Most security programs still measure success by counting blocked attacks. At Cloud Security LIVE 2026, Ariel Panas, co-founder at Mediga, and Roee, field CTO at Orca, made the case for a different metric entirely. Prevention will never reach zero probability, and both of them were comfortable saying so out loud. What decides the outcome, once an attacker is already inside with a legitimate credential, is how fast you spot them and how honestly you have prepared the board for the day it happens.
What Is Zero Impact Cloud Security and Why Is It Better Than Zero Breach?
Panas coined the term “zero impact” to describe a shift away from prevention-only thinking. Attackers with legitimate credentials will eventually get in. The question that matters is whether they can do any damage once they’re inside.
We don’t really need to care about the attack as long as there is no impact to the business.”
— Ariel Parnes, Co-Founder, Mitiga
Patching vulnerabilities and fixing misconfigurations still make an attacker’s job harder, and Panas was clear about the limit. Prevention alone cannot close the gap between the volume of exposure most organizations carry and the speed at which attackers move through it.
How Did Attackers Turn One Legitimate Salesforce Login Into a Ransomware Incident?
Panas illustrated the concept with a real incident at a Fortune 500 company. The threat actor group ShinyHunters impersonated an IT operator, called a sales team leader, and asked for a five-digit code showing on the employee’s screen. That code came from the device authorization grant process, the same login flow used to sign into streaming apps on a hotel TV.
The employee handed it over. With one valid credential the attacker was inside Salesforce, and within minutes was querying records and pulling data. The instance happened to store customer support tickets that contained AWS credentials, so the attacker used those to move laterally into AWS, where they stole data from S3 buckets and deployed ransomware.
“The only way to truly combat these situations where attackers move fast with legitimate access is by focusing on the impact of the attack rather than the actual attack.”
— Ariel Parnes, Co-Founder, Mitiga
It took the security team days to piece together what happened, and that was with strong tools, continuous vulnerability scanning, and capable partners already in place.
Should Security Leaders Focus on Prevention or Detection and Response?
Days to reconstruct an attack that had run in minutes. That gap is where Roee took the conversation next: if prevention cannot stop a determined attacker, what is the honest answer? Instead of asking whether a breach will happen, Panas reframed the question to whether the team can detect unusual behavior fast enough to stop it before it causes damage.
Roee offered a related example from his own experience, working with a data protection team fixated on preventing any breach involving personal data, including from nation-state actors.
“That might be very costly. Even if we had ten times that budget, we won’t be able to prevent a nation-state attack if they targeted our organization.”
— Roee Shohat, Field CTO, Orca
The fix was not more prevention spend. It was shifting the conversation toward risk and probability, and toward the organization’s ability to respond.
How Does AI Accelerate Both Cyber Attackers and Security Defenders?
If detection speed is the new battleground, AI is what is raising the stakes on both sides of it. Panas summed up its effect in three words: faster, better, and more. Attackers can move through credential harvesting, authentication, lateral movement, and exfiltration in seconds instead of relying on manual operators. AI also sharpens social engineering, letting attackers research a target and tailor an approach with far more precision.
“There is no question here, leveraging AI is not an advantage, it’s a necessity.”
— Ariel Parnes, Co-Founder, Mitiga
Defenders get the same speed and scale advantage, putting AI to work in the SOC for detection, triage, and analysis, and increasingly for response. Roee added a practical example from his own testing. A newly published vulnerability with no existing proof-of-concept code yet can still be weaponized quickly once an AI model is given the right instructions to build the exploit.
How Can CISOs Effectively Communicate Cyber Risk to Board Members?
That speed is exactly why the board conversation has to change. Panas argued that CISOs carry the responsibility of changing how boards think about security, moving away from counting blocked attacks and toward a language that boards already understand: risk as the combination of probability and impact.
“This is the type of discussion that I strongly recommend CISOs to have with the boards. They lead to a more constructive and a more relevant type of strategy.”
— Ariel Parnes, Co-Founder, Mitiga
That means walking the board through an uncomfortable truth: no amount of patching lowers breach probability to zero. The more productive conversation covers the cost of mitigation, the compensating controls available, and the choice to accept, manage, or transfer whatever risk is left.
Where This Leaves Security Teams
The session closed on consistent advice: stop selling prevention as a guarantee, invest in the ability to detect and respond at the same speed attackers now operate at, and bring the board a risk conversation instead of a scorecard.
If your organization is rethinking how it measures readiness against identity-based attacks, Orca can help. Get a demo.
Zero Impact & Cloud Security LIVE 2026: Frequently Asked Questions
What percentage of attacks today don’t involve malware at all?
Panas cited a figure of 80%, meaning most attacks have no malware signature for traditional tools to catch. That is a big part of why prevention-only strategies fall short against identity-based intrusions.
What is a “compensating control,” and how did one CISO use it to manage a $100 million risk exposure?
In a separate case Panas described, a Fortune 200 company found 12 risky configurations across two SaaS applications carrying a quantified $100 million risk, with a two-year timeline to fix. Rather than wait, the CISO deployed continuous monitoring across those two applications as a compensating control, cutting the risk without closing every gap first.
What are the three visibility gaps that leave organizations exposed to fast-moving attacks?
Panas named coverage (multi-cloud and SaaS environments with only partial log collection), retention (short log history that limits anomaly detection and lets attackers dwell undetected), and normalization (logs from different tools that can’t be cross-correlated quickly enough).
Why does short log retention help attackers rather than defenders?
Attackers know that many organizations only retain logs for a few weeks, so they deliberately slow down and dwell inside an environment, operating under the radar until that retention window passes.
Why is normalizing logs across tools harder than just collecting them?
Different platforms log the same type of event differently. Panas pointed out that Salesforce, GitHub, and Office 365 all structure identity and activity logs in their own way, which slows down cross-correlation and gives attackers more time to act before security teams connect the dots.
