only has to be right once". Two things follow. First, breaking a link defeats a *path*, not a person: the crew rebuilds the broken link and tries again, which is why the argument is about raising cost across repeat attempts. Second, the claim carries a premise — that the path really does traverse those links, in that order, starting at Reconnaissance.
go deeper
Be ready to state the seven stages in order and, more importantly, the one-sentence claim they exist to support. Practise saying the claim before the list, because reciting the list alone reads as memorisation.
An interviewer expects you to explain why the argument works — it is a conjunction, so negating one term is enough — and to name the premise it rests on, that the path traverses those links at all.
Show you can attribute a real control class to a stage and say which plausible intrusion paths that stage appears on. Saying a control 'helps with the kill chain' without naming the stage or the path is what gets marked down.
Own the framing question: the chain is one narrative standard among several, and standardising a whole organisation's reporting on it buys comparability at the cost of paths it cannot describe. Be able to say what you would keep it for.
## Where the claim comes from The Cyber Kill Chain was published by Lockheed Martin researchers in 2011, in a paper on intelligence-driven defence. It borrows the military idea of a kill chain — a sequence of steps an attack must complete — and applies it to computer intrusions. Its seven stages, in order, are: 1. **Reconnaissance** — researching the target: people, addresses, exposed services. 2. **Weaponization** — pairing something that executes with something that carries it, e.g. building a malicious document. 3. **Delivery** — getting that thing to the target: mail, web, removable media. 4. **Exploitation** — triggering it, typically against a software or human weakness, so code runs. 5. **Installation** — establishing something that survives, so access does not depend on repeating steps 3 and 4. 6. **Command and Control** — opening a channel back, so the intruder can issue instructions. 7. **Actions on Objectives** — finally doing the thing they came for. ## The claim, stated precisely People quote the stage list and think the list *is* the model. It is not. The stage list is scaffolding for one argument, and interviewers are listening for the argument: > An intrusion of this shape succeeds only if **every** stage completes, in order. Therefore making **any one** stage fail defeats the whole attempt. That is a claim about a conjunction. Seven things must all be true; negate one and the conjunction is false. It is why the model was influential: before it, the received wisdom was that the person attacking needs to succeed once while the people defending must succeed every time. The kill chain flips that for a single intrusion attempt — the intruder needs seven consecutive successes on one path, and one broken link is enough. ## What "breaking a link" means Breaking a link means arranging that a stage cannot complete. It is deliberately abstract about how: the original framing enumerated actions that *deny, degrade, disrupt, deceive* or *destroy* an intruder's ability to finish a stage. Stripping executable attachments attacks Delivery. Removing the vulnerable code attacks Exploitation. Preventing an unsigned binary from persisting attacks Installation. The model does not tell you which control class to buy; it tells you that whatever you buy should be attributable to a stage, and that a control which touches no stage on a plausible path buys you nothing. ## What the claim does *not* say Three misreadings are common enough to be worth naming. **It does not say the intruder is finished.** Breaking a link defeats an attempt. A crew that wanted your estate yesterday still wants it today; they rebuild the link that failed and run the path again. The original argument accounted for this — its value came from the fact that reused elements of the path are expensive to change, so each broken link taxes the next attempt. The claim is economic, not terminal. **It does not predict behaviour.** The chain is a narrative frame, not a forecast. It says an intrusion of the described shape has this structure; it does not say what a particular crew will do next, and it names no specific techniques. **It is not universal, and this is the important one.** The conjunction argument only bites on links the path actually traverses. The model was written in, and for, an era in which essentially every intrusion worth writing about began with reconnaissance and arrived by delivering something that had to be exploited to run. If a path enters halfway along — because the position was bought, or already held for a legitimate reason — then stages one through four were never traversed by that party at all. There is nothing to break, so the interdiction argument makes no promise about that path. The model is not thereby wrong; its **domain of validity** is narrower than the way it is usually quoted. ## How to say this in an interview Lead with the argument, not the list. "The chain's claim is that an intrusion has to clear all seven stages in order, so one broken stage defeats the attempt — that inverts the asymmetry people assume. The premise is that the path really starts at the beginning, which is a claim about 2011-style delivery intrusions, and it is the premise that fails first on a modern path." That answer shows you know the seven stages without reciting them, which is what the question is really testing.
- Why was that asymmetry claim considered novel when it was published?The prevailing framing was that an intruder only has to be right once while the people protecting an estate must be right every time, which makes defence look hopeless. The kill chain reframes a single intrusion as a conjunction of seven consecutive successes, so the person attacking now needs to be right seven times in a row and one interdiction is sufficient for that attempt.
- Does breaking a link put the adversary out of business?No. It defeats one path. A motivated crew rebuilds the failed link and retries, so the honest version of the claim is economic: each break forces them to change something, and the elements that are expensive to change are the ones worth attacking. Treating a broken link as permanent removal is the most common overreach in quoting the model.
- What premise does the break-one-link claim quietly depend on?That the path being argued about actually traverses the earlier links, in order, beginning at Reconnaissance. The conjunction argument only has force over stages the intrusion genuinely needs. If a path enters mid-sequence, the earlier links were never traversed by that party, so breaking them removes nothing from it.
A relay race where every runner must finish their leg: drop the baton once and the team does not place, however fast the other six ran.
saying these in an interview costs you the question
- Recites the seven stages and stops, never stating the claim
- Says the model predicts an intruder's next move
- Thinks a broken link removes the adversary permanently
- Treats the chain as a list of malware categories
- Claims every intrusion must begin at Reconnaissance