What usually causes failures
Most failures are not exotic. They are practical control gaps: unmanaged devices, patchy MFA coverage, stale patching habits, messy admin roles, missing evidence, legacy authentication still enabled, Defender misconfiguration, over-broad sharing and policies nobody owns.