Defense does not grow by the amount you buy. Line up the major incidents of 2025–26 and the entrance, each time, was something bought as defense: the admin account handed to a contractor, the defense product itself, the platform's management plane. Three exits became one entrance.
Structural Analysis 03 described the practice of developing with AI and putting no AI into the product, bringing the attack surface close to zero. 04 described the arrival of an age in which you can stand independent of the platform. This chapter fills the gap between them. It checks, with facts, what is happening to those who buy defense, and sets out the structure by which defense moves from something bought to something held.
Fact — purchased defenses became the entrance
Three forms. Dates and sources follow the survey memo behind this chapter.
The first form: outsourcing. ASKUL (intrusion June 2025, discovered October) was entered through a VPN with the leaked ID and password of an admin account for a contractor. That account "exceptionally had no multi-factor authentication." About four and a half months passed between intrusion and discovery; the attacker disabled EDR, moved laterally, and deleted backups; some 740,000 records were affected. Tokai University's contractor (November 2025): a remote-maintenance entrance and a stolen admin account. YCC, contractor to Yamagata City and others (April 2026): the admin account of a network device, "guessed or obtained." Marks & Spencer in the UK (April 2025): the CEO testified that the attacker came "through a third party rather than a system weakness," and the company put the hit to operating profit at £300 million. In the US, Sophos reported two cases in 2025 alone in which a single admin account of an MSP's remote-management tool was taken and used to push malware to many customers at once.
The second form: products. The defense product itself became the entrance. CrowdStrike (19 July 2024) halted 8.5 million Windows machines with a faulty update. F5 (disclosed October 2025) had source code and unpublished vulnerability information taken by a state-backed actor, and CISA issued an emergency directive. Cisco ASA (September 2025), Citrix NetScaler (August 2025), on-premises SharePoint (July 2025, over 400 systems). Every one is a defensive device at the perimeter or a product that runs as root.
The third form: platforms. IDCF Cloud (7 October 2026): a single intrusion stopped the whole of East Japan Region 1, and the provider told customers that restoring from snapshots was difficult and that rebuilding in its other regions was not recommended for now. The same happens without an attack. In autumn 2025, AWS, Azure, and Cloudflare were stopped by their own operations for about 15, 8, and 6 hours respectively.
The statistics support the line-up. In Mandiant's M-Trends 2026, exploitation of vulnerabilities leads initial access at 32%, the sixth year running. Verizon's DBIR 2026 also puts vulnerabilities first, at 31%. Japan's National Police Agency finds 50–60% of ransomware intrusions come through VPN devices. In IPA's Ten Major Threats 2026, "attacks on the supply chain and contractors" sits second for organizations for the eighth year in a row. And in Sophos's 2026 survey, 97% of organizations breached through compromised credentials already had some multi-factor authentication in place at the time. It was not absent. There was an exception.
Structure — the common factor is zero distance between the entrance and root
The common factor is not "they got in." It is that once in, there was a straight road to full administrative rights.
A contractor's account is an administrator from the start; it is created that way for maintenance. A defense product runs as root; EDR, VPN appliances, hypervisors touch everything in order to see everything. A platform's management plane reaches everything that sits on it. So when any of these becomes the entrance, the distance from the entrance to root is zero.
Purchased defense is another name for handing root to someone else: to a person in outsourcing, to a company in a product, to a provider in a platform. While the recipient holds out, it is called defense. The moment the recipient fails, the root you handed over becomes the attacker's root as it is.
To buy defense is to hand over root. Only while the recipient holds out is it called defense.
Public guidance already describes this structure. The joint advisory from CISA with the UK, Canada, Australia and New Zealand (AA22-131A) says to treat contractor accounts as privileged, never reuse admin credentials across customers, consider time-based privileges, and log the contractor's connections and actions on the customer's side. The UK's NCSC writes that "identity services should never be shared" and that contractor users should use accounts administered by the customer. NIST SP 800-41 says to deny both inbound and outbound by default. The guidance is in place. What is not in place is the number of people to carry it out.
Structure — a defense boom cannot defend
Exposure to attack creates work: investigation, recovery, prevention, audit, reporting. Demand for defense grows. Gartner forecast information-security spending of $244 billion in 2026, up 11.6% in constant currency (February 2026). In the short run, IT companies' revenue grows strongly on the defense side.
But the people do not grow. ISC2's 2024 study estimated the global shortfall at 4.8 million. Its 2025 study (16,029 respondents) reports that the main concern has shifted from headcount to skills, and the Japanese respondents (1,225) say employment is stable while budgets and pay are uncompetitive. No country has added defenders in proportion to the attacks.
People who cannot be added must be spread thin. The forms of spreading thin are outsourcing, products, and platforms. A few people watch many customers, so one administrator holds many roots. Gather on one platform, and one incident does more damage. Here is the contradiction. A defense boom multiplies promises of defense without multiplying defenders. Promises sell, but defense is backed only by people. So a defense boom cannot defend.
This is not "spend nothing on defense." It is: separate the defense you can buy from the defense you cannot.
Forecast — defense moves from something bought to something held
Defense that cannot be bought must be held. The shape of held defense matches what this series has already written.
- Subtraction. Reduce what has to be defended. The static public face of 03 — no AI in the product, no CMS, no database — is an example of erasing the attack surface without buying defense. Fewer listening ears, fewer things running as root.
- One person and one machine. One person with an AI holds one machine with discipline: deny by default in and out, automatic updates, a copy on another machine, in another place, under another authority. That discipline is frozen into procedures in Chapters 5 and 10 of the server series. One person holds that machine's root, and the failure domain closes at that machine.
- Outsourcing that hands over no root. Outsourcing is fine. But under your own IDs, time-limited, with the logs on your side and no shared accounts. If the contractor disappears, root stays in your hands.
AI works here. Have it write the defensive procedures, paste in logs for inspection, and draw up the list of who holds root. As 07 argued, AI is a tool that raises an individual's capability, and defense is its plainest use. At the same time AI strengthens the attacker. As Structural Analysis 1-05 recorded, the ability to find thousands of zero-days autonomously has already been published. The stronger the attacker, the more it pays to reduce what must be defended rather than to buy more defense. Subtraction is a defense whose value rises in the age of AI.
AI introduced from above becomes, within this structure, a fourth form. An AI product distributed across a company holds the rights to touch everything in order to see everything. Documents, mail, core data are handed over so that an agent can operate them on people's behalf. It is a product running as root, the same as EDR or a hypervisor. The problem that defense cannot be bought is the problem of AI introduced from above, as it is. One more place where the distance from entrance to root is zero, added after the defense products. AI held from below does not take this form. One person keeps root on one machine and has the AI write procedures, read logs, and freeze what it builds into code. What is handed to the AI is work, not root.
Some things remain worth buying: absorbing sudden load, a thin window that takes the DDoS, a third party's inspecting eye. What they share is that they can be bought without handing over root. A borrowed window sits in front of the public face and never touches the machine inside. An inspection reads and holds no right to write. Buy anything except the defense that reaches root.
Conditions under which this forecast fails
A forecast should state how it could fail. Three ways.
First, if AI truly multiplies the defenders. If automated detection and response stand in for people, and a few can fully defend many customers, then the boom can defend. But that AI is itself a product running as root, and carries the risk of returning to the second form.
Second, if regulation and insurance demand purchased defense. If audits require specific products and insurers require certified contractors, held defense alone will not suffice. Even then, the craft of buying in forms that do not reach root remains.
Third, if leaks that subtraction cannot remove become the norm. In the SharePoint incident, the keys left in the response to an incoming request. Closing the exits does not stop what leaks in a response. As long as something sits on the public face, this leak remains. So the conclusion — put the minimum on the public face — does not change.
Implication — count who holds root
Brought down to practice, three implications.
- If you outsource, do it without handing over root. Time-limited, your own IDs, logs on your side, no shared accounts. Create no "exception" to multi-factor authentication; the exception is the road into the 97%.
- Count the products that run as root, and reduce them. EDR, VPN appliances, remote-management tools, hypervisors. Each one removed is one fewer place where the distance from entrance to root is zero.
- Share no management plane. Your own machine, and a borrowed window. Geographic separation and separation of authority are different things.
All three can be checked now. Have an AI draw up the list of people, products, and providers that hold root-equivalent rights in your environment, and for each one set out whether it has an expiry, whether the logs are on your side, and what remains if it disappears. The length of that list is the length of the defense you have bought.
Defense cannot be bought. Only defense that does not reach root can be. Defense that reaches root, you hold yourself — subtracted to a size one person, one machine, and an AI can hold.
Related articles
- Structural Analysis 03: Security Design in the Mythos Era
- Structural Analysis 04: Independence from the Cloud — AI Supports Only the Open Layer
- Blog: The Day a Cloud Vanished — Five Lessons from the IDCF Incident
- Blog: Move to the Cloud and Harden It, and It Is Still Breached
- Growing a Debian Server with Claude, Chapter 5 — The Basics of Defense
- 2-05: Standing Up the Gatekeeper — One Login with PocketBase