THE SECURITY BRUTALIST

Security Brutalism Under Real Conditions, Part 7: Where This Goes Next

This post breaks from the others. Parts 1 through 6 built a playbook. This one thinks out loud about where security brutalism and survivability engineering need to go over the next one, three, and five years, given what AI and other technology shifts are doing to the threat environment. Some of this reflects what's already happening, and some of it is speculation. I'm more interested in asking the right questions right now than in having the right answers.

The Frame I Keep Coming Back To

The survivability framework often assumes the systems you're defending are deterministic. They do what they're programmed to do, they behave consistently, and restoring to a known-good state means something because a known-good state exists.

That assumption is eroding, quickly, and I think the erosion is the central challenge for the next five years, less about specific attacks or technologies than about what survivability means when the systems being defended are themselves adaptive, non-deterministic, and in some cases not fully understood even by the people who deployed them. AI runs in two directions at once here, standing as the new attack surface we have to defend while increasingly becoming the mechanism through which attacks arrive, and both sides grow more complex over the next five years rather than less.

The Next Twelve Months

The gap between a vulnerability becoming known and getting actively exploited has compressed to hours in many cases, as AI-assisted scanning finds and characterizes attack surface faster than the old grace period after disclosure can account for. Patching faster only goes so far, since testing and deployment cycles set a floor, which means blast radius limitation and recovery capability carry more weight than they did when attackers moved slowly. A system that can't be patched in time can still have a bounded blast radius.

Credential and identity attacks scale with AI too. Phishing now runs personal and contextually accurate at volumes that make low success rates commercially viable, and the organizations that hold up are the ones that stripped the value out of a single stolen credential, through MFA, passwordless access, no standing access, and no long-lived tokens carrying broad permissions.

Agents are going into production without security review, under the same assumption organizations made about SaaS tools five years ago, that usefulness justifies deployment and security catches up later. Later tends to arrive after the first incident. Agent security work is urgent now, not in two years.

The Next Three Years

This is where I'm less certain and more interested in the questions. Agentic malware is the logical extension of AI-assisted attacks, autonomous systems that land in an environment, reason about what they find, and pursue high-consequence targets without human direction, adapting rather than following fixed paths or matching known signatures. Behavioral anomaly detection grows more important against this kind of adversary, even as it grows harder to run, since adaptive behavior gets designed to look reasonable at each individual step.

This doesn't make the survivability framework wrong. It makes it more important, since an adaptive adversary moving intelligently through your environment still has to move through it, and bounded blast radius with limited lateral movement paths blunts the value of that adaptability. The harder question is what happens once defense turns agentic too. A defense agent that monitors, reasons, and responds without waiting for human approval reacts faster than any security team, but that speed creates its own failure mode because a defense agent racing to close a vulnerability window might push an untested patch that breaks something the attacker never would have reached. The more capable the defense agent, the more consequential its mistakes, and some of the most important design decisions ahead will be about where to force a pause rather than how to eliminate every one.

AI-generated voice and video of known individuals already works well enough for targeted attacks, and will only improve over three years, turning what once required a human to impersonate a CFO on a call into something automated at scale. As the human trust anchor for high-consequence decisions grows less reliable, separation of duties and multi-party approval for irreversible actions grow more important. If a synthetic executive voice requesting an urgent wire transfer isn't enough to trigger the action, the attack fails. If it is enough, the control was missing.

Compliance frameworks already lag the threat environment by two to four years, and that lag is growing as the pace of change accelerates, which means organizations treating compliance as their security program drift further from actual risk. This is a survivability argument, not a knock on compliance, and it makes the separation between survivability controls and compliance controls, discussed throughout this series, more load-bearing over time.

The consequence map needs to become a living document rather than something built in a workshop and updated whenever someone remembers to schedule a refresh. Environments now shift faster than annual reviews can track, and a significant architectural change, a new agent deployment, or a new AI integration can shift the existential list within weeks. The quarterly cadence from Part 4 may not hold up in three years for organizations moving at the pace AI-assisted development enables.

The Five-Year Horizon

Here I'm speculating, and these read more like questions that I'm thinking about rather than predictions. The line between attack and defense blurs, as the active disruption layer from Part 5, the specialist cell running deception and war-gaming outside the perimeter, evolves toward AI-assisted continuous operation, automated war-gaming, adaptive deception that updates on real adversary behavior, and continuous intelligence without a human running every operation. A smaller human team operating a more automated capability may replace the five-to-eight person cell model.

The same evolution happens on the attack side. As sophisticated attack operations automate, the expertise required to run them drops, the number of capable actors rises, and the deterrence model built on scarcity of skilled adversaries weakens.

Survivability for AI systems becomes its own discipline. A traditional system has a point-in-time backup and a restoration procedure, while an AI system carries weights, fine-tuning history, system prompts, tool configurations, memory stores, and interaction history, and what counts as a clean restore or intended behavior for that stack isn't settled yet. I expect the organizations that work through these questions to sit in a meaningfully different position five years out than those that don't.

The identity problem grows before it grows manageable. Most organizations already carry more service accounts and API keys than they track, and five years out they'll carry more agents, more agent-to-agent trust relationships, and more automated processes acting on their behalf than any human team can inventory by hand. The number of things that can act is growing faster than the ability to manage them, and organizations that invest now in understanding their machine identity surface will handle the expanded version of that problem better later.

The patch cycle breaks down further, as AI-assisted vulnerability discovery finds issues faster than organizations can patch them, a trend already partly true and set to deepen. Reducing susceptibility as a strategy has a ceiling, and that ceiling keeps dropping, which raises the value of blast radius limitation, fast detection, and tested recovery as closing every vulnerability window stops being realistic. Survivability engineering was designed for a world where some things get compromised, and that design assumption is aging well.

Questions I'm Still Working Through

What does the survivability test look like for an AI system? For a traditional system it's straightforward: assume compromise, measure detect, contain, restore. For an agent, compromise might mean a jailbreak, a manipulated system prompt, or adversarial training data shifting the model's behavior, and restore and known-good state both need new definitions worth working out rather than just acknowledging.

How do you hold situational awareness when your own environment changes at AI-assisted speed? Development runs faster, deployment runs faster, and the gap between what the consequence map reflects and what's actually running grows faster too. A review cadence that held up two years ago may not hold up today, whether the fix is better tooling, a faster cadence, or both.

How do you detect an adaptive adversary? One that adjusts behavior based on what it finds won't match signatures, and may not match behavioral baselines either if it moves slowly enough to look like legitimate use at each step. Deception assets hold up better here because a honeytoken firing stays near-zero false positive regardless of how the adversary otherwise behaves, but deception coverage is never complete. My best guess is making the environment small and well-understood enough that any access reads as anomalous, the minimal footprint principle taken seriously, though how achievable that is in a complex enterprise remains open.

What does the survivability framework protect when the organization itself runs partly on AI? This isn't hypothetical or far off. Some organizations already let AI systems make a significant share of operational decisions, and once the organization being protected includes AI systems as decision-making participants, both what the framework protects and what compromise means get more complicated.

What Stays Constant

How long you stay failed remains the right question through all of this, and the speed of modern attacks makes it more urgent rather than less relevant. The consequence map remains the foundation, with the systems that would end the business stay the ones needing the most protection regardless of what the attack looks like, and recovery capability tested with evidence remains worth more than recovery capability assumed from documentation.

The survivability framework rests on the premise that some things will be compromised and that the job is limiting damage and recovering fast, a premise that holds even more true in a world of AI-assisted attacks than when the framework was designed. The attacks run faster, more adaptive, and more automated, the environment runs more complex, and the assumption that all of it can be prevented grows less tenable by the year.

Which means the foundation carries more weight than it ever has, and the work described across the first five parts of this series grows more urgent, not less, as the threat environment gets faster and more capable.

That's the part I'm most confident about. The rest, I'm still working through.

More to come...

If you are thinking about any of this differently, or working on the questions above, I want to hear it. This series is a starting point for a conversation, not a settled answer. There is a lot ahead of us, security professionals. I think now, more than ever, is the time to go brutalist.