Security pros fail to identify and track the ways an environment was exploited, be it malware or human attack. Common root causes include social engineering, password guessing/cracking, unpatched software, misconfiguration, denial of service, and physical attacks. Figuring out how to stop break-ins is the ultimate objective of any defender, and understanding root causes goes a long way toward that goal. To find out what malware did, all you have to do is disassemble its code: It can only do what its instructions told it to do.”]
Source: https://www.csoonline.com/article/3005594/7-keys-to-better-risk-assessment.html