Operating framework

Close faster than offense can reuse

Defense must scale in speed, coverage, quality, and recovery—not merely in the number of findings.

  • 3 ingress paths
  • 7 capabilities
  • 4 separable planes

The governing inequality

Defensive coscaling is the continuous expansion of defensive speed, coverage, quality, and recovery capacity in step with—and preferably ahead of—the expansion of attacker capability and the defended environment.

For material attack paths: Tclosure < Treliable exploitation, at national coverage.

This is not a product category. It is an operating condition. Buying an AI tool for the security operations center does not satisfy it. Closing one company's exposure while thousands of suppliers remain open does not satisfy it.

Three paths in

Path 01

Exploitable technology

Unpatched software, insecure configuration, exposed services, vulnerable dependencies, zero-days, and chains.

Path 02

Human and identity compromise

Phishing, social engineering, token theft, session hijacking, password reuse, and help-desk manipulation.

Path 03

Trusted access abuse

Malicious or coerced insiders, compromised vendors, managed services, updates, administrators, and supply chains.

The first national sprint focuses on publicly reachable technical paths because attackers can discover and reuse them at scale, defenders can measure them from outside, and much of the closure work can become standardized machine work. The same architecture must then extend to identity, insiders, vendors, and zero-days.

Two closed loops

Offensive loop

  1. discover
  2. understand
  3. exploit
  4. expand
  5. destroy
  6. adapt

Defensive loop

  1. inventory
  2. model
  3. detect
  4. decide
  5. close
  6. verify
  7. recover
  8. learn

The defensive loop fails when any arrow stops. Inventory without ownership creates a backlog. A proposed fix without a safe deployment path creates advice. A deployed fix without independent verification creates faith. A backup inside the production identity plane creates a promise, not recovery.

Seven capabilities make the loop real

  1. Live inventoryMap the exposed service to its owner, version, identities, dependencies, business function, and recovery tier.
  2. Attack-path reasoningJoin findings into reachable paths instead of treating one severity score as the answer.
  3. Remediation factoryGenerate and test patches, configuration changes, isolation rules, compensating controls, and retirement plans.
  4. Bounded containmentRemove exposure, revoke access, or isolate the asset when safe remediation cannot beat exploitation.
  5. Independent verificationRescan externally, retest function, confirm policy, and retain a signed receipt.
  6. Recovery outside the blast radiusKeep clean images, keys, and restoration control beyond routine production identity.
  7. Collective learningTurn attacks, failed patches, workarounds, and restorations into minimized defensive knowledge for others.

The seven capabilities are deliberately coupled. A fast patch factory without live inventory will miss assets. Continuous scanning without attack-path reasoning will drown operators. Containment without authorization can become its own outage. Recovery without isolation can restore the compromise.

The Continuity SLO

01

Availability

The service performs its essential function.

02

Clean exposure

No known, reachable, unmitigated public attack path remains open.

03

Closure latency

A dangerous path is safely patched, isolated, or removed within the required interval.

04

Recoverability

The function restores from a clean, independently administered plane within objective.

Availability remains essential, but it is no longer allowed to hide exposure. A controlled defensive isolation is an outage; the scorecard should still distinguish it from negligent exposure and charge the root cause to the architecture and business decision that made isolation necessary.

What “100-percent clean” can honestly mean

No scanner can prove that an unknown flaw does not exist. The operational objective is narrower and enforceable:

Zero known, reachable, unmitigated attack paths under continuous current measurement, plus the ability to return to that state within minutes after a new path becomes knowable.

The response is not always “install the patch.” It is patch, isolate, disable, migrate, or withdraw from public reach. Mature architecture makes those actions safe through digital twins, regression tests, redundant capacity, staged deployment, signed provenance, automatic rollback, and preauthorized containment.

Four separable planes

Plane 01

National exposure plane

Maps public services to responsible entities, starts clocks, and verifies closure without creating a public target map.

Plane 02

Local continuity plane

Keeps company data local, maintains the twin and dependency map, tests fixes, contains, and restores.

Plane 03

Defensive reasoning plane

Runs the free model service, evaluates tools, distributes signed fixes, and learns from minimized outcomes.

Plane 04

Independent recovery and oversight

Keeps restoration beyond production compromise and preserves courts, evaluators, audit, and civil-liberties review.

Separation matters. A model that can inspect everything, change everything, certify itself, and reach every backup would concentrate the same catastrophic power the program is supposed to reduce.

The scoreboard

Measure the work that changes survivability:

The last two metrics prevent the program from declaring victory by breaking production or people.