Security Unconventional Warfare Part 8: Foundations first, always
Doctrine works as a living system, not a fixed manual. It grows through experience, testing, and contact with an adversary who keeps changing, and that growth is the only thing keeping defenders ahead.
The pillars underneath it (asset management, data security, identity discipline, segmentation, visibility, and vulnerability hygiene) stay fixed. What moves is the tactics built on top of them; a playbook that stops updating those tactics turns into a liability. It hands operators outdated guidance and a false sense of confidence, and the first real test against an adapted adversary breaks whatever the team had practiced, usually at the worst possible moment.
Keeping the tactics current depends on a feedback loop that runs on a clock rather than whenever someone gets around to it. An after action review has real value only while the incident is still fresh, so waiting a week to write it up means guessing at half the details that counted in the moment. Doing it within a day or two catches the operator while memory is sharp and emotions have settled enough to look at what worked without needing to defend a decision or place blame. Writing the finding down is what lets it survive past the person who lived through it. The lessons learned must be adopted on the next round of planning and capabilities building, and the following incident has to prove whether it actually took hold.
An example of this loops is multi-factor authentication. It has been non-negotiable for years, but the SMS token that used to satisfy that requirement gave way to phishing-resistant authenticators once SIM swapping turned it into an easy target. The requirement held but the method underneath it was rebuilt around the current threat. It was adapted.
Deception tactics need to follow the same rebuilding, only faster, because an adversary who spots the same trick twice learns to avoid it permanently. A honeypot that stays static starts to look fake next to real systems that keep evolving around it, and once it does, it stops being a trap and becomes a landmark the adversary routes around.
Staying unpredictable is the entire reason this kind of defense works.
This operating style rarely survives being left to any kind of informal effort, which is why leadership has to enforce it rather than hope it happens on its own. In practice that means having one owner, usually the SUW cell lead, so doctrine updates do not dissolve into being everyone's job and therefore no one's. SUW operators also need to understand the shift in framing, so they read adaptation as a sign of growth rather than proof that an earlier approach failed. An after-action review teaches nothing if operators run it as a formality to get through.
This approach works only because it rests on fundamentals. Remember that every security program feels pressure to chase the shiny, with vendors trying to sell platforms and leadership chasing "innovation". It's good to want the advanced tool, but don't forget that the record of actual breaches keeps pointing to simple tactics being used, like an unchecked account, a flat network, or a patch that sat too long. What SUW needs to fight this is not exotic, which is exactly the point and a disciplined baseline is what makes anything more advanced possible in the first place.
Attackers tend to take the path of least resistance; sophisticated adversaries have no reason to build custom malware if a stale privileged account will do the job. Once the foundation is secured, the whole environment turns harder to intruders. Every attempt now needs precision instead of luck, and that effort leaves noise behind it, which buys defenders time. That secured foundation is also what makes unconventional defense possible at all, not a separate layer stacked on top of it. Deception accounts mean nothing without real account audits behind them, honeypots cannot isolate anyone without real segmentation, and traps cannot be watched without real visibility. Once the foundation holds, the SUW cell's decoys and targeted hunting start making every step more expensive and more confusing for an attacker who can no longer trust what they find, a multiplier on the fundamentals rather than a substitute for them.
Doctrine built and enforced this way outlasts any single leader or team, because it lives in documentation and practice rather than in one person's memory. Operators carry the discipline of staying quiet, precise, and adaptive, leaders keep the doctrine protected from exceptions and bureaucratic dilution, and executives get resilience explained through a handful of real numbers instead of a wall of noise. The moment leadership starts granting exceptions, or lets the doctrine calcify into a document nobody revisits, the whole team starts drifting back toward distraction and exposure.
Any security leader can start this today, with the same basic moves that got neglected everywhere else. Cut identity access that no longer serves a purpose, segment critical systems without waiting on a perfect plan, and build logging around what's actually important rather than everything at once. Once that foundation holds, the next move is a small operator team built for deception and disruption, protected from bureaucracy, measured by the cost it imposes on an adversary, and expected to feed every lesson back into the doctrine before the cycle runs again. Run this way, a security program stays simple and hard to wear down. Attackers stop finding easy targets, every intrusion attempt gets expensive, and defenders set the pace instead of reacting to it.
Foundations first, always. Everything else depends on that.
If you need help implementing SUW, send us a message.