Infosec Stoic
@infosecstoic@infosec.exchange
infosec.exchange
Most breaches aren't the result of exotic zero-days or genius attackers. They're controls everyone believed were operational that had quietly decayed, or were never fully in place to meet the original intent.
@philvenables@infosec.exchange makes the case for Control Reliability Engineering: apply SRE discipline to security controls. SLIs/SLOs for control health, error budgets to govern acceptable failure, blameless postmortems and root-cause analysis when a control fails, production-readiness gates before a control is trusted.
The reframe I like: control strength stops being a checkbox and becomes a measured, decaying property you have to engineer for. Same gap I keep seeing in assessments, controls assumed working, never verified.
https://www.philvenables.com/post/control-reliability-engineering-cre-applying-sre-principles-to-cybersecurity-controls