A doctrine defines how a force operates, functioning as operational law rather than optional guidance. Security Unconventional Warfare, or SUW, runs on six rules that shape how operators and leaders act, each one built to counter something attackers rely on and exploit something they cannot easily fix. Treating these rules as suggestions rather than law is how organizations lose the asymmetric advantage that unconventional defense is supposed to provide.
The six rules are:
- Disrupt constantly
- Break the asymmetry by raising cost
- Treat fundamentals as force multipliers
- Act with precision
- Stay quiet and prepare unseen
- Adapt faster than adversaries
Attackers depend on a predictable rhythm, moving through reconnaissance, initial compromise, privilege escalation, lateral movement, and persistence generally in that order, which lets them plan, allocate resources, and run campaigns efficiently. The rule to disrupt constantly breaks that rhythm, forcing adaptation instead of rehearsed execution, and compresses the OODA Loop. Passive defense gives attackers a stable environment in which to learn and adjust, while active disruption forces them to spend time solving problems they did not expect, and this has to run continuously rather than in occasional bursts, since sporadic disruption becomes predictable and attackers learn to time around it. In practice, that means placing decoy systems in critical segments where they look like real targets, forcing attackers to question whether what they have accessed is genuine, and rotating credentials and keys in development environments often enough to break the persistence mechanisms attackers try to establish.
Traditional security also suffers from a mathematical disadvantage, since attackers can try forever while defenders have to block every single attempt to stay safe, and that asymmetry becomes hard to sustain with limited resources against unlimited persistence. Breaking the asymmetry by raising cost was put in place to address this, shifting focus from perfect prevention toward making every attempt expensive in time, resources, and exposure, since a rational adversary moves on to an easier target once attacking costs more than a successful compromise is worth. Raising cost works across several dimensions at once, hitting time, resources, skill, and risk together. Hardening privilege elevation pathways means an attacker cannot go from stolen credentials to administrative access in one step and needs real skill and time instead, deceptive credentials and honeypots force attackers to burn stealth investigating false leads, every mistake an attacker makes generates a log entry and an alert that pushes the burden of avoiding detection onto them, and controlled obstacles at segmentation boundaries turn lateral movement into multiple separate compromises rather than a single pivot.
However, none of this works against an organization that skips the basics, which is why the rule to treat fundamentals as force multipliers rejects the idea that they are passive maintenance. An organization that pursues unconventional warfare before mastering basic hygiene tends to build expensive distractions that mask real vulnerabilities, and adversaries just route around the elaborate deception by exploiting an unpatched system or a misconfigured account instead. Asset visibility lets deceptive systems get placed precisely, identity discipline keeps legitimate accounts from undermining honeypot credibility, and segmentation gives disruption tactics a controlled space to operate without risking business continuity. Every unconventional tactic should tie back to a Brutalist Security fundamental rather than living as its own separate program, so honeypot accounts fit into regular identity review cycles, patching stays current before deception gets attempted, and segmentation gets priority so disruption stays contained.
Broad defensive action creates noise and overhead without much gain in protection, so acting with precision forces the concentration of limited resources where the impact is greatest. Unfocused effort often protects low-value assets with the same intensity as critical systems while leaving the real targets under-defended, even though most incidents aim at specific data or capabilities rather than total network compromise, which gives defenders room to concentrate. That means protecting the assets that really carry business and adversary value first, accepting calculated risk elsewhere rather than pretending every system deserves equal protection. This is where the consequence map comes into place. This map is a working system list and a reasonably complete identity inventory that drives every prioritization decision in the program, with systems listed by how existential and critical they are to the business. A handful of well-designed, carefully maintained traps beat dozens of poorly managed decoys that add overhead without reliable detection, and monitoring tuned around a few critical behavioral baselines catches unusual privilege use and abnormal administrative activity while routine noise gets filtered out automatically.
The rule to stay quiet and prepare unseen covers two sides of the same discipline. Security teams need to run their missions without chasing external recognition, because public talk about security gives intel to adversaries, who can use it to adapt. That means limiting knowledge of unconventional capabilities to people with am operational need, avoiding conference talks or case studies that describe specific techniques, and compartmentalizing information about deception assets strictly. Success gets celebrated internally through discipline metrics and capability improvement rather than media coverage, and operators learn early that professional satisfaction comes from control and effectiveness rather than external validation.
The same silence has to extend into how the work gets prepared. Most successful unconventional defense happens before an attacker ever tries anything, through planning, internal reconnaissance, and training that shape outcomes long before an actual incident, and this preparation has to stay invisible; visible preparation reveals priorities and capabilities that let attackers adapt ahead of time. Deception assets and traps need weeks or months of hardening before they face a real attacker, since hastily built honeypots contain obvious flaws that experienced attackers spot easily. Red team exercises under controlled conditions keep operators sharp and expose weaknesses before adversaries find them, contingency playbooks for likely scenarios such as credential theft or segmentation failure need regular testing rather than a scramble during an actual emergency, and threat intelligence should drive quiet tactical preparation rather than broad organizational awareness campaigns.
Adversaries change their tools and techniques constantly after hitting resistance, so the team need to adapt faster than adversaries, requiring defenders to move even quicker to keep the advantage. A static defensive posture becomes a predictable vulnerability that a patient attacker eventually studies and defeats, while continuous tactical evolution forces attackers to keep investing in reconnaissance instead of running proven playbooks. This adaptation needs to be systematic rather than chaotic, because random configuration changes create new vulnerabilities without buying real improvement. After-action reviews within 24 hours of a significant event capture lessons learned while the details are still fresh, and those lessons need to get built into doctrine and daily procedure rather than living in a slide deck nobody revisits. Training should reflect current adversary tactics as well, and rotating operators across roles within the defense cell keeps perspectives fresh and prevents the team from getting too comfortable with what it already knows.
Leaders carry the responsibility for making all six rules stick. That means enforcing doctrine as operational law rather than optional guidance, and measuring adherence against the rules themselves rather than activity counts. Cultural violations, especially ego-driven publicity seeking or quiet neglect of fundamentals, need a decisive response, and leaders need the courage to shield quiet professionals from pressure to disclose operational details for the sake of external recognition.
I can give you the example of a technology company's security team that put this doctrine to work after detecting reconnaissance against its development environment. Operators deployed deceptive credentials that appeared to unlock intellectual property but actually led nowhere real, all while triggering full monitoring, and when an attacker used those credentials, logging captured the source IP, the authentication method, and every subsequent command while silently redirecting the session into a controlled environment. Over the next several hours, the team watched the attacker download fabricated intellectual property, attempt privilege escalation with a known exploit framework, and set up persistence that provided no real access at all.
The activity pointed to a sophisticated actor using a custom variant of a commercial penetration testing framework, targeting machine learning algorithms and customer data code specifically, which gave the team useful intelligence about the attacker's real objectives. The attacker spent time trying to confirm the environment was real, which told the defenders the attacker had no prior knowledge of the company's actual defensive setup. The operators used the information learned as the attacker was busy with the fake environment to strengthen monitoring on real assets, adding additional controls on the fly. When the attacker eventually tried to move laterally out of the honeypot, the company's actual segmentation controls caught and contained them cleanly, and the attacker retreated after 18 hours of wasted effort, never realizing the whole engagement had been staged.
The operation was a success because leadership treated doctrine as law and operators applied creativity within disciplined limits. The entire success stayed invisible to anyone outside the team. Applied without that discipline, unconventional defense risks becoming expensive noise. Applied with it, a small security cell can produce an asymmetric advantage against adversaries who outnumber it many times over.