The Danger of Defending Yesterday
Sept 2021
Back in 2013 I wrote: "Security should not be a reaction to events. It should be proactive. The red team mindset builds this approach. It means thinking like an attacker, identifying what could be exploited, and staying several steps ahead. It means planning, preparing, and implementing detection and deception strategies before the first alert fires. This mindset makes future attacks harder to execute and less damaging when they come."
Yes. However... Let's go deeper into this.
Modern systems fail in familiar ways, but they break in unfamiliar ones. We have built a technology world that rewards optimization, speed, and comfort, and penalizes the act of asking what could hurt us rather than what is likely or trending. In security we talk about risk, but too often we mean cataloged risk, audited risk, risk that fits neatly into a spreadsheet. The real danger usually lives outside that frame, in places we have not named yet and therefore have not defended against.
One of my all time heroes in the world of red teaming said: "Entrenched social systems are incentivized to hold contrarian perspectives at bay. Regrettably, the defenses that preserve the status quo often fail against novel threats and hazards." (one of the Red Team Journal laws). That idea reaches beyond security programs or governments. It applies to companies, cultures, and individuals. Anything stable enough to last will eventually resist the ideas most likely to save it, the way an immune system protects the body but can also reject the transplant that keeps it alive.
I spent years studying adversarial simulation and how bad actors think because I wanted to understand why people prepare so poorly for failures they cannot yet imagine. We reason from precedent, not possibility, and mistake the absence of known threats for safety. When something has no name, no story, and no historical analogue, it rarely gets stress tested, red teamed, or taken seriously. Thinking two or three moves ahead is a way to outrun that lag, forcing scenarios into existence before they arrive unannounced and already too late to stop.
Security makes this failure mode easy to see. Breaches rarely succeed because defenses are absent, rather, they succeed because defenses are optimized for yesterday's attacker. We build controls around compliance checklists, past incidents, and vendor promises, then act surprised when an adversary steps sideways instead of forward. The attacker does not care how much effort went into the plan, only where it breaks. The same pattern shows up in business continuity, personal resilience, and relationships, where we prepare for the problems we recognize and get blindsided by the ones we assumed would never happen.
Thinking about what can hurt us is uncomfortable because it threatens the story we tell ourselves about control, and it requires entertaining ideas that feel pessimistic or disloyal to the system we belong to. Red teaming asks for respect for reality and an admission that complexity always leaks. Its goal is not to predict the future perfectly but to widen the set of futures we can survive.
Civilization evolved faster than cognition, so we run modern worlds on ancient firmware. After thousands of years of civilization, our biggest limitation is not technology, it is an imagination shaped by a world that no longer exists. If we want secure systems, resilient organizations, and lives that do not shatter at the first unexpected impact, we need room for uncomfortable questions. What could hurt us if someone wanted it to; what breaks if our assumptions fail; what happens when the thing we never planned for finally shows up. That mindset is the cost of operating in a world that no longer forgives surprise.