In 1970, Willis Ware delivered a classified report to the Defense Science Board that laid out the fundamental security problems of multi-access computer systems. The report was honest about the challenge. Contemporary technology, Ware wrote, could not provide a secure system in an open environment. DARPA had organized the task force in 1967 after a defense contractor in St. Louis wanted to sell spare compute time on a classified mainframe to local businesses. Nobody had a policy for that because nobody had thought about it.
Fifty-six years later, we still haven’t solved the problem Ware identified. We’ve surrounded it with compliance regimes, attestation requirements, control catalogs, and assessment frameworks. We’ve spent billions. And every year, compliant organizations get breached, compliant networks get owned, and compliant enterprises write checks to incident response firms to clean up the mess that compliance was supposed to prevent.
The cybersecurity industry has a structural problem, and it isn’t a lack of frameworks. It’s that the frameworks we built address the wrong question. There will be people who read that sentence and dismiss it as theoretical, idealistic, the kind of thing someone says when they haven’t had to sit across from an auditor or explain a failed assessment to a board. Those people have had fifty-six years to make their approach work. The results speak for themselves.
The Word We Forgot
The prefix “cyber” traces back to Norbert Wiener, a mathematician who studied anti-aircraft fire control systems during the Second World War. Wiener’s work on radar prediction problems led him to a theory of feedback, control, and communication between systems and their environments. He published it as Cybernetics: Or Control and Communication in the Animal and the Machine in 1948 and followed it with The Human Use of Human Beings in 1950.
Wiener’s cybernetics was about closed-loop adaptation. A system observes its environment, processes feedback, adjusts its behavior, and observes again. The loop runs continuously. The system adapts or it fails.
The field that inherited Wiener’s prefix stripped out his core concept and kept only the label. Cybersecurity as practiced today has almost nothing to do with cybernetics as Wiener theorized it. That isn’t trivia. It’s a diagnostic. We named the discipline after continuous adaptive control and then built it around annual attestation. The irony would be funny if the consequences weren’t measured in billions of dollars and compromised national security.
What Every Other Security Domain Knows
In 1952, Harold Smith opened the Smith System Driver Improvement Institute in Detroit and built a perception-based framework for defensive driving that’s still taught today. Driver education evolved the concept through SIPDE (Search, Identify, Predict, Decide, Execute) and then refined it into IPDE (Identify, Predict, Decide, Execute). The Motorcycle Safety Foundation moved through its own versions: SIPDE in early courses, SPA (Search, Predict, Act) in the 1989 Experienced RiderCourse, and eventually SEE (Search, Evaluate, Execute) in the current Basic RiderCourse.
These aren’t academic exercises. They’re cognitive loops designed to keep operators alive in dynamic environments where threats emerge, move, and change faster than any checklist can catalog. A driver scanning an intersection runs IPDE in under a second. Identify the kid chasing the ball. Predict trajectory. Decide to brake. Execute. Then cycle again because the minivan behind you may not have seen the same thing.
John Boyd developed the OODA loop (Observe, Orient, Decide, Act) from his experience in air combat. The framework has since been applied across military strategy, business, and, nominally, cybersecurity. But most applications flatten Boyd’s thinking into a four-step sequence, which misses his central insight entirely. For Boyd, Orient was the center of gravity. Everything feeds back through orientation, which is shaped by experience, culture, prior training, and the accumulated mental models that determine what an operator sees when looking at ambiguous data. The loop isn’t a checklist. It’s a continuous reorientation process with implicit guidance feeding directly from Orient to Action without always passing through Decide.
Bob Gourley, the former CTO of the Defense Intelligence Agency and founder of OODA LLC, has spent years trying to bring Boyd’s actual thinking into the cybersecurity conversation through OODAcon and his broader work. He’s been candid about the problem: most people who invoke the OODA loop in corporate settings are committing exactly the linearization error that Boyd warned against. As Gourley has pointed out, the intelligence cycle (collect, process, analyze, disseminate) fails for the same reason the four-step loop fails when taught as a sequence. The adversary is moving while you’re still in phase two.
Gary Klein’s research on Naturalistic Decision Making offers another lens. Klein studied how firefighters, military commanders, and ICU nurses make decisions under time pressure and uncertainty. His Recognition-Primed Decision model found that experienced operators don’t compare options. They recognize patterns, mentally simulate one course of action, and execute or adjust. That’s not a process you can reduce to a control catalog. It’s a trained cognitive capability that develops through repeated exposure to ambiguous, contested environments. The Marines and Army incorporated Klein’s RPD model into their command and control doctrine. Cybersecurity education hasn’t touched it.
The Category Error
Every one of those domains, driving, aviation, special operations, law enforcement, treats rules as boundaries around an adaptive process. A fighter pilot operates within Rules of Engagement, but ROE doesn’t tell the pilot how to fly the engagement. It tells the pilot what targets are authorized and under what conditions. The pilot still has to observe, orient, decide, and act inside those constraints at combat speed. A tier 1 special operator works within mission parameters and the law of armed conflict, but nobody hands them a 400-control catalog and asks them to attest annually. The constraints are the box. The adaptive decision cycle is what happens inside the box.
In cybersecurity, compliance replaced the adaptive process. The control catalog isn’t the boundary. It is the activity. The SOC analyst isn’t running a perception-decision loop bounded by policy. The analyst is checking alerts against a playbook that was written to satisfy an audit finding. The CISO isn’t orienting against a shifting adversary. The CISO is preparing for an assessment. The entire organizational energy gets redirected from “what is the adversary doing and how do I counter it” to “can I prove I did what the auditor expects.”
Consider the operational reality. A single SOC analyst may face hundreds of events per shift. A mature security operation generates thousands. Each one demands a perception-decision cycle: is this signal real, what does it mean, what do I do about it, did my action work? That is a cognitive workload closer to an air traffic controller or a combat pilot than to an accountant. And yet the compliance model tries to force this work into something resembling GAAP, Generally Accepted Accounting Principles, where every transaction is discrete, every entry is auditable, and the books balance at the end of the quarter. Security events are not ledger entries. They’re ambiguous, time-sensitive, adversary-driven, and they don’t wait for the audit cycle. Treating a SOC like a financial reporting function doesn’t just slow the operation down. It misframes what the operation is.
This isn’t the usual complaint that organizations do compliance badly, that they game scope, mangle definitions, and produce evidence factories to satisfy auditors. Those things happen, and they’re corrosive. But the structural argument goes deeper. Even if every organization did compliance perfectly and honestly, it still wouldn’t produce security, because compliance is a point-in-time attestation applied to a continuous adversarial problem. The structure of the tool doesn’t match the structure of the threat.
Every Fortune 500 company has signed annual attestation of controls since Sarbanes-Oxley took effect in 2002. Twenty-four years of attestation. In that same window: OPM. Equifax. SolarWinds. Colonial Pipeline. Change Healthcare. Every one was compliant with something. The attestation didn’t lie in the narrow technical sense. The controls existed. The auditor validated them. And none of it mattered because the adversary doesn’t care about your scope boundary.

What Operators Actually Measure
The compliance model persists partly because it gives organizations something countable. Controls implemented. Findings closed. Assessment scores. Risk accepted in writing. These metrics satisfy boards, regulators, and auditors. They also have no predictive relationship to whether an adversary will succeed.
Every other security domain solves the measurement problem the same way: by measuring outcomes.
The fighter pilot measures mission effectiveness. Did the sortie accomplish its objective? What was survivability? Then the debrief tears apart every decision node. What did you see? What did you decide? What happened? What changes next time? The debrief isn’t an audit. It’s a learning cycle that feeds back into the next sortie.
The tier 1 special operator measures mission success or failure. Time on target. Collateral damage. Intelligence value. The After Action Review examines decisions, not procedures. Not “did you follow step 14 of the playbook” but “you made this call at this point with this information, here’s what happened, here’s what we do differently.” The AAR is the reorientation loop that makes the next cycle faster.
The mall cop measures incidents detected, response time, incidents resolved, losses prevented. Nobody audits whether the mall cop checked zone 3 at 1415 per the patrol schedule. They care whether the mall cop caught the shoplifter or missed the fight at the food court. That guard runs a perception-decision loop on every circuit, scanning for anomalies against a mental baseline, predicting what behavioral patterns mean, adjusting route and attention based on what they observe. The entire security industry spends billions on frameworks that can’t do what one person walking a food court does by instinct.
Admiral Mike Rogers, former Director of NSA and Commander of U.S. Cyber Command, repeatedly called for cybersecurity to “increase resilience, speed, agility, and precision.” Those are attributes of an adaptive system. They describe an operational capability, not a compliance posture. Rogers understood the distinction, likely because 37 years of naval service will do that. The military doesn’t confuse readiness with paperwork. Cybersecurity does.
The Fulcrum Breaks
For years, the compliance model was counterbalanced by a particular culture. Organizations that took security seriously treated compliance as the floor, not the ceiling. They built adaptive capabilities on top. They hired smart people and gave them room to operate. The compliance weight sat on one side of the fulcrum, and a culture of operational security sat on the other.
That balance is collapsing. Three forces are accelerating the failure.
First, AI-enabled attacks are compressing adversary cycle time. When an attacker can generate, test, and iterate phishing campaigns, exploit code, and social engineering approaches at machine speed, the defender’s loop has to run at least as fast. A compliance regime that cycles annually or quarterly cannot compete with an adversary that cycles in minutes.
But the fact that adversaries use AI does not mean defenders must become AI-dependent. AI is a crescent wrench. It’s a useful tool in the kit, not the kit itself. AI still struggles with the gut-level recognition that an experienced analyst develops after years of watching network traffic, the sense that something about this session is wrong before the signature fires. Human error will always create false negatives. Analysts will miss adversary activity. AI can help resurface those missed signals, reprocess the noise, and flag what the human eye skipped. That’s a real contribution. But a human analyst can predict badness developing on the network and direct agents to close, adapt, or change controls faster than any current AI can reason through the same problem. The right model isn’t AI replacing the analyst. It’s AI extending the analyst’s perception while the analyst runs the decision loop. For too long we’ve built cybersecurity around a series of static gates inside the enterprise, firewalls, segmentation boundaries, access control checkpoints, and treated them as permanent fixtures. The environment those gates are supposed to control is chaos manifest. It shifts constantly. Static gates in a chaotic environment give you the illusion of order until an adversary walks between them.
Second, the vulnerability apocalypse is expanding the attack surface faster than any control catalog can track. The volume of disclosed vulnerabilities, the speed of weaponization, and the interconnection of systems mean that the environment changes between the time you start an assessment and the time you finish it. The map is never current. Any framework that depends on a stable picture of the environment is building on sand.
Third, the policy response to both of these pressures is more compliance, not less. CMMC for the defense industrial base. HITRUST for healthcare. Expanding audit regimes, expanding scope definitions, expanding attestation requirements. The answer to the failure of checklists is longer checklists. We are doubling down on the approach that has failed for fifty-six years, at the precise moment when the threat environment has made that approach less viable than it has ever been.
The Education Pipeline
The structural problem starts before the framework. It starts in the classroom.
Computer science education from CS101 forward teaches students to think about systems as designed, not as contested. Security courses layer on top of that foundation and mostly teach taxonomy. Here are the control families. Here is how you map a finding to a framework. Here is how you write a Plan of Action and Milestones. Even the best programs in the country, and I include Purdue’s CERIAS among them, sit inside academic structures that reward publication and methodology over operational tempo and adaptive judgment. Eugene Spafford has built something extraordinary there, and saying so is not a qualification but a fact. The gap isn’t about the quality of the faculty. The gap is about the structure of the discipline.
Nobody in the cybersecurity education pipeline learns to run the loop. Nobody gets the equivalent of what a fighter pilot gets in training: repeated high-speed exposure to ambiguous, contested environments where you make a decision with incomplete information, execute, observe the result, and reorient. Red team exercises are the closest analog, and they happen maybe once or twice a year at organizations that bother. That’s not training. That’s a demonstration.
Someone will point to Capture the Flag competitions at DEF CON or university cyber competitions and say this training already exists. It doesn’t. CTF is attacker-centric. It trains people to find vulnerabilities and exploit systems, which is useful, but it isn’t training defenders to run a perception-decision loop under pressure. Defend the Flag events are closer, but they’re simulations with defined start and stop times, known scope, and artificial constraints that don’t replicate the ambiguity of a real operational environment. We already know the cultural problems that arise when we run even basic attack simulations against users. Phishing exercises generate resentment, erode trust, and produce compliance metrics rather than behavioral change. Now imagine trying to run continuous attack simulations against SOC analysts without turning the exercise into a morale problem or a liability.
Purple teaming, where red and blue teams operate together and test each other continuously, comes closest to the model I’m describing. In theory, it’s an ongoing adversarial feedback loop where defenders learn to detect, respond, and adapt in something approaching real time. In practice, most organizations turn purple team engagements into compliance exercises. The engagement gets scoped. The findings get mapped to controls. The report goes to the auditor. And the adaptive loop that was supposed to develop defender judgment becomes another evidence artifact in a compliance package. The compliance culture is so pervasive that it metabolizes even the tools designed to replace it.
The fix isn’t just curricular. It’s structural. The entire model of how security professionals develop needs to look more like how military operators develop. Continuous training cycles with live-fire equivalents built into the career path, not front-loaded in a degree and then abandoned to annual compliance refreshers.
The Path Forward
A caveat before going further. None of what follows applies to an organization that can’t do basic hygiene. If you haven’t established a baseline set of security controls, if your patching cadence is measured in years instead of days, you aren’t ready for this conversation. Some organizations operate systems so old that their patch mitigation strategy amounts to obscurity: the adversaries don’t target the platform because the last time it was updated, those adversaries hadn’t been born yet. That’s not a security posture. That’s a bet on irrelevance, and it stops paying off the moment someone curious runs a scanner against your address space. Basic hygiene is the floor. What follows is about what happens above the floor, and it only works if the floor exists.
Nancy Leveson at MIT has spent decades building STAMP, a systems-theoretic accident model that treats safety failures as control problems rather than component failures. She argues against checklist approaches in favor of continuous systems-theoretic analysis with feedback loops. Her work applies across aviation, nuclear power, medical devices, and increasingly to cybersecurity. It is the closest existing academic framework to what the cybersecurity field actually needs: an engineering discipline built on continuous adaptive control rather than periodic attestation.
Dan Geer has argued for decades that security is fundamentally about dependence and risk quantification, not control catalogs. His economics-driven approach to security measurement provides the analytical foundation for an alternative measurement model, one built on quantified outcomes rather than compliance scores.
The path forward combines these streams with what every other security domain already knows.
Replace the compliance-as-activity model with a constraints-as-boundary model. Regulations, standards, and organizational policy define the box. They don’t define the activity inside the box. Just like ROE for the fighter pilot. Just like the law for the mall cop. The adaptive decision cycle is what happens inside the boundary, and it runs continuously.
Build cybersecurity education around perception-decision loops, not control catalogs. Teach pattern recognition, mental simulation, and rapid decision-making under uncertainty. Train defenders the way we train operators: through repeated high-speed exposure to contested environments, with after-action reviews that feed the next cycle. Design thinking and systems of systems engineering should be foundational courses, not electives that security students never encounter.
None of this runs without resources, and this is where the argument has to be honest about the real world. In most security programs, operations already eats strategy for lunch. The day-to-day work of keeping systems running, responding to tickets, managing vendors, and feeding the compliance machine consumes every available hour. There is no capacity left for strategic thinking, and tactics degrade into reaction rather than adaptation. To operate at adversary speed, an organization needs capacity across all three levels: strategy to set direction, operations to sustain the mission, and tactics to execute the loop in real time. A fighter squadron doesn’t fly combat missions with a maintenance crew of two and no intelligence section. But that’s how most security programs are staffed relative to the threat they face. If leadership wants an adaptive security function, they have to fund one. The alternative is what we have now: a compliance function with a security label on it.
Measure outcomes, not attestation. The metrics exist. Mean Time to Detect. Mean Time to Respond. Mean Time to Remediate. Alert adaptation rate, meaning how fast the detection environment evolves to catch what it missed yesterday. Adversary dwell time. Impact containment. Cycle time between detection, decision, and action. These are operational outputs that answer a single question: are we reducing risk to the organization? Every one of them feeds an after action review that makes the next loop faster and sharper. None of them require an auditor.
The core job of a cybersecurity function is to reduce risk to the company. Not to pass an audit. Passing an audit is itself a business risk to manage, because regulatory penalties and contract requirements are real, and pretending otherwise would be naive. But risk reduction is the mission. Compliance is a constraint on that mission, not a substitute for it. When compliance becomes the mission, the organization optimizes for the wrong output. It produces audit evidence instead of security outcomes. And the adversary, who does not read your POA&M, keeps moving.
The predictable response to all of this is the pat on the head. Isn’t that cute. The real world is more complex than your theory. We have regulations to meet, contracts to keep, boards to brief, and auditors on the calendar. Don’t worry your pretty theoretical head about it while the adults manage the program. That response deserves a direct answer.
Yes, the real world is complex. That is the point. Complexity is the argument for adaptive systems, not against them. A complex, chaotic, adversary-driven environment is exactly where static controls fail and continuous feedback loops succeed. Every domain that operates in genuine complexity, combat aviation, emergency medicine, special operations, has learned this. Cybersecurity is the outlier that keeps insisting the complex environment will hold still long enough for the audit to finish.
And yes, passing audits is a requirement. Nobody disputes that. But “we have to pass the audit” is not a security strategy any more than “we have to file our taxes” is a business strategy. You do it because the law requires it. You don’t confuse it with the actual work of running the enterprise. The compliance-first crowd has had fifty-six years, since the Ware Report, to demonstrate that their approach produces security. It hasn’t. The same thinking that created the problem will not fix it, no matter how entrenched the people defending it are, no matter how many auditors they employ, and no matter how uncomfortable the alternative makes them. Comfort is not a security outcome.
Build adaptive architectures, not compliance architectures. Systems of systems engineering provides the discipline. Treat the security function as a continuous control loop operating across interconnected technology domains, not as a set of controls implemented against a catalog and measured against a point-in-time snapshot. The technology substrate that runs modern business and government is not divisible into neat compliance categories. IT, OT, cloud, identity, communications, these all serve the same mission: enabling the organization to command, control, communicate, and coordinate. The security function has to operate across that entire surface at the speed the adversary operates, not at the speed the auditor visits.
Wiener had it right in 1948. Security is a feedback problem. The system observes, processes, adapts, and observes again. The loop runs continuously. The system adapts or it fails. We named the field after his insight and then spent fifty-six years ignoring it.
It’s time to run the loop.