Security Unconventional Warfare Part 7: Working unseen
Unconventional defense depends on SUW cell members who work behind the scenes, and their work succeeds when nothing happens. No breach, no exposure, and no compromise. That outcome rarely earns applause, yet it represents the highest standard of performance a security professional can reach.
Attackers study defenders through public presentations, vendor case studies, and industry publications that reveal defensive methods and tactics. If an SUW cell publicizes its methods, whether through its own disclosures or through conference talks and marketing that showcase its wins, attackers adjust before they even engage, and months or years of tactical development lose their value overnight. That kind of exposure might serve a real business purpose, like demonstrating competence to stakeholders, but it hands attackers exactly what they need to spot and avoid similar traps next time, and it pulls operator attention away from real tactical work in the process. Staying quiet protects the doctrine itself and preserves an advantage that took real effort to build. This means working without public credit, keeping projects discreet and shared only with people who need to know. Measuring success by the absence of incidents rather than headlines is the way to go. Members who start valuing personal reputation over effectiveness drift toward dramatic but ineffective moves that generate attention rather than results, so staying quiet toward outside audiences is a must. However, this is different from hiding things from leadership; appropriate internal oversight continues as it should.
Cell members hold operational details inside trusted circles, even in casual conversation. They keep up asset inventories, review access controls, and refresh deception assets because those activities support real effectiveness, and they aim for actions that maximize impact rather than anything showy, staying flexible enough to adjust tactics quickly as attacker behavior shifts. In order to prevent ego, success gets credited to team coordination rather than individual brilliance. Leadership outside the security circle need to say consistently that the organization values results and that external communication about the cell's capabilities needs to stay off the table entirely.
That message has to travel up the chain, repeatedly, until it holds. Staying quiet in this way is the cultural backbone that makes unconventional defense actually work.
Still, executives, boards, and senior leadership need clarity about what is happening and why, especially to support budget. Holding onto operational discipline while still communicating progress in a way leadership can actually use takes a deliberate translation skill, one that converts technical work into business language without exposing sensitive detail along the way.
Operators think in log correlations, anomaly patterns, and behavioral indicators, while executives think in operational continuity, financial impact, and regulatory standing. That's where reporting usually tends to break down. Speaking only in technical terms leaves leadership blind to the business value of the work, and demanding full visibility into every tactic compromises the doctrine itself, since tactical effectiveness depends on adversaries staying ignorant of exactly these details. The solution is reporting outcomes rather than methods. A statement that adversary dwell time dropped from 30 days to under 7 hours communicates real improvement without revealing the detection method behind it, and a note that privileged access reviews cover every account each quarter shows disciplined identity management without exposing the review procedure itself.
Framing security discipline in terms of business risk based on survivavility makes this land with a board as well. Framed this way, discipline reads as risk reduction rather than technical maintenance, and that's what helps executives see security spending as real business value.
Reporting itself should stay simple, built around four to six metrics tied to business outcomes rather than activity counts, such as the share of privileged accounts under regular review, mean time to patch, adversary dwell time, and a quarterly resilience score. Keeping that same metric set consistent across reporting periods is more valuable than adding variety, since a rotating set makes real improvement hard to see.
It's really important that both the cell members and leadership resist the pressure toward over-disclosure, whether it comes from a board asking too many questions or an external audit that could become an intelligence source for an adversary studying the organization. Exact trap locations, hunting methodology, and detailed technical playbooks stay out of any external report, and communications summarize outcomes in plain business terms instead. A useful quarterly update follows a consistent shape, opening with brief context on the threat landscape, moving into an update on the fundamentals framed by business impact, then a summary of unconventional defense outcomes without disclosing specific tactics, a short metrics snapshot, and one or two priority areas for the next quarter.
Operators need to see executive reporting as serving a real business need rather than a burden competing with real work. Executives, in turn, need to see operational discretion as protection for business value rather than a way to dodge accountability. Handled well, this gives leadership real confidence that the organization's defenses are resilient and effective, while adversaries stay blind to the methods and capabilities that make that possible.
Go to Part 8.