Security Unconventional Warfare Part 2: From conventional to unconventional
Conventional security reacts. Incidents happen, alerts fire, and teams scramble to contain damage after the fact, which puts defenders at a permanent disadvantage because attackers keep the initiative while everyone else tries to catch up. Conventional programs run on detection and response cycles that keep investigating alarms only after activity has already happened, building backlogs while adversaries keep operating. They stack overlapping tools that compete for analyst attention and generate fatigue that hides genuine threats, they measure compliance and process completion instead of adversary frustration, and they try to protect everything equally, which spreads resources so thin that nothing gets real concentrated defense.
This creates weaknesses that experienced adversaries learn to count on. They know defenders patch and react slowly, and get distracted by false positives that provide useful cover, so once an attacker gets an initial foothold, lateral movement through a flat network or abuse of a neglected privileged account can continue for months without anyone noticing. Most of the team's time goes to investigating alerts and responding to incidents, which leaves little capacity for the proactive work that would reduce that reactive load in the first place.
Closing that gap means shifting toward unconventional defense, a model built on a different starting assumption. It treats intrusion attempts as continuous and accepts that infiltration will eventually succeed regardless of the defenses in place, so the goal shifts from preventing every attack to frustrating adversaries, slowing their progress, and raising their operational cost until a campaign stops being worth running. This approach shapes the terrain in the defender's favor before an attack even starts, rather than waiting to respond once one is underway.
Disruption adds deliberate friction, so attacks become noisy and slow instead of quiet and efficient, through authentication barriers that trigger monitoring, micro-segmentation that forces an attacker to repeatedly establish new access points, and systems that fail securely when tampered with. Deception plants false systems, accounts, and data that look legitimate to automated scanning and manual reconnaissance but trigger an immediate alert the moment someone touches them, giving defenders early warning they would not otherwise get. Precision targeting concentrates protection on the assets that actually carry risk rather than spreading equal effort everywhere, accepting calculated risk on less critical resources in exchange for real strength where it counts, while adaptation keeps changing networks, monitoring configurations, and controls often enough that an attacker's earlier reconnaissance stops being useful, forcing them to start the discovery phase over again. What makes all of this work is a mindset shift underneath it, as defenders stop waiting for an alarm and start actively shaping the operational terrain, so success becomes statistically unlikely and expensive for anyone trying to break in.
None of this stands on its own. Unconventional defense needs Security Brutalism underneath it, because advanced tactics become counterproductive on unstable ground. A honeypot provides nothing if an attacker can compromise a real privileged account without hitting resistance, and a deception asset loses its value if an adversary can just walk across a flat network to the real target without tripping any monitoring. Organizations that reach for unconventional tactics before mastering asset management, identity control, and segmentation usually end up building elaborate distractions that mask the real vulnerabilities underneath, and adversaries simply route around the distraction by hitting an unpatched system or an abandoned account instead.
Making this shift work in practice calls for deliberate phases rather than jumping straight to advanced tactics. The first phase hardens the operational environment across comprehensive asset visibility, data protection, identity discipline, segmentation, reliable logging, and consistent vulnerability hygiene, since skipping this step undermines everything built afterward. The second phase forms a small operational cell dedicated to experimenting with disruption and deception, kept small to preserve flexibility and avoid the bureaucratic drag that slows innovation, with a mission that stays narrow and specific, frustrating adversary operations, raising their cost, and building traps that catch intrusions early. The third phase puts specific tactics into controlled environments, embedding honeypots that blend naturally into real network segments, planting deceptive accounts that trigger monitoring if touched, and building segmentation choke points with amplified logging to catch lateral movement. The fourth phase tracks measurable outcomes, including adversary dwell time from compromise to detection, the number of wasted attacker attempts against deceptive assets, and evidence of earlier detection across attack campaigns.
Leaders need to remove the fear of failure that keeps teams from experimenting, since operators need room to try tactics that will not always work on the first attempt. Protecting the unconventional defense cell from routine bureaucracy keeps it agile, and reporting outcomes to executives works best in cost terms, showing that attackers now need far more time and effort for far less result. Leaders also need to set realistic expectations, since this kind of defense builds effectiveness over months and years, not weeks.
Operators, for their part, need to shift from reactive analyst to proactive terrain-shaper. Continuous threat hunting becomes the standard rather than the exception, deploying deceptive assets requires enough discipline to keep them convincing without disrupting real business operations, and studying adversary behavior patterns lets defenders place obstacles and monitoring exactly where an attacker is likely to trigger detection. Creativity is important here, but it needs to stay connected to the fundamentals rather than turning into unfocused experimentation disconnected from the rest of the security architecture.
As an example, I can give you a mid-size financial services organization that showed what this looks like in practice. before I helped them, the company had spent eighteen months struggling with alert fatigue and slow incident response before committing to fundamentals first, and it took eight months to harden asset management, data classification, identity discipline, segmentation, logging, and vulnerability management to a mature state before the organization began experimenting with unconventional tactics at all. A team of six security professionals then took on the unconventional defense mission, and within four months they had placed decoy servers inside network segments holding genuine business systems, set up segmented communication channels for executive leadership, and deployed false credentials built to trigger immediate alerts if touched. Adversary activity that used to go unnoticed for months started getting caught within a short period of time, attackers who once moved efficiently through the network instead spent weeks chasing traps that led nowhere, and mean time to detection improved from 200 days to 12 hours for most compromise scenarios. This also enabled both the unconventional operators and the SOC analysts to pursue better threat intelligence due to the information gathered during the first few months.
The improvement came from a cultural and operational shift, moving from chasing alerts to hunting threats and shaping terrain, rather than from adding hundreds of new tools. The team kept its focus on the fundamentals while layering tactical innovation on top of that stable foundation, and that combination is what let the organization stop operating at a permanent disadvantage and start setting the terms of engagement itself, an edge that adversaries cannot easily overcome through technology alone.
Go to Part 3.