Security’s Absurd Cycle

As we focus on building, enhancing, and applying lessons learned from the services we provide at Black Arrows, a simple pattern keeps showing up. Security moves in cycles, and the difficulty stays constant, only the reasons change.

In the beginning, security was difficult because humans are fundamentally flawed. Cryptography wasn't the hard part, a person making a mistake was, clicking something careless or losing focus for a moment. The job of information security centered on engineering simple, understandable defenses around that inherent fallibility. For years, the community worked behind the scenes building solid foundations, trying to shrink the surface area that human nature could expose.

That effort paid off, in a way. The obvious doors got bolted shut, simple phishing emails lost some of their effectiveness, and the industry reached a baseline of safety. That success brought a different kind of difficulty though, a new, self-imposed complexity that makes the old problems look small by comparison.

Security has become an incredibly complex mess now, driven less by harder math and more by the sheer volume of unnecessary tooling built into modern environments. Every new problem gets met with a wave of vendors offering solutions nobody asked for. These tools often solve nothing substantive, yet they demand resources, generate mountains of noise, and introduce new, unexpected attack surfaces. The industry has traded a simple, hard human problem for a complicated, expensive, and opaque universe of vendor-driven complexity.

The technology itself keeps getting more convoluted by the minute, when it should be getting simpler. Everything sits layered, abstracted, and constantly shifting, leaving security professionals chasing ghosts through systems built for expediency and profit rather than elegance. The hardest part of the job today involves protecting systems from the systems themselves, an effort that keeps climbing into the absurd even as the underlying cycle repeats.

This endless, exhausting chase after complexity suggests the industry lost the thread somewhere along the way. Regaining strength, resilience, and sanity calls for a brutal pare back rather than another black box purchase. Embracing Security Brutalism means stripping away the abstraction, cutting the unnecessary tools, and focusing only on the fundamentals that genuinely reduce risk. Building defenses that stay simple, visible, and enduring, even when they aren't pretty, frees up time once spent managing vendor spreadsheets and puts it toward engineering systems that are actually secure.