What is Privilege Disruption?
Deny the conversion of access into control.
A cybersecurity doctrine focused on the privilege and Execution Authority a threat actor needs to advance an operation.
DENY THE CONVERSION OF ACCESS INTO CONTROL.
Reshaping adversary behavior by disrupting the privilege and Execution Authority required to turn access into persistence, privilege escalation, lateral movement, operational control, and impact.
A simple path from concept to operational meaning.
Deny the conversion of access into control.
A cybersecurity doctrine focused on the privilege and Execution Authority a threat actor needs to advance an operation.
Threat actors may already have access. What authority remains?
Privilege debt increases the Execution Authority a successful compromise can inherit.
Apply the doctrine continuously.
“Privilege Disruption is the doctrine that gives defenders a playbook for proactive cyber defense.”
State Agency Cyber DefenderWhat must remain true regardless of technology, actor type, or implementation.
Zero Trust governs whether access should be granted. Privilege Disruption governs what authority remains after access is granted — and whether that authority can be prevented from becoming adversary control.
Explicitly verify the actor, resource and conditions under which access is granted.
Assume access can occur. Reduce the privilege and Execution Authority a successful compromise can inherit and compose.
Shape the adversary by making compromised access carry less standing value and fewer reusable paths to control.
Find and retire privilege that should not exist; bound what must remain; interrupt illegitimate authority at execution time.
Find authority-supplying conditions and warning signals before they become realized ATT&CK behavior.
“Shaping adversary behavior, introducing costs and consequences into this mix.”
Sean Cairncross, National Cyber Director · Source