Horizon 02
Cyber & Resilience
Adversarial behaviour, systemic dependency, and what it takes to keep operating when an assumption fails.
New capability creates new exposure.
The shift
Security is usually described as a contest between attackers and defenders. That framing is accurate and incomplete. Many consequential failures are not elegant intrusions; they are ordinary dependencies discovered at an inconvenient moment.
Every capability an organisation adopts is also a new thing that must keep working. The supplier, the model, the identity provider, the certificate, the API — each is a quiet assumption. Resilience is the discipline of knowing which assumptions are load-bearing.
Adversaries also adopt new technology, on roughly the same curve as everyone else and typically with fewer procurement constraints.
Some risks begin as capabilities. Others begin as dependencies.
What we ask
- What must remain available for this to keep working?
- Which single supplier failure would be indistinguishable from an outage of our own?
- What does an adversary have cheap access to that they did not have last year?
- How long could this run in a degraded state before anyone outside noticed?
- What is the recovery path when the failed component is one we do not control?
Lines of inquiry
- 01
Emerging attack surface
New interfaces arrive faster than the practices for securing them. We examine exposure created by model endpoints, tool integrations, automation, and the proliferation of machine identity.
- 02
Systemic and supply dependency
Concentration is efficient until it is correlated. We look at where many organisations independently depend on the same small number of components, and what that means for failures that arrive everywhere at once.
- 03
Adversarial capability
The useful question is not what a technology enables in principle, but what it lowers the cost of in practice — for reconnaissance, for social engineering, and for operating at scale.
- 04
Operating through failure
Resilience is measured on the worst day, not the average one. We are interested in degraded modes, manual fallback, and whether recovery plans survive contact with the dependency that actually failed.
Resilience is measured on the worst day.
If you are trying to establish which of your dependencies are genuinely load-bearing, that is the kind of question we like.