Security Survivability Engineering

If it doesn't reduce risk, it's attack surface.

Survivability Engineering is the security discipline of designing systems to keep functioning, absorb damage, and recover fast. It gives Security Brutalism its measure, judging a system by how exposed it is, how bad a breach would be, and how fast a team can recover from one. After 25 years working across nearly every area of security, I've watched programs break down under real-world conditions because they skip a basic assumption, that compromise is always possible. What the architecture promises, what the controls report, and what a team believes to be true often diverge from what is actually happening on the ground.

Survivability engineering builds systems that keep functioning when things go wrong. It designs with failure in mind, measures true resilience, and closes the gap between what a security program claims and how it performs under stress. The aim is to understand how long a system stays in a failed state and to keep reducing that time.

Head over to the Security Brutalist Blog to read more about it.