RVA Cyber · Public working draft 0.3

P(hack)=100%

The case for defensive coscaling before digital Pearl Harbor

  • September 16, 2026
  • RVA Cyber Research
  • Policy argument + stress test

The five-minute case

p(hack)=100% is a preparedness axiom, not a claim that economic destruction has a measured 100-percent probability. The United States should act as if a capable person will use AI to attempt a systemic cyber campaign. Whether that attempt becomes catastrophe is still a choice.

The choice turns on one inequality:

Defensive time-to-closure must remain below adversarial time-to-reliable-exploitation—across the economy, not only inside a few wealthy firms.

That is defensive coscaling. It requires continuous discovery, attack-path reasoning, tested remediation, bounded containment, independent verification, clean recovery, and collective learning. A quarterly scan and a spreadsheet are not enough.

Two economies share one blast radius

Economy A

AI-native

Models, agents, machine-readable state, software-defined infrastructure, rapid deployment, and digital twins. It can be designed for safe machine-speed change.

Economy B

Installed and revenue-producing

Custom applications, old databases, appliances, industrial controls, medical devices, acquired systems, spreadsheets, VPNs, identity forests, and manual approvals.

The AI-native economy can be built around machine-readable state, automated testing, digital twins, reversible deployment, and rapid recovery. The legacy economy cannot wait to be replaced. It produces the revenue and essential services that keep the country functioning today.

The two are coupled. AI depends on power, telecom, finance, logistics, law, and government. Those systems increasingly depend on cloud, identity, software, and data platforms. The Hack wins through the coupling.

The market pays for the wrong outcome

Legacy IT teams are not failing because they do not care. They are following the objective function their organizations gave them.

The result is predictable: organizations pay people to keep vulnerable systems stable, then blame those people when the risk matures.

A public service that is available but materially exploitable is not up. It is operating in a failed continuity state.

The loop that decides the outcome

Offensive loop

  1. discover
  2. understand
  3. exploit
  4. expand
  5. destroy
  6. adapt

Defensive loop

  1. inventory
  2. model
  3. detect
  4. decide
  5. close
  6. verify
  7. recover
  8. learn

The unit of success is not a finding. It is a closed, independently verified attack path plus a tested way back.

Replace the uptime SLO with a Continuity SLO

01

Availability

The service performs its essential function.

02

Clean exposure

No known, reachable, unmitigated public attack path remains open.

03

Closure latency

A dangerous path is safely patched, isolated, or removed within the required interval.

04

Recoverability

The function restores from a clean, independently administered plane within objective.

The board owns this scorecard. The chief executive, technology leadership, and business owners must fund the architecture and accept the consequences of delay. Operators execute within authority; they do not become the liability sink for unfunded risk.

The governing objective is 100-percent clean, 100 percent of the time, against everything the organization and national system can currently know and safely test. That does not pretend unknown zero-days do not exist. It refuses to tolerate a known, reachable, unmitigated path.

A national program with a hard edge

Duty

Move responsibility to boards, executives, business owners, and controlling suppliers.

Capacity

Provide an open defense stack, free federal model service, Stewards, financing, and emergency engineering.

Evidence

Measure continuously, assign ownership, verify closure independently, and prove clean recovery.

Consequences

Use material civil penalties for overdue paths and criminal law for deliberate culpable conduct.

The mandate and the public utility belong together. A requirement without affordable capacity would close small organizations and deepen dependence on the largest platforms. Capacity without a duty would leave systemic risk optional.

The law should therefore require closure, fund the means to comply, scale civil consequences with culpable delay, and reserve criminal liability for deliberate concealment, falsification, obstruction, sabotage, or willful defiance of a lawful emergency order.

What this paper does—and does not—claim

The opening attacker is a fictional stress test assembled from capabilities and precedents that exist in pieces. No source proves that one person is running that exact operation. Current models still struggle with some long, realistic cyber sequences. The timing, composition, and impact of a systemic attack remain uncertain.

The paper also does not dismiss loss-of-control risk from advanced AI. Its narrower claim is that society need not solve the entire alignment debate before acting against an AI-enabled cyber pathway already visible in evidence.

The uncertainty is the reason to build resilience. It is not a reason to wait.

Choose a reading path