Your journey
  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
0 of 34 units

Degree 4

Protection

The gate of this degreeA miniature red-team test and a cognitive defence plan.

You can now produce work with the tool. What you learn here is how you get attacked — both the system you have built and the mind that runs it. This degree brings classical information security, model security and cognitive security together into a single defence.

Entry condition
A documented output from the gate of degree 3.
The gate
A miniature red-team test + a cognitive defence plan.
Units
Six
Dimensions
System · People

OPENING STORY

Why Fawzooz built a shield that protects no server

After the night of the transfer I described at the start of this programme, Fawzooz sat down to analyse the incident as he would analyse any breach. He filled pages with the layers: network, identity, application, data. In every one of them the controls were sound. Then he wrote a line at the bottom of the page that changed the whole direction of his work: "the layer that was breached is not on the list."

There was no place anywhere in the security models called "cognition". We protect data from leaking, systems from stopping and identities from impersonation — and we do nothing at all to protect an employee's conviction from being shaped. Once systems could manufacture a voice, an image and persuasive text at almost no cost, that layer became the cheapest attack surface available and the one that pays best.

Out of that single line came what was later named the "cognitive shield", and then the cognitive security maturity model you will work with in the next degree. What this degree gives you is the foundation both were built on: how intelligent systems get attacked, how your own mind gets attacked, and why the two defences cannot be separated.

The red-teaming workflow

Six steps that turn a random attempt into a report someone can decide on — the spine of this degree.

FIG. A5 — From the attack to a proven control
1
Set the scope
Which system, which data, and what may you break? Written and approved before the first attempt.
2
Build the scenarios
Prompt injection, context leakage, voice impersonation, source poisoning, control bypass.
3
Execute, on record
Every attempt with its date, its exact text and its result. What is not documented did not happen.
4
Estimate the impact
What does the business lose if this attempt really succeeds? In money, reputation and obligation.
5
The counter-control
One control for each confirmed hole, with an owner and a date.
6
Retest
The same attempt is repeated after the control. No hole is closed except by a failed attempt.
■ The attacking side■ The estimate■ The defending side

The sixth step is what separates a professional red team from a performance: a hole is not closed by the report, but by repeating the attempt and having it fail.