What is Security Brutalism?
Security Brutalism: Know what you have, make it hard to break, see trouble fast, and limit and recover.
Most organizations run security programs that look complete on paper, with tools, dashboards, audits, and compliance reports covering every angle. Attackers still get in through phishing, stolen credentials, and unpatched systems, because that complexity never protected anything. It produced noise instead.
This philosophy is a direct response to the failures of over-engineered security programs, while attackers continue to succeed with basic tactics like phishing and exploiting unpatched vulnerabilities. Rather than adding layers of complexity, Security Brutalism strips away unnecessary elements to focus on what truly reduces risk and protects critical assets. It requires every control to prove it reduces exposure or limits damage before it earns a place in the program; a control that proves neither only adds complexity, and complexity itself becomes part of the attack surface.
The model runs on survivability engineering, which evaluates every system across three dimensions. Susceptibility covers the realistic attack paths through actual identities, data flows, and trust relationships as they exist, not as they're documented. Damage defines the blast radius if a system is compromised, and what an attacker can reach from there. Recovery time measures how fast a team detects, contains, and restores, and whether that speed has been tested or only assumed.
The operating assumption is that entropy stays constant. Security starts degrading the moment a system goes live, as teams change, integrations accumulate, and controls drift. Survivability engineering accepts this pattern and designs for it.
Four disciplines carry the model. Know builds a living inventory of every identity, trust relationship, and data flow, since exposure can't be measured without it. Harden works by subtraction, stripping out every tool, policy, and integration that doesn't reduce exposure or limit blast radius, aiming for deliberate simplicity over accumulated control coverage. See is detection that reveals a compromise while it's still happening, before it spreads, built on behavioral monitoring, real-time anomaly detection, and deception assets, with speed of awareness as the real measure of success. Recover is tested restoration under stress, using kill switches, immediate access revocation, practiced incident response, and chaos engineering, judged by how long a system stays stuck in a failed state.
Security brutalism raises a harder question than whether a program satisfies stakeholders. When you get hit, and you will, do you survive it?
How It Looks in Reality
For an established security organization, the focus is on stripping out unnecessary complexity and running a leaner program.
Start by removing redundant tools, overlapping controls, and policies that don't add real protection. Then build up the essentials, strict access controls, timely patching, and strong authentication, set as non-negotiable defaults for identity, access, logging, and patching. Cut the attack surface further by removing unused features and services, keeping a full asset inventory, and hardening whatever remains. The less there is to attack, the less there is to defend.
When something goes wrong, incident response follows strict, pre-planned protocols, including hard containment steps like automated credential revocation or immediate isolation of compromised endpoints. Real time monitoring, centralized immutable logging, and regular review keep the environment lean and able to adapt to new threats. Interfaces stay utilitarian too, simple, information dense tools and clear dashboards, built for function rather than polish.
This approach pays off in a program that detects faster, decides faster, and recovers faster, because there's less friction from unnecessary tools or unclear processes. The result is a program that's strong, durable, and easy to run.
Strip it down. Lock it down. Test it often. Trust nothing. That's the brutalist approach to security, simple, strong, and survivable.