
07.07.2026
The greatest risks for companies rarely arise from spectacular hacker attacks, but rather from everyday vulnerabilities that attackers strategically combine.
Cyberattacks rarely begin as spectacularly as many companies suspect. While highly complex hacking attacks or zero-day exploits are often discussed, practice shows a different picture: attackers usually exploit known vulnerabilities, inadequately secured access points, or human error to gain access to company networks.
Fabian Mosch, Head of Offensive Services at r-tec, part of the accompio group of companies, experiences precisely this reality daily in penetration tests and attack simulations. In the interview, he provides insights into typical attack vectors, recurring vulnerabilities, and explains why many security measures, while sensible, are not sufficient on their own.
Cyberattacks rarely begin as spectacularly as many companies suspect. In offensive security projects, it repeatedly becomes apparent that phishing campaigns, weak passwords, or a lack of multi-factor authentication often form the first step of a successful attack. At the same time, many companies focus on individual risk areas and lose sight of other potential attack vectors.
This is exactly the reality Fabian Mosch, Head of Offensive Services at r-tec as part of the accompio group of companies, experiences daily in Penetration testing and attack simulations. In the interview, he provides insight into typical attack vectors, recurring vulnerabilities, and explains why many security measures, while sensible, are not sufficient on their own.
Find out which attack vectors Fabian Mosch repeatedly observes in penetration tests, which vulnerabilities companies often underestimate, and how risks can be specifically reduced with offensive security in the full video interview.
An attacker rarely looks for a single critical vulnerability. Instead, they combine several smaller weaknesses.
An insecure password, an inadequately protected VPN connection, or an inconspicuous misconfiguration are often enough to gradually spread further within the corporate network. It is precisely this chain of different vulnerabilities that makes many attacks so successful.
That's why it's not enough to regularly check individual systems. The crucial question is which attack paths emerge across different systems.
Identities are among the most important protected assets in modern IT security.
A large proportion of modern attacks today target user accounts and permissions, rather than individual servers. Weak passwords, a lack of multi-factor authentication, or overly extensive permissions frequently allow attackers to gain widespread access to company resources within a short period. Particularly cloud services, VPN access, or collaboration platforms offer attractive entry points for this.
Many companies invest significant sums in modern security solutions and overlook everyday risks.
Historically grown configurations, default permissions, inadequately maintained systems, or outdated software versions often provide attackers with significantly easier routes than spectacular security vulnerabilities. It becomes particularly critical when several of these weaknesses combine.
Classical vulnerability scans provide valuable insights into technical risks. A Penetration testing or a realistic attack simulation goes significantly further: Here, the effects of different vulnerabilities in conjunction are examined and whether a successful attack can actually be developed from them.
It is precisely this perspective that enables companies to prioritise their security measures based on actual risk rather than individual findings.
The three common offensive security approaches differ significantly in scope and assertiveness.
| Approach | What is being checked | Result |
| Vulnerability scan | Individual systems for known technical vulnerabilities | List of individual technical findings |
| Penetration testing | Selected systems and their interaction | Concrete, demonstrable attack paths |
| Attack simulationRed Teaming) | Total infrastructure including people and processes | Realistic sequence of a full attack |
„In our attack simulations, we think and act like real attackers. It is precisely through this that we find the vulnerabilities that classic tests often overlook.“
— Fabian Mosch, Head of Offensive Services at r-tec (part of the accompio group)
Technology is only ever one component of an effective security strategy.
Fabian Mosch repeatedly encounters the assumption that the use of a particular manufacturer or a modern security solution automatically leads to a high level of security.
In practice, effectiveness depends significantly on how solutions are configured, integrated and operated. Even modern endpoint detection or antivirus solutions can be circumvented if basic security measures are missing or attack vectors are not viewed holistically.
Cloud platforms, remote work, and the increasing use of artificial intelligence are continuously changing the landscape of attack vectors.
As companies modernise their infrastructure, new attack surfaces emerge. Furthermore, attackers are increasingly using AI to identify vulnerabilities more quickly or to prepare attacks more efficiently. This makes it all the more important to regularly adapt security measures to the actual threat situation.

accompio helps companies to analyse and assess their security structures. We identify vulnerabilities before they can be exploited.
Security vulnerabilities rarely arise from single spectacular errors. Rather, the decisive factor is the combination of technical weaknesses, organisational failures, and human factors.
Companies that consistently align their security strategy with realistic attack vectors and regularly review them lay the foundation for effective protection. Cyber Security. Offensive Security provides these insights preventatively, even before a potential security incident.

Fabian Mosch is a security expert at r-tec (part of the accompio group) and is intimately familiar with hacker behaviour and the security vulnerabilities they exploit.
The most common entry points are phishing, weak or reused passwords, lack of multi-factor authentication, and publicly accessible systems with known vulnerabilities. In many cases, attackers combine several of these factors rather than exploiting a single security loophole.
After initial access, attackers typically attempt to escalate their privileges, compromise further systems, and gain access to sensitive data or administrator accounts. The aim is to spread throughout the infrastructure as unnoticed as possible.
Vulnerability scanners detect known technical vulnerabilities. However, they usually don't show how multiple minor vulnerabilities can be combined. It is precisely these attack paths that are investigated in penetration tests or realistic attack simulations.
Identities are among the most important targets for attacks today. Weak passwords or a lack of multi-factor authentication often enable attackers to gain direct access to corporate networks or cloud services. Effective identity management is therefore one of the most important protective measures.
Penetration tests simulate the methods of real attackers. They not only reveal individual vulnerabilities but also make visible which attack paths would actually be successful and what impact these would have on the company.
A automated penetration test simulates the actions of a real attacker on selected systems and their interplay. Instead of looking at individual vulnerabilities in isolation, the test checks whether several minor weaknesses can be combined into an actual attack path. manual penetration tests IT security experts act and bring their experience from IT projects to test various attack vectors. This provides companies with a risk-based foundation for prioritising their security measures.
Historically established permissions, default configurations, inadequately maintained systems, and outdated software versions are often underestimated. These everyday misconfigurations often open up simpler pathways for attackers in practice than complex, spectacular security vulnerabilities, especially when several of them work together.
Particularly effective are consistent patch management, strong authentication with multi-factor authentication, regular security reviews, a well-thought-out role and authorisation concept, as well as employee awareness of phishing and social engineering.
The most reliable way to achieve this is through offensive security approaches such as penetration testing or red teaming. These simulate real attack scenarios to identify and specifically close vulnerabilities, misconfigurations, and possible attack paths early on.

Arrange an initial consultation