Security Brutalism
Most organizations have security programs that look complete, with tools, dashboards, audits, and compliance reports covering every angle on paper. Attackers still get in through phishing, stolen credentials, and unpatched systems, because that complexity never protected anything. It produced noise instead. Security Brutalism is a back-to-fundamentals security philosophy that is a direct response to this.
Security Brutalism rests on one requirement, that every control must justify itself by reducing susceptibility or limiting damage. A control that does neither expands the attack surface, since no complexity stays neutral. That requirement takes shape through survivability engineering, an evaluation that measures every system across three dimensions. Susceptibility maps the realistic attack paths through actual identities, data flows, and trust relationships as they exist, not as they are documented. Damage traces the blast radius if a system is compromised and what an attacker can reach from there. Recovery time measures how fast a team detects, contains, and restores, and whether that speed has been tested or only assumed.
The operating assumption is that entropy stays constant. Security starts degrading the moment a system goes live, as teams change, integrations accumulate, and controls drift. Survivability engineering accepts this pattern and designs for it instead of against it.
Security Brutalism plays out through four connected disciplines. It starts with Know, a living inventory of every system, identity, trust relationship, and data flow, since susceptibility cannot be measured without it. Building on that inventory, Harden works by subtraction, stripping out any tool, policy, or integration that fails to reduce susceptibility or limit blast radius, and aiming for deliberate simplicity instead of accumulated coverage. Once a system has been stripped down, See carries the load, detection built to catch a compromise while it is still happening and before it spreads, using behavioral monitoring, real-time anomaly detection, and deception assets, with speed of awareness as the real measure of success. When detection alone cannot stop something in time, Recover decides the outcome, restoration tested under stress through kill switches, immediate access revocation, practiced incident response, and chaos engineering, judged by how long a system stays stuck in a failed state.
Security Brutalism asks a sharper question than whether a program satisfies stakeholders: when you get hit, and you will, do you survive it?
The Security Brutalist Blog
You can expand your knowledge of implementing Security Brutalism and its foundational security approach through the articles and insights available in the blog.