July 23, 2026
Security Is War
Why winning means fighting fewer battles, not harder ones.

By happyelf
6 min read
— -
The art of war is of vital importance to the State. It is a matter of life and death, a road either to safety or to ruin. Hence it is a subject of inquiry which can on no account be neglected.
Sun Tzu, The Art of War, Laying Plans (trans. Lionel Giles)
In my last essay I argued that your data is cash. Here is the uncomfortable next step. Cash this valuable is already drawing people toward it, which means you are at war whether you declared one or not. So let me tell you one of the first mistakes many new defenders make, because I made it too.
The mistake is to see enemies everywhere.
You read your first incident report, you feel the violation of it, and suddenly every user is a risk, every unpatched server a betrayal, every contractor a possible spy. You want to fight all of it at once. And if you try, you will lose. Not because you are wrong about the danger, but because a general who treats everyone as the enemy has already given up his only real advantage: the freedom to choose his battles.
Sun Tzu described this trap twenty-five centuries ago. Reinforce the front, and the rear grows weak; reinforce the rear, and the front does; try to be strong everywhere, and you end up strong nowhere. The defender who insists on guarding all of it equally has, in that very act, made all of it weak.
It took me years to learn the way out, and it is stranger than it sounds. Most of what looks like an enemy is not one, or does not have to be. The real art of this war is not fighting harder. It is turning most of your enemies into something that is not an enemy at all, until the number of wars you actually have to fight is small enough to win. You win by subtraction.
So let me walk you through the faces of the "enemy," in the order that matters, and show you how each one you can turn is one fewer battle you have to fight.
The "enemy" you build yourself
The most dangerous adversary I have ever faced did not come from outside. I built it. Or rather, a design did, and I let it stand.
You cannot leave a slab of rotten meat on the table and act surprised when the flies come. Every system that puts something valuable within easy reach, and then relies on people simply choosing not to take it, is rotten meat. The question is never whether the flies are bad. It is why you left the meat out.
Let me tell you about the cleanest example I have ever seen. To make it easier for customers to claim their codes, the business wanted a new interface built around personal information the user already carried: something predictable, reusable, and never designed to be a secret. No password to remember. Convenient. A small new door, no changes to the system, everyone happy.
The interface was known to the project team. Security was simply not part of the design review. The failure was not that one person forgot to send a message. It was that a new way to log in could go live without anyone independent ever asking whether it was safe.
It was not. Information that is predictable is not a password. It looks like authentication, but it offers almost no resistance to a patient script, and the safeguards against automated attempts were not strong enough. It looked like a lock. It was theater. We had set the users' own identities on the table and planted a little flag beside them that read password.
This was the same kind of failure I described last time: value placed behind a door nobody had properly assessed. The incident that taught me data is cash was not bad luck, and it was not a brilliant hacker. It was a design that assumed people would behave, wrapped around something that was worth misbehaving for.
This is why the first battle of any security war is not fought against an attacker at all. It is fought at a whiteboard, months earlier, when someone is deciding how the system will work. It is the cheapest battle you will ever win, if you are in the room. The tragedy is how often security is not in the room until long after the meat has been left on the table.
## The allies who look like liabilities
Now to the people inside your own walls, and the first real act of subtraction. This is where a book is supposed to get dramatic, as if you turn an enemy into a friend with a single stirring speech. In practice, security and IT already work side by side every day. The friction, when it comes, is rarely institutional. The policy itself may be, but the friction becomes personal at the point where someone actually has to carry it out.
You do not win that one by force. The moment it becomes a contest of authority, you have made an enemy out of someone who should be your strongest wall. You win it by making the safe path the path of least resistance, so that doing the right thing and doing the easy thing finally point the same way. You reframe the rule as protection rather than a leash. Follow the safe path, and the organization stands behind the decision: if something breaks, it is not on you. Ignore it, and it is. And if you think the rule itself is wrong, you do not quietly work around it: you bring it to us, and from that moment it is our duty to carry forward, not yours to carry alone. The only path that still ends on you is the one that goes around us. In one move, compliance stops being a burden and becomes the cheapest insurance they will ever buy. People will always look for somewhere to raise a risk, and I would rather they bring it to the team built to deal with it than bury it where no one is looking.
The careless were never your enemy. They are recruits you had not signed yet.
The insider risk you can deter
Some insiders are not careless. They mean it. A code that converts straight to cash is a temptation, and some people, in the wrong moment, will reach for it. This is the malicious insider, and they frighten executives more than any outside hacker, because they are already past the walls and they know where the treasure sleeps.
But this risk, too, can be made smaller, because you can change the math around it. You will never make misuse impossible, and you should stop trying. What you can do is make it harder, more visible, and not worth it.
One that actually happened. A pool of redeemable value inside the company turned out to be poorly reconciled and lightly watched. A few people noticed, and began using it for things it was never meant for. We caught the pattern only because some of it moved the way normal work never does, out through channels it had no reason to take.
The part worth keeping is what we did next. We reconciled the inventory, closed the gap in who could reach what, clarified the policy, and only then made the monitoring visible. The point was not surveillance for its own sake. It was to remove any ambiguity about what was allowed, and to make misuse both easy to catch and not worth attempting. We did not see the same pattern again. Containing that kind of risk is not another wall. It is an environment where what is valuable is accounted for, misuse becomes visible, and everyone knows it.
The adversary you cannot turn
Strip away the ones you can design out, recruit, and contain, and what remains is the adversary you cannot turn. You cannot bind them with a contract, deter them through HR, or train them into vigilance. They owe you nothing. They are often a stranger you will never see. And here is the whole asymmetry of it: they choose the time, the place, and the weapon, while you have to hold a far wider surface, across far more time, with resources that never cover all of it. They only need one narrow path to work, and they can keep trying until it does.
That is an unfair fight, and pretending otherwise is how defenders burn out and budgets bleed. You will not stop every attempt, and you should not build as if you could. What you can do is make sure no single failure is the whole story: you layer your defenses, so that when one gives way, another still holds. That is the adversary who makes security a war and not a checklist.
Winning by subtraction
So when I say security is war, I do not mean you should arm every wall and brace for a siege on all sides. I mean the opposite. The defender who tries to fight everywhere loses, because finite resources spread across every threat at once become the same as no resources at all.
You win by subtraction. You design away the enemy you would otherwise create. You recruit the careless into your own ranks. You contain the malicious until betrayal is not worth it. And only then, with your forces no longer scattered across three wars that never had to happen, do you turn to face the one enemy who was always going to require a real fight.
What remains, in this case, is a single, coldly rational adversary: someone who picked the fastest route from data to cash and weighed effort against reward. They are doing economics. You will not out-fight them by fighting harder. You out-fight them by spending smarter, by knowing, down to the last asset, what is worth defending and what you are willing to lose.
Which means the person who wins this war is not, in the end, a soldier at all. They are an accountant who happens to be holding a sword.
— -
Next, I want to talk about that accountant with a sword. An accountant counts what a thing is worth. A general decides where to point the blade. Put both in one person, and the moment they weigh what is worth defending and where the blade will do the most, they are no longer either. They have become an economist.
Author's note: This essay is based on real events. Some details have been changed to protect confidentiality.