Research pillar · Zero Security Theatre

Attack-and-recovery engineering

Engineering disciplines specify an outcome, instrument the system, attack the assumption, measure what happens, and improve. This pillar applies that sequence to cyber resilience and collects the evidence needed before any composite score can honestly be defined.

The question

Which measurements actually predict whether an organisation survives an attack?

Active · since 2026 · Zero Security Theatre

The intervals that decide the loss

observation

Prevention determines whether an intrusion starts. Detection, understanding, containment, and recovery determine how much it costs. Most programs report heavily on the first and thinly on the rest.

The clock an attack actually runs onAn intrusion moves from first action through detection, understanding, containment, recovery, and verification. Each interval can be measured and tested.Intrusionfirst attacker actionDetectsomething is wrongUnderstandscope and pathContainspread stopsRecoverservice restoredVerifycheck that the fix held
The time spent at each step helps determine the size of the loss.

The candidate scorecard

hypothesis

These are the measurements the pillar is collecting evidence about. Inclusion here is a proposal, not a finding. Several are likely to prove weak once compared against real outcomes.

MeasureDefinitionHow it is demonstrated
Mean time to detectFirst attacker action to first accurate alertInjected activity in production, measured against the alert record
Mean time to understandAlert to a correct account of scope and pathTimeline reconstruction after exercises and real events
Mean time to containUnderstanding to the point spread stopsTimestamped containment actions during drills
Mean time to recoverContainment to validated service restorationTimed restore into a clean environment with business sign-off
Demonstrated RPOData loss actually incurred in a tested restoreComparison of restored state against the last known good state
Demonstrated RTOElapsed time in a tested restore, not the targetThe clock on the drill
Blast radiusSystems and data reachable from one compromised identityAttack-path analysis, confirmed by attempt
Repeat vulnerability rateShare of findings of the same class recurringLongitudinal finding records
Finding to verified remediationTime from discovery to retested closureRetest evidence, not ticket closure
Tested restoration coverageShare of critical systems with a passed restore in periodRestore register
Tested containment coverageShare of critical identities with a rehearsed containment pathDrill register
Machine-verifiable evidenceShare of controls with automated evidenceEvidence pipeline inventory
Candidate measures under study. No weighting is proposed yet.

A Measured Attack-and-Recovery Resilience Score

unknown

A fair comparison may eventually be possible. There is no formula yet because the underlying measures have not been validated. Publishing weights now would give guesswork a tidy number.

The open questions are which measures carry independent signal, how to normalise for size and sector, how to treat unknowns so they cannot be scored as neutral, and whether a single composite is even useful compared with a small dashboard of four or five numbers.

Measures that may belong in a resilience scoreThe research is testing detection time, containment time, recovery, identity reach, repeated findings, and the share of controls checked by machines. No weights have been set.Tested resilienceDetectiontime to noticeContainmenttime to stop spreadRecoverydemonstrated RTO and RPOBlast radiusreach of one identityDurabilityrecurrence of findingsEvidencemachine-verifiable share
Gather real results before deciding how to combine them.

What would prove us wrong?

unknown

The pillar assumes these intervals are measurable, comparable, and predictive.

  • Evidence that measured detection and containment times vary more with attacker sophistication than with defender capability, making cross-organisation comparison meaningless.
  • Results showing that organisations optimise the measured intervals at the expense of unmeasured harm, for example containing quickly by destroying evidence needed for notification.
  • Outcome data where recovery capability, not detection speed, explains nearly all the variance, which would justify collapsing much of the scorecard.

Put this to work

Research decision record

Use the question “Which measurements actually predict whether an organisation survives an attack?” on a real case and produce a record another person can challenge.

For
Practitioners, researchers, founders, and operating leaders.
What you keep
A research decision record you can review, revise, and send.
What counts as sound
  • Answers a named decision
  • Separates evidence from assumptions
  • Includes the strongest contrary case
  • Names missing evidence
  • Ends with a test, owner, and date

The result is a working analysis. Check it against source evidence and qualified judgment.

Nothing entered here is stored or sent. Review the prompt before sharing confidential, personal, patient, or privileged information.

Review the prompt

You can leave any field blank. The prompt will mark it as not provided.

If the record survives your review, send the question, evidence, unknowns, and requested next step.

Experiments for this pillar

Patterns and anti-patterns

  • Pattern

    Score unknown as red

    Remove the not assessed category. A control whose effect has not been demonstrated is reported as failing until it is tested, which makes the verification backlog visible to the people who fund it.

See the full patterns register

Evidence for this pillar

Read the full evidence library

Notes under this pillar

Design Patterns

Operating Theorys