In my previous article, The Illusion of Security: When Trust Becomes Passive, I argued that a dashboard is not the infrastructure.
It is a representation of the infrastructure.
That distinction sounds obvious.
But modern cybersecurity is built on forgetting it.
We look at the vulnerability count and assume it represents exposure.
We look at the SIEM and assume it represents activity.
We look at an attack surface dashboard and assume it represents everything that exists.
We look at a risk score and assume it represents risk.
We look at an AI-generated summary and assume it represents understanding.
But none of these things are reality.
They are interpretations of reality.
And once that becomes clear, a more difficult question appears.
How do we know that what we believe about our environment is actually true?
That is not only a cybersecurity problem.
It is an epistemology problem.
And the deeper I look at modern security operations, the more I suspect we have been treating the two as though they were unrelated.
The Security Industry Has Become Very Good at Producing Answers
A modern security team rarely suffers from a lack of information.
Endpoints generate telemetry.
Firewalls generate logs.
Identity platforms generate authentication events.
Cloud environments generate audit trails.
Vulnerability scanners generate findings.
Threat intelligence platforms generate indicators.
Attack surface platforms generate inventories.
Risk engines generate scores.
AI systems now sit above all of them and generate explanations.
Every layer produces another interpretation.
The security team ends up surrounded by answers.
That sounds like progress.
Sometimes it is.
But there is a hidden assumption inside the entire architecture:
more information must produce better understanding.
That assumption deserves investigation.
Because information is not knowledge.
And knowledge is not truth.
Before information becomes useful, somebody or something has to interpret it.
The scanner interprets a service.
The SIEM interprets an event.
The detection rule interprets behaviour.
The analyst interprets the alert.
The AI interprets the analyst's evidence.
Every step adds context.
Every step also creates the possibility of distortion.
Cybersecurity rarely observes reality directly.
It observes reality through layers.
That is where the epistemology problem begins.
The Scanner Says 2,431 Vulnerabilities Exist
Imagine opening a vulnerability dashboard and seeing:
2,431 vulnerabilities detected.
The number feels objective.
It has precision.
Precision creates authority.
But what does the number actually tell us?
It tells us that a particular scanning system, using a particular detection method, with a particular level of access, at a particular moment in time, observed 2,431 conditions matching its vulnerability logic.
That is not the same statement.
The scanner may not know about every asset.
It may not reach every network segment.
Authentication may have failed.
A temporary workload may have disappeared before the scan.
An externally exposed service may never have entered the inventory.
A vulnerability rated Critical may be practically unreachable.
A lower-rated weakness may become dangerous only when combined with identity exposure, weak segmentation or an overlooked trust relationship.
None of this makes vulnerability scanning useless.
Quite the opposite.
It makes interpretation essential.
The interesting question is not simply:
What did the scanner find?
The more important question is:
What had to be true for the scanner's conclusion to be reliable?
That one question changes vulnerability management from counting findings into understanding evidence.
And that distinction matters because attackers do not attack vulnerability counts.
They attack conditions.
Attackers Have Always Been Epistemologists
Not in the academic sense.
In the practical one.
A good attacker spends enormous effort trying to understand what the defender believes.
Which systems are trusted?
Which identities are privileged?
Which vendor relationships bypass scrutiny?
Which alerts are routinely ignored?
Which behaviours look normal?
Which tools are assumed to be authoritative?
Which network segments are believed to be isolated?
The attacker is not only searching for a technical weakness.
They are searching for a gap between reality and the defender's model of reality.
That gap can be more valuable than a vulnerability.
The SolarWinds compromise is a useful example.
The technical story is well known.
Malicious code was inserted into legitimate SolarWinds Orion software updates and subsequently distributed through a trusted software channel.
But the technical description hides the more interesting pattern.
The attacker exploited an assumption.
The assumption looked something like this:
Trusted supplier + legitimate software update + valid signing process = trusted software
That assumption was reasonable.
That is precisely why it was valuable.
The adversary did not merely break through a security control.
The adversary entered through the logic that told organizations the control was trustworthy.
This is an important shift in perspective.
A vulnerability exists inside software.
An assumption exists inside the defender.
Both can be exploited.
We Rarely See the Attack
Security investigations are exercises in reconstruction.
A suspicious login.
A PowerShell execution.
A new administrative account.
An unusual DNS request.
A connection to unknown infrastructure.
A process spawned from an unexpected parent.
None of these is the attack itself.
They are traces.
From those traces, analysts build explanations.
That makes cybersecurity surprisingly similar to forensic investigation.
A forensic investigator rarely watches the crime happen.
They examine residue.
Position.
Sequence.
Timing.
Relationships.
Contradictions.
Then they attempt to reconstruct the most plausible version of events.
Cybersecurity analysts do the same thing.
The log is not the incident.
The alert is not the incident.
The indicator is not the incident.
They are observations from which a narrative is constructed.
The problem is that humans are not passive interpreters.
Once we begin believing a narrative, we tend to notice evidence that supports it.
Psychology calls this confirmation bias.
Cybersecurity often disguises it as investigation.
We find one suspicious artefact.
A hypothesis forms.
Then we keep gathering evidence that strengthens the hypothesis.
The investigation gradually shifts from:
What happened?
to:
How can I prove what I think happened?
The difference is subtle.
The consequences are not.
What Would Prove You Wrong?
Karl Popper argued that strong scientific ideas should expose themselves to falsification.
The point was not simply to collect evidence that supports a theory.
The point was to ask whether the theory could survive serious attempts to disprove it.
That idea belongs surprisingly well inside threat hunting.
Suppose an analyst believes:
This endpoint is compromised.
Evidence appears.
Suspicious PowerShell.
An unusual login.
A new persistence mechanism.
An outbound connection to infrastructure with a poor reputation.
The hypothesis now looks strong.
But there is another question the analyst should ask:
What evidence would make me change my mind?
Perhaps the PowerShell process belongs to an approved automation tool.
Perhaps the authentication anomaly came from legitimate administrative activity.
Perhaps the IP reputation data is stale.
Perhaps the suspicious persistence mechanism belongs to sanctioned software.
The objective is not to become paralysed by doubt.
It is to prevent plausibility from quietly becoming certainty.
There is a significant difference between:
I found evidence that supports my conclusion.
and:
My conclusion survived serious attempts to disprove it.
The second produces stronger analysis.
It also requires something cybersecurity does not always reward.
Intellectual discomfort.
The Map Is Not the Territory
Alfred Korzybski famously argued:
The map is not the territory.
A map represents reality.
It simplifies reality.
It has to.
A map containing everything would be as complicated as the territory itself.
Cybersecurity is full of maps.
A risk score is a map.
A SIEM dashboard is a map.
A vulnerability report is a map.
An attack surface inventory is a map.
A compliance assessment is a map.
An AI-generated incident summary is a map.
The problem is not that we use maps.
The problem begins when we forget they are maps.
A dashboard might say:
Attack surface under control.
But the more accurate statement would be:
Based on the assets our discovery mechanisms currently know about, using the evidence available to us, interpreted under our current assumptions, we have not observed enough information to conclude otherwise.
Nobody wants that sentence on an executive dashboard.
So we replace it with green.
That is understandable.
Green is efficient.
Green is readable.
Green is comforting.
But green also compresses uncertainty.
And once uncertainty disappears from the visual interface, it often disappears from the conversation.
The map becomes the territory.
The score becomes the risk.
The dashboard becomes the truth.
Cybersecurity Has a Certainty Habit
Security platforms communicate with remarkable confidence.
Critical.
Malicious.
Trusted.
Compliant.
Secure.
High Risk.
These labels are useful.
Organizations need classification to make decisions.
But classification has a behavioural consequence.
It creates the feeling that uncertainty has been resolved.
A Critical vulnerability may be technically severe but operationally irrelevant in one environment.
A Medium vulnerability may become strategically important when combined with exposed identity infrastructure.
An IP address classified as malicious may later be reassigned.
A compliant organization may still be compromised.
A device shown as healthy may simply exist outside the visibility of the tool declaring the environment healthy.
The deeper problem is not inaccurate labels.
It is the human tendency to treat labels as reality.
The moment a judgment becomes a category, it gains authority.
The moment it receives a colour, it gains confidence.
The moment it enters a dashboard, it becomes organizational memory.
This is how uncertainty slowly transforms into fact.
Not because anybody intended to deceive.
Because simplification is necessary.
And necessary simplification is easy to mistake for truth.
Then We Added AI
The epistemology problem becomes more interesting when AI enters the chain.
Imagine an analyst investigating unusual activity.
The analyst asks an AI system to explain the event.
The AI references a threat intelligence platform.
The threat intelligence platform aggregates multiple providers.
Those providers rely on automated classification, sensors, community submissions, historical observations and other intelligence sources.
The chain now looks something like this:
Each layer transforms the evidence.
The event becomes telemetry.
The telemetry becomes an alert.
The alert becomes intelligence.
The intelligence becomes a summary.
The summary becomes a decision.
At each stage, interpretation increases.
So does distance from the original event.
I think this deserves a name:
epistemic distance.
Epistemic distance is the space between what actually happened and the final conclusion we eventually act upon.
The greater that distance becomes, the more difficult it is to distinguish observation from interpretation.
AI does not create this problem.
It amplifies it.
Previously, an analyst might manually inspect multiple sources.
Now the synthesis appears instantly.
That improves speed.
It also creates a dangerous psychological shortcut.
Fluent language feels authoritative.
A coherent explanation feels complete.
A confident answer feels researched.
Human beings are remarkably vulnerable to explanations that make sense.
That may be AI's most interesting cybersecurity risk.
Not that it can produce nonsense.
But that it can produce nonsense that fits beautifully into the story we already wanted to believe.
The Most Dangerous Attack May Be the One That Makes Sense
Attackers understand something security engineering sometimes forgets.
Humans are pattern-seeking machines.
We are uncomfortable with ambiguity.
When fragmented evidence appears, the brain tries to turn it into a coherent story.
This is useful.
Without that ability, investigation would be impossible.
But coherence is not the same as correctness.
A phishing message works because the story makes sense.
The CEO needs something urgently.
The finance department expects the invoice.
The cloud provider needs the credentials verified.
The software update comes from the trusted supplier.
The login page looks familiar.
The attack succeeds not because the victim stopped thinking completely.
Sometimes it succeeds because the victim thought inside the wrong model.
That distinction is important.
A good social engineer does not always need to deceive your eyes.
They need to satisfy your expectations.
The same principle applies to security operations.
If evidence arrives in a pattern we already understand, we process it faster.
Daniel Kahneman via his article Judgment under Uncertainty: Heuristics and Biases described how human judgment frequently depends on fast cognitive shortcuts.
Those shortcuts are not stupidity.
They are efficiency.
But efficiency becomes dangerous when attackers learn the shortcut.
The adversary does not always need to hide from your detection systems.
Sometimes it is enough to produce signals that your systems already know how to interpret incorrectly.
Security Has Always Been About Knowledge
Traditional cybersecurity questions usually sound technical.
Is the endpoint compromised?
Is the account legitimate?
Is the software vulnerable?
Is the vendor trustworthy?
Is the alert malicious?
But underneath each question is another question:
How do we know?
That is where epistemic security begins.
I use epistemic security to describe the protection of the integrity, reliability and quality of the knowledge upon which cybersecurity decisions depend.
Traditional security asks:
Is this system compromised?
Epistemic security asks:
How trustworthy is the evidence telling us that the system is compromised?
This introduces four practical dimensions.
Evidence Quality
Is the evidence current?
Complete enough?
Accurate?
What can the sensor observe?
More importantly:
What lies outside its visibility?
A blind spot is not simply missing data.
It is missing reality.
Source Reliability
Where did the information originate?
Primary telemetry?
A vendor?
Threat intelligence?
Community reporting?
AI-generated synthesis?
How many transformations separate the current conclusion from the original evidence?
The more transformations occur, the easier it becomes for context to disappear.
Interpretive Integrity
Are observation and inference being treated as different things?
What assumptions are influencing the conclusion?
What alternative explanations exist?
Are contradictory signals being investigated or discarded?
Correct evidence can still produce an incorrect conclusion.
The failure may not be in collection.
It may be in interpretation.
Epistemic Confidence
How certain should we actually be?
There is an important difference between saying:
This activity is malicious.
and saying:
Based on the available evidence, we assess with high confidence that this activity is malicious.
The second statement does not weaken the conclusion.
It exposes the reasoning standard behind it.
It leaves space for revision.
It forces us to remember that evidence can change.
That is not indecision.
It is epistemic humility.
The Problem Is Not Lack of Visibility
For years, cybersecurity has treated visibility as one of its greatest objectives.
More logs.
More sensors.
More telemetry.
More integrations.
More attack surface discovery.
More threat intelligence.
More automated analysis.
More AI.
But visibility has a hidden assumption.
It assumes that what becomes visible will also become understandable.
That is not guaranteed.
You can collect more telemetry and still construct the wrong explanation.
You can improve detection and still misunderstand the attacker.
You can automate analysis and automate a false assumption.
You can build the most beautiful executive dashboard in the organization and still be looking at an incomplete map.
The real challenge may therefore be less about seeing everything.
It may be about understanding the limits of what we see.
That requires separating four things:
What happened.
What the system observed.
What the system inferred.
What the human concluded.
Those are not the same thing.
The space between them is where uncertainty lives.
It is also where attackers operate.
Perhaps the Next Security Control Is Doubt
Cybersecurity spends enormous effort trying to eliminate uncertainty.
Maybe that is the wrong ambition.
Uncertainty cannot always be eliminated.
It can only be understood, measured and challenged.
This creates an uncomfortable possibility.
Perhaps good cybersecurity is not about becoming increasingly certain.
Perhaps it is about becoming increasingly disciplined about what deserves certainty.
That would change the analyst's role.
The analyst of the future may not be the person who knows the most threat actor names.
It may be the person who asks better questions.
Where did this evidence come from?
What assumptions does this conclusion depend on?
What can our tools not see?
What other explanation fits the evidence?
How confident should we be?
What would prove us wrong?
Those questions sound philosophical.
They are also operational.
Because every security decision is ultimately an act of belief.
We believe an alert is malicious.
We believe a vendor is trustworthy.
We believe a device is clean.
We believe a control is working.
We believe an AI-generated explanation is accurate.
And eventually, we act on those beliefs.
The attack surface therefore extends beyond systems, identities and software.
It includes the way we construct knowledge about them.
That may be the blind spot.
We keep asking whether our technology can be trusted.
We spend less time asking whether our understanding of that technology deserves the same trust.
And perhaps that is where the next generation of attacks becomes interesting.
The attacker may not need to make you blind.
They may only need to make you certain.
How much of what we call security is actually knowledge, and how much is simply confidence in a story we have not yet tried hard enough to disprove?
I will leave the philosophical reflection here for now. See you in the next post, where we will explore a different topic.

Post a Comment
0Comments