Research pillar · Zero Security Theatre
Attack-and-recovery engineering
Engineering disciplines specify an outcome, instrument the system, attack the assumption, measure what happens, and improve. This pillar applies that sequence to cyber resilience and collects the evidence needed before any composite score can honestly be defined.
The question
Which measurements actually predict whether an organisation survives an attack?
Active · since 2026 · Zero Security Theatre
The intervals that decide the loss
observation
Prevention determines whether an intrusion starts. Detection, understanding, containment, and recovery determine how much it costs. Most programs report heavily on the first and thinly on the rest.
The candidate scorecard
hypothesis
These are the measurements the pillar is collecting evidence about. Inclusion here is a proposal, not a finding. Several are likely to prove weak once compared against real outcomes.
| Measure | Definition | How it is demonstrated |
|---|---|---|
| Mean time to detect | First attacker action to first accurate alert | Injected activity in production, measured against the alert record |
| Mean time to understand | Alert to a correct account of scope and path | Timeline reconstruction after exercises and real events |
| Mean time to contain | Understanding to the point spread stops | Timestamped containment actions during drills |
| Mean time to recover | Containment to validated service restoration | Timed restore into a clean environment with business sign-off |
| Demonstrated RPO | Data loss actually incurred in a tested restore | Comparison of restored state against the last known good state |
| Demonstrated RTO | Elapsed time in a tested restore, not the target | The clock on the drill |
| Blast radius | Systems and data reachable from one compromised identity | Attack-path analysis, confirmed by attempt |
| Repeat vulnerability rate | Share of findings of the same class recurring | Longitudinal finding records |
| Finding to verified remediation | Time from discovery to retested closure | Retest evidence, not ticket closure |
| Tested restoration coverage | Share of critical systems with a passed restore in period | Restore register |
| Tested containment coverage | Share of critical identities with a rehearsed containment path | Drill register |
| Machine-verifiable evidence | Share of controls with automated evidence | Evidence pipeline inventory |
A Measured Attack-and-Recovery Resilience Score
unknown
A fair comparison may eventually be possible. There is no formula yet because the underlying measures have not been validated. Publishing weights now would give guesswork a tidy number.
The open questions are which measures carry independent signal, how to normalise for size and sector, how to treat unknowns so they cannot be scored as neutral, and whether a single composite is even useful compared with a small dashboard of four or five numbers.
What would prove us wrong?
unknown
The pillar assumes these intervals are measurable, comparable, and predictive.
- Evidence that measured detection and containment times vary more with attacker sophistication than with defender capability, making cross-organisation comparison meaningless.
- Results showing that organisations optimise the measured intervals at the expense of unmeasured harm, for example containing quickly by destroying evidence needed for notification.
- Outcome data where recovery capability, not detection speed, explains nearly all the variance, which would justify collapsing much of the scorecard.
Put this to work
Research decision record
Use the question “Which measurements actually predict whether an organisation survives an attack?” on a real case and produce a record another person can challenge.
- For
- Practitioners, researchers, founders, and operating leaders.
- What you keep
- A research decision record you can review, revise, and send.
- What counts as sound
- Answers a named decision
- Separates evidence from assumptions
- Includes the strongest contrary case
- Names missing evidence
- Ends with a test, owner, and date
The result is a working analysis. Check it against source evidence and qualified judgment.
Nothing entered here is stored or sent. Review the prompt before sharing confidential, personal, patient, or privileged information.
Review the prompt
You can leave any field blank. The prompt will mark it as not provided.
If the record survives your review, send the question, evidence, unknowns, and requested next step.
Experiments for this pillar
- Measure the real detection interval
How long does it take to notice activity that a deployed control claims to detect?
- Timed restore into a clean environment
What is the demonstrated recovery time and data loss for a critical system?
- Blast radius of one ordinary identity
What can be reached from a single compromised workstation account?
Patterns and anti-patterns
Pattern
Score unknown as red
Remove the not assessed category. A control whose effect has not been demonstrated is reported as failing until it is tested, which makes the verification backlog visible to the people who fund it.
Evidence for this pillar
- NIST Cybersecurity Framework 2.0
Organises outcomes across govern, identify, protect, detect, respond, and recover. Used here as a requirement source, not as evidence of effect.
- NIST SP 800-61, computer security incident handling guide
The reference model behind the detection, containment, and recovery intervals this area measures.
- MITRE ATT&CK
The behaviour catalogue used to select techniques for detection and containment measurement.
- Operational Truth
The intended, reported, recorded, inferred, observed, and verified distinction used throughout this area.
Notes under this pillar
Design Patterns
- Measure the time between each response step
Incident counts depend on how hard an organisation looks. Detection, containment, and recovery intervals can be generated on demand and compared over time.
2026-09-15
Operating Theorys
- Put the last demonstrated RTO beside the target
A recovery objective is a statement of intent written during planning. The useful number is the one produced by the last real restore, with the date attached.
2026-09-15
- Do not publish a resilience formula yet
People often ask for one weighted score. Publishing it before the measures are validated would give an untested formula the look of certainty.
2026-09-15
