I hate when security folks say "attackers only have to win once, defenders have to win every time" because it's flawed thinking.
Thanks @haroonmeer for this: "Actually, an attacker can win everywhere and as a defender you only have to find them once"https://youtu.be/Wqww0BRIX5U
I suppose it depends on what your definition of “win” is. A single compromise might be a “win” which can be detected by blue team within time. Or it could be “I’ve been on your network for years without you noticing and left of my own terms”. Ymmv