Degree 4
Protection
The gate of this degreeA miniature red-team test and a cognitive defence plan.
You can now produce work with the tool. What you learn here is how you get attacked — both the system you have built and the mind that runs it. This degree brings classical information security, model security and cognitive security together into a single defence.
OPENING STORY
Why Fawzooz built a shield that protects no server
After the night of the transfer I described at the start of this programme, Fawzooz sat down to analyse the incident as he would analyse any breach. He filled pages with the layers: network, identity, application, data. In every one of them the controls were sound. Then he wrote a line at the bottom of the page that changed the whole direction of his work: "the layer that was breached is not on the list."
There was no place anywhere in the security models called "cognition". We protect data from leaking, systems from stopping and identities from impersonation — and we do nothing at all to protect an employee's conviction from being shaped. Once systems could manufacture a voice, an image and persuasive text at almost no cost, that layer became the cheapest attack surface available and the one that pays best.
Out of that single line came what was later named the "cognitive shield", and then the cognitive security maturity model you will work with in the next degree. What this degree gives you is the foundation both were built on: how intelligent systems get attacked, how your own mind gets attacked, and why the two defences cannot be separated.
Six steps that turn a random attempt into a report someone can decide on — the spine of this degree.
The sixth step is what separates a professional red team from a performance: a hole is not closed by the report, but by repeating the attempt and having it fail.
