On Deception and Security Unconventional Warfare

Dan Wood just published an article that should be required reading for anyone who thinks they understand modern security and red teaming. In "Deception as a System", he argues that most cyber deception discussions stay stuck at the tool level, honeypots, decoys, fake credentials, while missing the real power play that is deception as structured decision engineering. Drawing from military doctrine across Western, Russian, and Chinese traditions, he frames real deception as deliberately shaping what adversaries believe, controlling the evidence they observe, and measuring whether their behavior changes. The point that should make every security leader uncomfortable is this: if your red team plan doesn't state the belief you're trying to create or test, you're running a technical exercise with vibes, not doing deception.

Security teams stay so deep in control-testing that they lose sight of what adversaries actually target, the mind of the defender, not the tools in front of them. Teams build frameworks and dashboards for everything, and mature threats still walk right through, because they treat belief itself as a vulnerability.

Deception isn't a niche technology or a control you bolt on when you're feeling ambitious. It's how real adversaries operate. They shape what you see, what you believe, and what you decide. They make you think it's ransomware when it's espionage. They make you focus on the wrong timeline, the wrong actor, or the wrong containment action. And while a red team congratulates itself for getting domain admin, nobody asks whether the SOC would recognize the strategic objective, or whether they'd just burn hours chasing the wrong story.

It comes down to looking at the whole picture, thinking in graphs, and applying common sense.

This is why I created Security Unconventional Warfare (SUW), and why Dan's article lines up with how I think about this problem. SUW centers on small, elite cells that actively hunt threats, disrupt reconnaissance, and make the environment hostile to adversaries before they even get started. It runs on deception at a larger scale, feeding attackers false information, forcing them to waste resources, and turning every lateral movement attempt into a noisy, expensive gamble. Traditional security waits for alerts. SUW makes attackers regret ever looking at the target.

SUW only works if you treat deception as a system rather than a trick. That means thinking the way Dan describes, defining the belief you want to create in an adversary's mind, controlling the evidence they observe, and measuring whether their behavior changes. It means treating red teaming as adversarial decision warfare, testing whether an organization can recognize intent under misdirection rather than whether the EDR blocks a known binary. It means building small teams that operate the way adversaries think, not the way compliance officers do.

Security isn't a job of defending everything equally. It functions as asymmetric warfare, where the side that controls the narrative wins. That calls for treating deception as doctrine rather than decoration, building threat emulation that actually emulates intent, designing exercises around decision failure modes, and training teams to disrupt reconnaissance by shaping what attackers believe is possible.

Right now, defenders test their controls while adversaries test their capacity to think clearly under pressure, and that fight is going badly for the defenders.