Time to detect
From the first attacker action to the moment a human or system knows something is wrong. Measured from injected activity, not from the incidents that happened to be noticed.
Research pillar · Zero Security Theatre
Security programs are usually described by what they have: purchased tools, signed policies, closed findings, and certificates. That says almost nothing about what would happen if a capable attacker tried something today. This pillar tests the controls and measures what happens.
The question
If the attacker tried this today, what would actually happen?
Active · since 2026 · Zero Security Theatre
hypothesis
A control does not count just because it is there. Test it against a real attack and see what happens. A deployed tool that has never faced the behaviour it is meant to stop has an unknown effect, and unknown is red.
Tools and policies are still necessary. The open claim is that organisations which repeatedly test their controls against attacks suffer smaller losses than comparable organisations that do not. That sounds plausible, but this research has not proved it.
recommendation
Each can be observed, timed, and repeated. If the organisation cannot produce the number, write unknown. Do not fill the gap with a comfortable estimate.
From the first attacker action to the moment a human or system knows something is wrong. Measured from injected activity, not from the incidents that happened to be noticed.
From detection to the point where spread stops. Containment is an action with a timestamp: an account disabled, a host isolated, a key revoked, a segment closed.
What one compromised identity, key, service account, or workstation can reach. Measured by attack-path analysis and by trying it, not by reading the access matrix.
Whether a named path from an ordinary foothold to a crown-jewel system still works after the last round of remediation.
How often the same class of weakness returns after being closed. Recurrence suggests the fix addressed an instance rather than a cause.
The share of critical systems restored from backup within the last period, with a timed result and business validation.
observation
Inventories persist because they are cheap to produce, easy to audit, and comfortable to present. A count of controls can be assembled from configuration exports in a day. A measured detection time requires somebody to generate real activity in production and accept what the number says.
Reports follow what is easy to collect. Finding counts are easy. Attack results are harder. Changing the measure usually requires an executive willing to see a red number where the old report showed green.
unknown
The pillar rests on the claim that tested controls predict outcomes better than inventoried controls. Several results would weaken it.
Put this to work
Use the question “If the attacker tried this today, what would actually happen?” on a real case and produce a record another person can challenge.
The result is a working analysis. Check it against source evidence and qualified judgment.
Nothing entered here is stored or sent. Review the prompt before sharing confidential, personal, patient, or privileged information.
You can leave any field blank. The prompt will mark it as not provided.
If the record survives your review, send the question, evidence, unknowns, and requested next step.
How long does it take to notice activity that a deployed control claims to detect?
What can be reached from a single compromised workstation account?
Pattern
Attach an outcome test to every security purchase
Make a named production test a condition of acceptance and renewal. Run the attack behaviour, record what the control changed, and use the result in the buying decision.
Pattern
Score unknown as red
Remove the not assessed category. A control whose effect has not been demonstrated is reported as failing until it is tested, which makes the verification backlog visible to the people who fund it.
Anti-pattern
Reporting agent coverage as security posture
A coverage percentage measures software installation. It carries no information about whether anything is detected, contained, or recovered, and it rises fastest on the systems that matter least.
A public record of what is actually being exploited, useful for separating theoretical from observed risk.
The behaviour catalogue used to select techniques for detection and containment measurement.
Annual incident pattern data. Useful for base rates, with the usual caution that the sample is not a population.
Design Patterns
Counting open findings measures the discovery process. It says nothing about detection speed, containment, or recovery, and it falls when scanning stops.
2026-09-15
Operating Theorys
If nobody can show that a control works, score it as failing. Amber and blank let an untested control sit quietly beside a tested one.
2026-09-15
Procurement produces a deployment date. Nothing in the ordinary purchase process produces evidence that the tool changes an attack outcome in this environment.
2026-09-15