SecOps vs the Mossad

Why your threat model might be fundamentally incoherent

The security consultant sat across from me, earnest and well-meaning, walking through their proposed architecture. “And here,” they gestured at a complex diagram of network segmentation, “we implement zero-trust principles with microsegmentation, ensuring that even if one system is compromised…”

I interrupted as gently as possible. “What if the Mossad wants in?”

They blinked. “I’m sorry?”

“The Mossad. Israel’s foreign intelligence service. If they specifically target us, does any of this matter?”

The consultant’s expression shifted through several emotions in quick succession: confusion, amusement, then a sort of uncomfortable recognition that I wasn’t joking. “Well, I mean, obviously if you’re up against a nation-state actor with unlimited resources…”

And there it was. The conversation we never quite have in cybersecurity, the uncomfortable truth that lurks beneath most enterprise security planning: threat modeling only works if you’re honest about which threats you can actually defend against.1

The adversary hierarchy

Let’s establish a framework. In information security, adversaries exist on a spectrum of capability, and it’s useful to think about them in tiers:2. First, in the bottom bracket, there are the script kiddies and opportunists. These are the bulk of threats most organizations face. They’re running automated scanners, trying default passwords, exploiting known vulnerabilities that haven’t been patched. Their attacks are spray-and-pray. Your organization is a target only in the sense that your IP address exists on the internet.

Let me move up the ladder of serious threats. At the second tier, you’ve got your competent criminals: ransomware operators, organized fraud rings, and moderately sophisticated APT groups. These folks have some resources and actual skill. They’re willing to invest a few weeks or even months on a target if the money’s right. They’ll dig into who you are, craft convincing spear-phishing emails, and if the potential payoff justifies it, they might even drop some cash on zero-day exploits. The third tier is where well-resourced corporations sit. I’m talking about litigation opponents with deep pockets, competitive intelligence operations, and private investigation firms. These organizations can hire genuinely talented people, run operations that stretch over extended periods, and they’ve got substantial legal and financial muscle behind them.

Then you hit tier four. Standard nation-state actors. These are the APT groups you see written up in threat intelligence reports. They work with significant resources, custom-built tools, and dedicated teams. What makes them particularly dangerous is their patience. They’re methodical, can maintain access to compromised systems for years, and this category encompasses most nation-state intelligence operations and military cyber units.

At the very top, tier five, you’ve got what I think of as the apex predators, the Mossad and similar organizations. We’re talking about a small handful of intelligence services that operate at such a sophisticated level that they make other nation-states look amateurish by comparison. The Mossad, the CIA’s Tailored Access Operations unit, certain divisions within China’s Ministry of State Security, maybe the FSB on a particularly good day. These organizations exist in a category of their own.

  • Effectively unlimited budgets for high-priority targets
  • Decades of operational experience
  • Access to industrial supply chains
  • The ability to conduct physical operations anywhere in the world
  • No meaningful legal constraints on their operational methods
  • The patience to run operations that span years or decades

The uncomfortable reality is that security controls designed for Tier 1-3 threats often don’t scale meaningfully to Tier 4, and almost nothing scales to Tier 5.3

What does Mossad-level capability actually mean?

Let’s ground this in some concrete examples, because I think many security professionals have a somewhat Hollywood-ified notion of intelligence agency capabilities.

In 2010, Stuxnet represented what was probably an NSA/Unit 8200 joint operation.4 The attack required:

  • Multiple zero-day exploits (eventually four were identified, possibly as many as seven)
  • Stolen digital certificates from legitimate companies
  • Deep knowledge of Siemens SCADA systems and Iranian nuclear centrifuge configurations
  • Physical access or incredibly sophisticated supply chain compromise to introduce the worm
  • Operational security good enough that attribution took years and is still not officially confirmed

This was against an air-gapped facility, behind physical security, in a hostile nation. It worked.

Or consider the more recent pager operation in Lebanon.5 According to reporting, Israeli intelligence managed to intercept a shipment of pagers destined for Hezbollah and modify them to include explosive charges. This required:

  • Intelligence on procurement plans and supply chains
  • Physical interdiction capabilities
  • Technical expertise to modify consumer electronics
  • Operational security across potentially hundreds of operatives
  • All while maintaining devices that functioned normally until remotely triggered

The point isn’t that these operations are impossible to defend against. The point is that defense requires resources, paranoia, and operational discipline that exceed anything in standard enterprise security playbooks.6

The fundamental asymmetry

Here’s where we need to talk about the math, because the math is brutal.

Imagine you’re running security for a mid-sized tech company. You have maybe 10-50 people on your security team, budget constraints, competing priorities, and the constant pressure to not impede business operations. Your threat model probably includes:

  • Random internet attacks (automated)
  • Targeted ransomware
  • Maybe some corporate espionage
  • Insider threats
  • Supply chain risks from your vendors

Now imagine the Mossad (or equivalent) decides your company is strategically important. Not “might want to look at someday” important. Genuinely, “allocate serious resources to this target” important.

They might assign:

  • A dedicated team of 20-100+ highly skilled operatives
  • Access to signals intelligence (SIGINT) capabilities that dwarf your defensive monitoring
  • Physical surveillance and access operations
  • Supply chain interdiction capabilities
  • Unlimited time and budget for this specific operation
  • Legal authority to operate outside normal constraints

The asymmetry isn’t just quantitative. It’s qualitative. You have to defend every vulnerability, every moment of every day. They have to find one way in, once.7

Moreover, your security controls have to be documented, auditable, maintainable, and compatible with business operations. Their attacks can be completely bespoke, undocumented, and designed specifically to evade your defenses.

You face institutional constraints about what’s “reasonable” security spending. They face no such constraints on high-priority targets.

You have to assume your employees need to be productive, travel internationally, use consumer devices, and have some semblance of work-life balance. They can dedicate people to multi-year infiltration operations if needed.

Why traditional SecOps fails

Most enterprise security programs are built around compliance frameworks, best practices, and defense-in-depth principles. These work reasonably well for Tier 1-3 threats. For Tier 4, you need to get more sophisticated, but there are at least playbooks. For Tier 5, the playbooks mostly assume you’ll lose.

Let’s talk about network segmentation first. The principle is absolutely sound. You want to limit lateral movement if an attacker manages to get in. But here’s the reality against a sophisticated adversary: it mainly just increases the time to full compromise from hours to days, or maybe weeks if you’re lucky. If they have persistent access and custom tools, they will eventually map out your entire network, identify the paths through your segmentation, and establish themselves in whatever high-value segments they’re targeting. It’s inevitable.

Then there’s zero-day management. You keep your systems patched, run vulnerability scanning, maybe even have a bug bounty program. All of that is great, genuinely good practice. But the Mossad has intelligence about vulnerabilities before they’re publicly disclosed. They potentially have relationships with hardware manufacturers that give them insight you’ll never have. They certainly maintain a stockpile of zero-days that far exceeds anything your patching strategy can address.

Modern endpoint detection and response solutions are genuinely impressive technology. They can catch a lot of malware, detect anomalous behavior, and provide forensic visibility into what’s happening on your systems. But against a nation-state adversary with custom tooling designed specifically to evade your particular EDR vendor? It becomes a speed bump at best. They’ll study your EDR’s detection signatures, test their attacks against it in their own laboratories, and craft approaches that slip right through without triggering alerts. And finally, access controls and authentication. You implement multi-factor authentication everywhere, use certificate-based authentication, maybe even physical tokens. These are all good defensive practices, no question. But if the adversary can…

  • Intercept and modify your token vendor’s supply chain
  • Compromise the certificate authority infrastructure
  • Conduct physical surveillance to steal credentials
  • Deploy targeted malware that harvests authentication tokens

…then your access controls are just inconvenient, not prohibitive.

Airgapping, the nuclear option (pun intended) of security: completely isolate the critical systems from any network. This actually works against most attackers, but Stuxnet demonstrated it’s not absolute. If an adversary can compromise the supply chain, bribe or blackmail insiders, or conduct physical operations, air gaps can be bridged.8

When should you care?

Now for the critical question: when does this level of threat modeling actually matter?

For the overwhelming majority of organizations, the answer is: it doesn’t. Your actual adversaries are almost certainly in Tiers 1-3, maybe Tier 4 if you’re in a sensitive industry or work on critical technologies. Building security architecture around Mossad-level threats is like designing your house to withstand a tactical nuclear strike, it’s theoretically possible but not a good use of resources.9

However, there are scenarios where this becomes relevant:

So when do you actually need to worry about tier five adversaries? There are really only a few scenarios where this threat model becomes relevant.

If you’re working on strategic national security technologies, then yes, you probably do face these apex predators. Building advanced weapons systems, working on nuclear programs, developing critical intelligence capabilities, these activities put you squarely in their crosshairs. Your threat model needs to reflect that reality.

If you’re a prominent dissident or activist against a capable state, you’re in a similar position. When you’re effectively at war with a nation-state intelligence service, the standard security advice everyone gives, use Signal, enable two-factor authentication, is necessary but nowhere near sufficient. You need to think like a target because you genuinely are one. Critical infrastructure also attracts this level of attention. Power grids, telecommunications backbone, financial systems, the targets that, if compromised, could cause strategic damage. These become extremely attractive to tier five adversaries during periods of geopolitical tension.

And finally, if you have information a nation-state really, really wants, you’re in their sights. Maybe you’re a journalist sitting on major classified leaks. Maybe you’re a research institution that’s achieved a breakthrough in dual-use technology. Maybe you’re in a position to influence significant geopolitical decisions. Whatever the specifics, if a nation-state has decided they need what you have, your threat model changes fundamentally.

For everyone else, this is an intellectual exercise. An interesting one, certainly, but not practically actionable.

The correct response

Let’s say you’ve done the analysis and concluded you genuinely face Tier 5 adversaries. What do you do?

You need to accept that traditional security models are insufficient. You simply can’t “best practice” your way out of this situation. SOC 2 compliance, ISO 27001 certification, these frameworks were built assuming adversaries with bounded capabilities. You’re facing unbounded capabilities focused on specific targets, and that changes everything.

You also need to limit your attack surface radically. If you’re a high-value target, every convenience becomes a potential vulnerability. This might mean no cloud infrastructure, because cloud providers are large, juicy targets for supply chain compromise. Extremely limited use of consumer devices. Restrictions on international travel. Physical isolation of critical systems. A minimal digital footprint. This isn’t how normal companies operate, but that’s precisely the point.

Assume compromise and plan accordingly. Don’t waste energy building architecture around “preventing” a breach, that’s not realistic. Instead, build around minimizing the value of what can be stolen, limiting the damage from compromise, detecting and responding to persistent access, and regularly rotating and compartmentalizing everything. Your security posture needs to function under the assumption that they’re already in.

Invest in counterintelligence. Most security programs are purely defensive, but against sophisticated adversaries, you need offensive counterintelligence. This means actively looking for signs that you’re being targeted, monitoring for surveillance, understanding the specific tactics, techniques, and procedures that adversaries use in your particular context.

And finally, accept operational limitations. You will move slower than your competitors. You will be less efficient. You will frustrate your employees and stakeholders. This is simply the cost of operating under genuine threat, and there’s no way around it.

The epistemological problem

Here’s where this gets philosophically interesting: How do you know if you’re actually facing Tier 5 threats?

The signature of a truly sophisticated adversary is that you don’t know they’re there. If the Mossad is in your network and doesn’t want you to know, you probably won’t. They’re not going to leave calling cards. They’re not going to be noisy.10

This creates a paradox: The organizations that most need Tier 5 security posture are often the ones least likely to realize they need it, precisely because sophisticated adversaries don’t announce themselves.

Meanwhile, many organizations that are paranoid about nation-state threats probably don’t actually face them. That marketing VP who thinks the Chinese government is after their customer database? Almost certainly wrong. But the researcher working on breakthrough battery technology who isn’t worried? Maybe should be.

The base rate matters enormously here. There are tens of thousands of companies that consider themselves “potential nation-state targets.” There are maybe a few hundred that actually warrant sustained attention from Tier 5 adversaries. But the paranoid 99.5% and the genuinely-at-risk 0.5% look similar from the inside.11

Living with uncertainty

In rationalist circles, we talk a lot about operating under uncertainty, making decisions with incomplete information, and updating our beliefs based on evidence. The security domain is particularly challenging because:

  1. The adversary actively works to hide evidence of their presence
  2. False positives (seeing threats that aren’t there) are cheap; false negatives (missing real threats) can be catastrophic
  3. The cost of overreacting is high (operational paralysis, wasted resources)
  4. The cost of underreacting is also high (compromise, data loss, strategic damage)

The correct Bayesian approach is probably something like:

  • Start with reasonable priors based on your actual strategic importance
  • Update significantly if you see any actual evidence of sophisticated targeting
  • Maintain baseline security hygiene that protects against Tier 1-3 threats
  • Have a plan for how you’d escalate security posture if your threat assessment changes
  • Don’t optimize for threats that don’t match your prior probability

But in practice, organizations tend to either ignore nation-state threats entirely or over-index on them based on fear rather than rational assessment.12

The uncomfortable implications

If we take seriously the idea that some organizations do face Tier 5 adversaries, and that conventional security controls don’t meaningfully protect against them, what follows?

There are some broader implications here that are worth thinking through carefully. Much of what passes for “advanced” security in sensitive contexts is actually just sophisticated-looking security theater. It might stop less capable adversaries, sure, but it doesn’t address the actual tier five threat it’s supposedly designed for. Organizations spend enormous amounts of money on security measures that look impressive and check compliance boxes but would crumble against the adversaries they claim to defend against.

Here’s an uncomfortable thought: if you’re holding information that would genuinely attract Mossad-level attention, maybe it shouldn’t be on networked computers at all. Paper, properly secured, has real advantages. Air-gaps and physical security can actually work if you’re willing to accept the operational costs. We’ve become so enamored with digital convenience that we’ve forgotten there are some things that simply shouldn’t be digitized.

Location matters more than most people realize. Running your operations in the United States makes you more vulnerable to the NSA, CIA, and Tailored Access Operations. Running them in China makes you more vulnerable to the Ministry of State Security. Running them in Israel makes you more vulnerable to Unit 8200 and the Mossad. Physical jurisdiction isn’t just a legal question, it’s fundamentally a security question. If you, personally, are targeted by a tier five adversary, you cannot win that fight alone. This is just reality. You need the backing of an organization with similar capabilities, like a friendly nation-state’s security service, or you need to fundamentally change your life to eliminate the attack surface. Individual-level security measures simply aren’t sufficient.

And perhaps most importantly, we’ve been assuming the wrong game this whole time. Most security thinking assumes the goal is “prevent unauthorized access.” But against sophisticated adversaries, maybe the goal should be different. Maybe it should be “make the attack more expensive than the value of the information” or “ensure you detect and can respond to compromise” or even “make your organization low-priority compared to other targets.” When you can’t win the game, sometimes you need to change which game you’re playing.

What this means for normal organizations

For the 99%+ of organizations that don’t actually face Tier 5 threats, what’s the takeaway?

Get your threat model right. Be brutally honest about who your adversaries actually are. If you’re a mid-market SaaS company, you’re almost certainly not facing nation-state adversaries. Design your security program for the threats you actually face, not the ones that sound impressive in board presentations.

Don’t use “nation-state threat” as an excuse. I’ve seen this pattern play out too many times: an organization has mediocre security, suffers a breach, and then claims it was a “sophisticated nation-state actor” to avoid accountability. Unless you have actual evidence, and I mean real evidence, not just “it was really sophisticated”, this is just excuse-making. Most breaches happen for much simpler reasons. Recognize the limits of security. Even good security programs can’t prevent all breaches. That’s not a failure, it’s reality. The goal is risk reduction, not risk elimination. Accept that fundamental truth and plan accordingly.

And if you genuinely believe you face tier five threats, then act like it. Don’t half-ass the response. Either commit to the serious operational costs of defending against sophisticated adversaries, the slowness, the inefficiency, the frustrated employees, or acknowledge that you’re not actually defending against them. There’s no middle ground here. You can’t sort of defend against the Mossad.

The meta-level lesson

This essay is partly about cybersecurity, but it’s more fundamentally about threat modeling, resource allocation, and honest assessment of risk.

The pattern appears everywhere: We spend resources defending against threats that are vivid and scary rather than threats that are probable. We implement controls that look impressive rather than controls that actually reduce risk. We tell ourselves stories about our adversaries that are more flattering (or more paranoia-inducing) than accurate.13

The Mossad makes for a good thought experiment precisely because it’s an adversary that forces honesty. You can’t pretend that “following best practices” is enough. You can’t hide behind compliance frameworks. You have to actually think about what defense means against an adversary with unbounded capabilities.

For most of us, most of the time, the answer is: we wouldn’t win that fight, so let’s make sure we’re not actually in it.

But for the few who genuinely are in it, the answer requires a level of paranoia, operational discipline, and resource commitment that most organizations simply cannot sustain. And that’s okay, as long as we’re honest about it.

The worst outcome is the middle ground: spending enormous resources on “nation-state level” security theater while not actually being secure against nation-state threats, meanwhile neglecting the more mundane but more probable risks that actually threaten your organization.

Choose your battles

The rationalist community often talks about asymmetric weapons and strategic selection of battles. In security, this means being clear-eyed about which battles you can win, which you can’t, and which you need to fight anyway.

If you face Tier 1-3 adversaries (most organizations), modern security best practices work reasonably well. Invest in them.

If you face Tier 4 adversaries (nation-state level but not apex predators), you need sophisticated security operations, but there are playbooks and they can work.

If you face Tier 5 adversaries (the Mossad and similar), you need to completely rethink your operational model, accept severe constraints, and recognize that you’re in an arms race you might not win.

The key is knowing which situation you’re actually in.

Most security consultants won’t tell you this because it’s bad for business. Most security vendors won’t tell you this because they’re selling solutions that claim to work against all threats. Most security frameworks won’t acknowledge this because they’re built around the assumption that defense is possible.

But defense is always contextual. It’s always about specific adversaries, specific capabilities, specific trade-offs.

When your adversary is the Mossad, standard SecOps doesn’t save you. You need to play a different game entirely, or acknowledge you’re not really playing at all.

The hardest part isn’t implementing the security controls. It’s being honest about whether you need to.


  1. The concept of “threat modeling” in security is well-established, but it’s often done poorly. Organizations frequently identify threats based on what’s been in the news recently rather than actual risk assessment. For a good primer on threat modeling: OWASP Threat Modeling. The fundamental challenge is that threat modeling requires admitting there are adversaries you can’t defend against, which makes risk officers uncomfortable. ↩︎

  2. This tier framework is my own construction, though it’s loosely based on threat categorizations used in various intelligence community assessments. MITRE ATT&CK provides a similar (though more granular) framework for categorizing adversary behaviors: https://attack.mitre.org/ ↩︎

  3. Bruce Schneier has written extensively about the security implications of nation-state adversaries: “When you’re up against a well-funded nation-state adversary, all your security is probabilistic. You’re not trying to make attack impossible; you’re trying to make it expensive enough that your adversary targets someone else.” This is from a 2013 essay that remains relevant. ↩︎

  4. The Stuxnet analysis has been extensively documented. For the technical details: Ralph Langner’s analysis from 2010-2011 remains definitive. The operation required such specific knowledge of Iranian centrifuge configurations that it essentially confirmed the operation was launched by a state actor with extensive intelligence resources. See also: Countdown to Zero Day by Kim Zetter for a comprehensive journalistic account. ↩︎

  5. The September 2024 Lebanon pager operation, while dramatic, isn’t fully documented as of my knowledge cutoff. However, similar supply chain interdiction operations have been reported by Der Spiegel (the NSA’s ANT catalog) and other sources documenting intelligence agency supply chain capabilities. ↩︎

  6. A study by the Ponemon Institute found that the average cost of a data breach in 2023 was $4.45 million. However, this statistic is almost meaningless for nation-state attacks because the value of what’s being stolen might exceed this by orders of magnitude, and the attackers don’t care about being “cost-effective” in the normal sense. ↩︎

  7. This asymmetry is fundamental to offensive versus defensive cybersecurity. As Dan Geer has pointed out, the defender must be right every time; the attacker only needs to be right once. This asymmetry becomes more pronounced as adversary sophistication increases. ↩︎

  8. The Stuxnet case study is the canonical example of air-gap bridging. Multiple analyses concluded that the initial infection vector was likely USB drives introduced either through a compromised insider or through social engineering. Air gaps work, but they require perfect operational discipline around the gap. ↩︎

  9. Risk prioritization based on actual probability is fundamental to good security practice but is often neglected. The psychology of security tends toward availability bias, we protect against threats that are vivid and recent rather than probable. This is discussed extensively in Schneier’s “Beyond Fear” and Kahneman’s “Thinking, Fast and Slow” applies directly to security decision-making. ↩︎

  10. The concept of “advanced” adversaries being stealthy is well-documented. FireEye’s M-Trends reports consistently show that sophisticated actors maintain presence for months or years before detection. In some cases, they’re only detected because they want to be (for strategic signaling) or through third-party intelligence sharing, not through the victim’s own security controls. ↩︎

  11. Base rates are crucial but often ignored in security decision-making. If 10,000 companies think they face nation-state threats but only 100 actually do, then even a 99% accurate threat assessment will produce 100x more false positives than true positives. This is a straightforward application of Bayes’ theorem but is rarely applied rigorously in practice. ↩︎

  12. The challenge of security decision-making under uncertainty is discussed in various academic papers on risk management. A particularly relevant framework is Douglas Hubbard’s “How to Measure Anything in Cybersecurity Risk,” which attempts to bring quantitative rigor to security risk assessment. The fundamental challenge is that the key variables (probability of attack, potential impact) are often unmeasurable or based on limited data. ↩︎

  13. The pattern of defending against vivid but improbable threats while neglecting probable but mundane ones appears throughout risk management. It’s discussed in the context of terrorism versus automobile accidents, dramatic diseases versus chronic conditions, and yes, security threats. The rationalist community has written extensively about this as an example of systematic biases in human risk assessment. ↩︎

‹ All posts