Every offensive has a high-water mark — a moment when it is as strong as it will ever be, and after which it can only weaken. Clausewitz named it the culminating point, and treated finding it as the central problem of both attack and defence. A ransomware crew that detonates encryption across a network has reached theirs. The question that decides the incident is whether the defender understood, before that moment arrived, that the attacker was already inside and already past the point of safety.
Military foundation
Clausewitz observed that an attack does not grow stronger the longer it runs. It consumes itself — supply lines stretch, troops tire, the defender's territory works against the invader. There is a point at which the offensive's remaining strength exactly equals the resistance in front of it, and one step beyond it the attacker is weaker than the defender. That is the culminating point. The art, for the attacker, is to achieve the decisive result before reaching it. The art, for the defender, is to recognise where it lies and to strike in the window where the offensive has overextended but not yet won.
The deeper insight is that the culminating point is reached quietly. An army does not announce that it has overextended; it simply finds, one morning, that it can no longer advance. The commander who waits for an obvious signal has already missed it. The defender's advantage is knowledge of the timeline — understanding that every additional step the attacker takes deeper into hostile ground is a step closer to vulnerability.
Cyber application
A ransomware operation is an offensive with a long, quiet approach march and one loud, decisive act. Initial access, reconnaissance, credential theft, lateral movement, privilege escalation, the staging of exfiltration — all of it happens in the dwell time, the days or hours an intruder spends inside before the payload fires. Encryption is the culminating point: the single irreversible blow the entire operation exists to deliver. Everything before it is the attacker advancing across your ground, getting stronger; everything after it is recovery, not defence.
This reframes where the contest is actually decided. Industry incident data has shown median dwell times falling from months to days as ransomware-as-a-service crews industrialise the approach march — but days is still a window, and a window is all the defence needs. During dwell time the attacker is committed, exposed, and generating signal: anomalous lateral movement, mass credential use, the quiet disabling of backups and shadow copies, reconnaissance against file shares. These map onto MITRE ATT&CK across lateral movement, defence evasion, and impact, and they are loudest precisely when the operator is overextending — touching too many hosts, escalating too fast, reaching for the backups that tell you encryption is next.
The defender who treats the encryption note as the start of the incident has met the offensive at its strongest. The defender who reads the approach march meets it past its culminating point — committed, noisy, and not yet finished. The same overextension that makes the attack powerful makes it visible. The whole discipline is to act inside that window rather than after it closes.
What you practise
In the range this becomes a race against a clock the attacker controls. On the offensive side you run the approach march and learn how little noise it takes to give yourself away — how each extra host, each backup you reach for, each privilege you grab, shortens your own runway. On the defensive side you practise the harder discipline: reading the quiet phase, recognising the shape of an offensive that has committed but not yet culminated, and striking in the window rather than waiting for the obvious blow. The AI Coach reconstructs the timeline afterwards and marks the exact moment the attacker passed their culminating point — the moment you could have won, whether or not you took it. It is the same instinct the OODA loop trains, read through Clausewitz instead of Boyd.
The three doctrine layers are all in the room: the strategy of timing the counter-stroke (WAR), the craft of detecting an offensive mid-advance (Ethical Hacking), and the real ransomware economy whose tempo sets the clock (Cyber Crime). The habit you build is Clausewitz's own — to stop measuring an attack by how strong it looks and start measuring it by how close it is to breaking. Against an adversary whose whole plan is one decisive blow, the defender who knows where the high-water mark lies is the one still standing on dry ground.