Attack-path reconstruction
Maintaining a current map of how an ordinary foothold reaches valuable systems, updated as identities and configurations change.
Research pillar · Zero Security Theatre
AI makes some attacks cheaper and gives defenders more ways to watch systems continuously. This pillar asks which neglected defensive jobs machines can now do, and which decisions still need a person.
The question
Which defensive work should machines carry, and which decisions must remain with people?
Active · since 2026 · Zero Security Theatre
recommendation
Machines should increasingly do the remembering, the monitoring, the correlation, the testing, the evidence gathering, and the routine enforcement. People should make the decisions that carry consequence: isolate a system, disclose an incident, notify customers, invoke counsel, halt production, or accept a risk.
Models will make mistakes. Some mistakes can be caught on the next pass. An automated disclosure sent in error cannot be recalled, so a person keeps that decision.
hypothesis
These jobs were sampled, scheduled, or skipped because nobody could watch them all the time. Machines may now run them continuously. The work still has to show that its error rate is acceptable.
Maintaining a current map of how an ordinary foothold reaches valuable systems, updated as identities and configurations change.
Assembling a defensible account of what happened from logs across systems, with each statement tied to its source record.
Repeatedly exercising controls against the behaviours they claim to stop, rather than testing once a year.
Continuous scanning of repositories, images, logs, and third-party surfaces for exposed material, with automated revocation paths.
Connecting a written requirement to the specific operational query that demonstrates it, and flagging requirements with no source.
Generating varied, current scenarios rather than reusing a template, then measuring behaviour rather than completion.
inference
Every criticism this area makes of security products applies to AI security products with more force, because the output is fluent and therefore harder to doubt. A model that summarises alerts convincingly while missing the one that mattered produces confidence without resilience.
The test stays the same: what bad outcome does this prevent, detect, contain, recover from, or prove? Judge an AI capability by the same evidence as any other control.
unknown
The pillar assumes machine-carried continuous defensive work improves measured outcomes.
Put this to work
Use the question “Which defensive work should machines carry, and which decisions must remain with people?” on a real case and produce a record another person can challenge.
The result is a working analysis. Check it against source evidence and qualified judgment.
Nothing entered here is stored or sent. Review the prompt before sharing confidential, personal, patient, or privileged information.
You can leave any field blank. The prompt will mark it as not provided.
If the record survives your review, send the question, evidence, unknowns, and requested next step.
Pattern
Machine prepares, human decides
Automate correlation, reconstruction, testing, and evidence assembly. Keep isolation, disclosure, notification, and risk acceptance with named people, and let authority move only as measured performance supports it.
Anti-pattern
Accepting a fluent AI report as an assessment
A polished report can sound surer than the facts allow. Require a source record for every generated claim so the reader can check it.
Relevant as AI components enter both the defensive stack and the attack surface.
Used when assessing AI components in defensive workflows, where the same evidence standard applies.
Design Patterns
Machines can watch systems and prepare evidence. People remain responsible for decisions that cannot be reversed.
2026-09-15
Operating Theorys
A generated security assessment reads better than a human one and is harder to doubt. Readability and correctness are unrelated properties.
2026-09-15
Generated, varied, current scenarios delivered continuously and measured behaviourally are a plausible substitute for a yearly module. Plausible is not proven.
2026-09-15