Inside The Next Breach

CRYSTAL MAZE CYBER-SECURITY EXPERIENCE

Read the Dispatch

Vol. VII

Special Edition

July 2026

Inside

the

NexT Breach

CRYSTAL MAZE CYBER-SECURITY EXPERIENCE

Crystal Maze, London

Syscomm · Strategic Network Solutions

Free Admission

Back Into the Maze, This Time in London

For a step-by-step look at three real attacks, an honest read on what AI has changed, and the four questions every organisation should be able to answer.

After the success of “Inside the Breach” in Manchester, Syscomm brought the format back to the legendary Crystal Maze, this time in London, for a follow-up built around a simple question: if organisations already own the security tools, why do breaches keep happening?

The morning belonged to Mark Wainwright and Chris Tyler, who had come with a case to make and the evidence to make it. Chris walked the room through three genuine incidents, step by step, in the order the attacker took them: where they got in, what they touched first, and how long they had before anyone noticed. The answer to that last question, it turns out, is twenty-seven seconds. That number did a good deal of work in the room.

Where breaches actually begin

Mark Wainwright opened by clearing the table. Not artificial intelligence. Not nation-state actors. Not zero-days. Whatever the headlines suggest, the incidents Syscomm gets called into rarely begin with anything exotic. They begin with three recurring root causes, all of them ordinary, all of them sitting inside systems the organisation already owns, already pays for, and in most cases believes are working. The rest of the session was spent on the harder part: how each one hides in plain sight, why the usual reporting misses them, and what it actually takes to demonstrate that you do not have them.

The next breach won't be because of AI. It'll be because there's some configuration which isn't correct, some visibility issue, or because nobody validated what they had.

What the three attacks had in common

Laid side by side, the three shared five patterns. One concerned backups that existed, were dutifully maintained, and had never once been tested against a real recovery. Another concerned alerts that fired exactly as designed and were read by nobody, because it was the middle of the night. A third involved a supplier who had done nothing wrong at all.

The uncomfortable thread running through all three: not one of those organisations lacked security technology. In every case, the tools needed to stop what happened were already installed and already licensed.

01

The tools are already there

Failures came from configuration, oversight, and monitoring, not a lack of security technology.

02

Attackers used trusted tools

Legitimate software was abused to avoid detection.

03

Backups weren’t enough

They existed, but hadn’t been properly tested for recovery.

04

Warnings were missed

Alerts were generated but not acted on, especially overnight.

The unsinkable ship

Which raises the obvious question: if the protection was already there, why did none of it hold? To answer it, Chris reached for a ship.

The Titanic carried the advanced safety measures of her day and a hull divided into watertight compartments, each designed to seal off flooding before it could spread. What sank her was not an absence of protection. It was that a single iceberg breached more compartments than the design had anticipated, and once the water was moving between them, every clever feature on board became irrelevant in turn.

Chris used the ship to explain what the word “protected” is really worth once an attacker finds one weakness and starts moving. It rearranged how a fair few people in that room think about their own network diagram. It is on page one of the recap.

Inside the Breach · Vol. I · Crystal Maze Manchester · November 2025

Syscomm

Next Upcoming Event...

10

th

Sept 2026

Webinar

Keeping the supply chain moving: Cyber resilience in transport and logistics

Is your cyber investment actually protecting the business? A free hour for transport and logistics leaders on breach risk, real costs and recovery.

Read Next Dispatch

Vol. II - Syscomm at BETT 2026 - ExCel London