The defender must be right every single time, and the attacker right only once.
Until the attacker has initial access.
Then the attacker needs to be right every single time.