The Security Brutalist
Security programs keep adding tools, dashboards, and audits, and attackers keep getting in through phishing, stolen credentials, and unpatched systems. Security Brutalism argues that complexity is the problem, not the fix. It strips a program down to four disciplines: know what you have, cut anything that doesn't reduce exposure, detect a compromise while it's still happening, and recover fast when something breaks.
This site works best read in order. Each post builds on the one before it, from the idea itself to a full applied framework.
- Form Follows Function. Security Follows Form., why the design comes first
- What Is Security Brutalism?, the full statement of the model
- Entropy Always Collects Its Debt, the assumption everything else is built on
- Survivability Engineering, the model applied: susceptibility, damage, and recovery time
- Building the Consequence Map and The Second Job, how to rank your systems and act on the ranking
- Security Brutalism Under Real Conditions, the full build out, from inventory to incident response
- Applying Security Brutalism, a playbook for leadership, architects, and engineers
- Four Roles In A Team, what this looks like for engineers, architects, responders, and managers
Prefer to browse instead? The full archive has everything by date, including the tools and the specialized posts that sit outside the main path.