Security Unconventional Warfare Part 6: Three Years to a mature security doctrine
Building security discipline takes time. In my experience usually three years to get to the level of operational focus that enables SUW. Skipping ahead to advanced tactics before the groundwork is solid guarantees failure later. Each year or phase has a distinct job, and if are able to keep it in this order, the chances of success grow.
The first year establishes the fundamentals. The work doesn't focus on advanced tactics, big tool purchases, or experimental defenses. The goal is acutally reduction of unnecessary tools and noisy metrics, with a focus on hardening asset management, data security, identity, segmentation, visibility, and vulnerability hygiene. The program works hard to build a solid baseline for execution and enforcement, so leadership can see progress measured in fundamentals and resilience rather than innovation. That means things like a full enterprise inventory with every asset assigned an owner, data classified by sensitivity and encrypted at rest and in transit, and a patching cycle with real deadlines tied to accountable owners. Budget in this first year should favor asset and identity work heavily over anything advanced, since sophisticated monitoring platforms and anomaly detection tools produce little value on top of an inventory that is still incomplete.
By year's end the organization should have a hardened baseline that attackers cannot easily exploit, which is the only precondition for anything more ambitious.
The second year is where a small Security Unconventional Warfare cell gets formed on top of that baseline to help weaponize them. This cell needs a clear and narrow mission, with disruption, deception, and precision aimed at raising attacker cost and reducing dwell time. It should stay small, initially three to six operators selected for adaptability, discipline, trustworthiness, and curiosity rather than credentials; you can grow the number later as you are more comfortable with the concept. Training comes before deployment because operators need immersion drills, red-on-blue engagements, and cross-role rotation before they touch a live environment. The toolkit should stay lean, given that at this stage most of the work is creative and process-driven rather than tool-driven. Once trained, the cell starts real operations in the back half of the year, deploying honeypots in non-critical zones, deceptive credentials that trigger alerts, canary tokens that flag intruder activity the moment they get touched, and active hunting instead of waiting on alerts.
Leaders need to shield this cell from bureaucracy, and routine monitoring duty or other rotations within the larger security department. The cell, on the other hand, needs to prove its value to executives through concrete outcomes like extended attacker dwell time and reduced access to critical systems, rather than vague reassurance.
The third year focuses on integration. The fundamentals and the SUW cell stop running as two separate tracks and start operating as a single system, with deceptive credentials folded into identity reviews, hunting tied to existing segmentation boundaries, and canary tokens feeding the same logging pipeline as everything else. Once that integration holds, the cell can expand into persistent hunting, an adaptive deception network that evolves alongside attacker behavior, an intelligence loop that feeds captured adversary tactics and deeper threat intelligence collection back into doctrine, and quiet interdiction that neutralizes activity without tipping off the adversary. Doctrine itself needs to get written down as a living manual, updated quarterly and codified so it survives staff turnover and leadership changes rather than existing as tribal knowledge in one person's head. Budget typically settles around 60 percent fundamentals and 40 percent SUW at this stage, and leadership's job shifts from building the program to sustaining it, with reporting outcomes in terms of dwell time, attacker effort, and consistency. Success at this stage shows up as a measurable drop in adversary dwell time compared to the year one baseline, doctrine that gets taught and updated as a routine practice rather than a one-time document, and critical functions that stay segmented, patched, and logged without constant intervention.
The risks shift with each year. In year one, the biggest threats are overcommitting to too many projects at once and letting executives carve out exceptions to the rules. In year two, the risk is growing the cell too fast, pulling operators into routine monitoring work, or overselling results before they are proven. In year three, the risk is treating doctrine as finished, letting the cell balloon with people who are not real operators, or losing the discipline needed to continue to build capabilities. At every stage the fundamentals have to hold, since nothing built on top of them survives if they slip.
This three-year approach turns a reactive security department into one that shapes the terrain instead of just responding to it, with attackers facing a harder, quieter, more disciplined target at every stage of the process.
Go to Part 7.