Frameworks Are Toothless — And the Attacker Already Has the Manual
I remember, early in the course, Roman said something that I haven't been able to shake, (paraphrased) “NIST is a fine framework, but adversaries don't care about frameworks.” I'd go further. I don't think they ignore frameworks. I think they read them carefully. MITRE ATT&CK is free, publicly available, and open to anyone on the planet. So is NIST CSF. So are the published mappings between them. According to Harvard, three in four companies now publicly disclose which framework they're aligned with which is up from four percent in 2019 (Harvard Law School on Corporate Governance). That announcement isn't a security credential. It's a menu. A motivated adversary now knows your control priorities, your governance structure, and where the gaps almost certainly are. The DOE OIG lists 44 prior-year recommendations are still open, and 82 of 101 systems at four DOE sites still running the outdated NIST 800-53 Revision 4 rather than Revision 5 which includes nuclear assets (Dille). The framework existed. The exposures exist anyway.
Here's what the framework revision cycle looks like from the other side of the table. Between June and August 2025, average attacker breakout time, initial access to lateral movement, dropped to 18 minutes. In one Akira ransomware incident, operators moved laterally in six minutes after initial login (GBHackers). Six minutes. NIST took over a decade to produce version 2.0. The governance machinery runs on fiscal years. The attack runs on a stopwatch. Six minutes. The question nobody in the framework community wants to answer is simple: when you publicly certify your defensive posture against a document that every threat actor can also read, are you building a wall or posting a blueprint of the walls weaknesses?
Six minutes.
What SOC can react in six minutes?
D3FEND exists because MITRE already knew ATT&CK had a problem. You can't publish the attacker's playbook and call it a defensive tool. The New England Patriots deflate balls and steal signals, imagine how good their offense would be if they had the defensive playbook of the opposing team. Maybe we already know. Our adversaries have our playbooks. Our adversaries know exactly what we can do in six minutes and in six weeks. Every countermeasure in D3FEND was written to script a response to something that already happened. The techniques were observed, documented, reviewed, and published on a schedule measured in months. An attacker who has read D3FEND, and they have, knows exactly which behaviors trigger which defensive responses. They don't just know how you're defended. They know how you'll react when they move. That's not a framework gap. That's a structural advantage built into the architecture of open-standard governance itself.
References
Department of Energy, Office of Inspector General. (2025, August). The Department of Energy's unclassified cybersecurity program — 2024. U.S. Department of Energy. https://industrialcyber.co/reports/doe-oig-report-flags-systemic-shortcomings-across-nist-cybersecurity-framework-functions/
Dille, G. (2025, August 18). IG warns of persistent cybersecurity weaknesses across DOE. MeriTalk. https://www.meritalk.com/articles/ig-warns-of-persistent-cybersecurity-weaknesses-across-doe/
GBHackers. (2025, September 23). Threat actors breach enterprise infrastructure within 18 minutes of initial access. https://gbhackers.com/enterprise-infrastructure/
Harvard Law School Forum on Corporate Governance. (2025, October 28). Cyber and AI oversight disclosures: What companies shared in 2025. https://corpgov.law.harvard.edu/2025/10/28/cyber-and-ai-oversight-disclosures-what-companies-shared-in-2025/
MITRE Corporation. (n.d.). MITRE ATT&CK. https://attack.mitre.org/
Comments