The regress of justification in cybersecurity
On a Tuesday in March, a vendor discloses a deserialisation flaw in a logging library. CVSS 9.8. The detection engineer reads the advisory, checks the internal asset inventory, finds fourteen instances of the library across three business units, and opens tickets. The tickets close over the following week as patches roll out to twelve of the fourteen. Two are missed — one because the owning team is between sprints, one because the host is a build server nobody remembers is internet-facing. Neither miss is recorded as open risk, because the quarterly configuration audit that would have caught it is eleven weeks away.
Eighty-eight days later, a scanner run during the audit finds the build server still running the vulnerable version, now with a working public exploit chained against it by an opportunistic worm. The exposure did not hide. It sat in a ticketing system, unflagged, for the entire gap between the moment someone learned the world had changed and the moment anyone next looked. The detection engineer's belief — "our exposure to this CVE is remediated" — had been true on day seven. It had been false since some point before day thirty, when the build server's package manifest drifted out of sync with the fix. Nobody's belief updated, because nothing was watching the manifest. The audit was watching. The audit runs quarterly.
What actually failed
Call the engineer's belief B: "we are not exposed to CVE-2024-XXXX." On day seven, B was justified. Justified by what? By a scan result, a ticket closure, a patch confirmation — a chain of evidence terminating in an observation made that week. That observation was the terminus: the point past which nobody needed to ask "justified by what?" again, because the scan had looked at the actual host and reported its actual state.
The failure was not that the scan lied. The scan was accurate, once. The failure was that the terminus was never renewed. B kept being asserted — implicitly, by the ticket sitting closed, by the absence of any alert — long after the observation that grounded it had gone stale. The manifest drifted. A rebuild pulled a cached, unpatched image. Nothing re-observed the host, so nothing re-justified B, so B simply persisted by default, unjustified, for eighty-one days, wearing the authority of a scan that no longer described anything.
This is a textbook case of what epistemologists call the regress of justification, and cybersecurity happens to be a domain where the regress has a clock on it.
The shape of the problem, briefly
Ask why a belief is justified and you get another belief. Ask why that one is justified and the chain continues. Aristotle worried about this in the Posterior Analytics: demonstration needs premises that are themselves known without further demonstration, or nothing is ever actually proven. Sextus Empiricus, reporting what tradition calls the Five Modes of Agrippa, turned the same structure into a weapon: the chain either runs forever, loops back on itself, or stops arbitrarily, and none of the three options is comfortable. Foundationalists say it stops at observation. Coherentists say the loop is fine if the web is wide enough. Both sides agree on the shape of the trouble: justification cannot float free of the world it is supposed to be about.
In security operations, the "world" is a fleet of hosts, packages, configurations and network paths that changes continuously and silently. A quarterly audit is a foundationalist stopping point that is only true at the instant it is taken. The eleven weeks either side of it are unobserved, and every belief about exposure during that interval is riding on a terminus that has expired.
Three positions on the same axis
A Large Language Model's justificatory chain for any empirical claim about the world terminates in its training corpus — disclosure text, exploit writeups, configuration guidance, all fixed at a cutoff. Ask a language model whether a given CVE is being actively exploited and it will answer from what was known when it was trained, confidently, coherently, and about the wrong month. That is not a reasoning failure. Its entire observational base is historical; nothing in the chain ever touched this week's telemetry.
A Large World Model narrows the terminus to the present, but only across a bounded scene. Point it at a network segment with live packet capture and it can ground "this host is beaconing to that IP right now" in an actual observation. The grounding is real and indexical. It also expires the moment the capture window closes or the segment boundary is crossed — a lateral movement into an unmonitored subnet simply falls off the edge of what the model can currently justify.
A Large Universe Model is the position where disclosure feeds, telemetry, malware corpora and configuration drift are all still arriving, continuously, across every stream that matters, and every belief carries a pointer back to the observation that grounds it — this host, this scan, this timestamp. The eighty-eight day gap does not appear, because there is no fixed appointment called "the audit" for exposure to hide inside. The regress is not abolished. It is kept short and made auditable: any analyst can ask "justified by what?" and get an answer with a date on it, rather than a shrug and a ticket closed months ago.
| position | terminus for "we are exposed to CVE-X" | typical gap |
|---|---|---|
| Large Language Model | training corpus, fixed at cutoff | months to years, unbounded |
| Large World Model | live scan of the observed scene | until the scene changes or capture stops |
| Large Universe Model | continuously renewed observation, provenance attached | approaches the natural latency of the stream itself |
Where coherence genuinely helps, and where it cannot
A well-run vulnerability management programme is a coherent system — CMDB, ticketing, SLAs, dashboards, all mutually reinforcing. If the numbers all agree with each other, that agreement is itself a form of warrant. Demanding continuous live observation on top of that smuggles in a foundationalist assumption that many epistemologists would reject outright.
This deserves a real answer, not a dismissal. A coherent programme is worth having; a CMDB that contradicts itself is worse than no CMDB. But coherence disciplines the interior of a belief set without indexing it to a moment. The standard reply to coherentism is the isolation objection: a perfectly self-consistent picture can be systematically false, and nothing internal to the system tells you which. A ticketing system where every ticket is closed, every SLA is green, and every dashboard is calm is exactly what both "we are actually patched" and "our closure records are simply wrong" look like from the inside. Only an observation — a scan of the live host, not a query against the ticket that claims the host was fixed — breaks the tie. Coherence tells you the story is consistent. Only contact with the host tells you the story is current.
But sensors lie too. Scanners miss assets, agents get uninstalled, EDR telemetry is sampled and sometimes silently dropped. A live observation is just another fallible belief, so the regress reappears one level down and the advantage of continuous intake evaporates.
Also correct, and it is why nothing here claims an indubitable stopping point. A scanner's coverage report, an agent heartbeat, a cross-check between two independent telemetry sources — these are further links in the chain, and the chain genuinely continues past the "observation." What changes is not the existence of further links but their reach. A missing agent heartbeat can be flagged and re-checked this minute, against a second source, on the same fleet. A training corpus frozen eighteen months ago cannot be cross-checked against anything; it has no neighbour to disagree with. Fallible, continuing, local contact with the fleet beats no contact with it, even though neither is beyond doubt.
What does not need saving
Not every belief in this domain is time-sensitive. A CVSS scoring formula, the syntax of a YARA rule, the mathematics behind a hash collision, the text of a compliance framework as written — these are non-indexical or a priori enough that a frozen reference is the right terminus, and no live feed improves them. The claim here is scoped: it concerns beliefs of the form "this system, right now, in this state." That is a narrow-sounding category that happens to contain almost every operational judgement a detection engineer is actually paid to make — is this host exposed, is this alert active, is this credential still valid, is this segment still isolated. Get the scope wrong in either direction and the argument breaks: claim too much and it is refuted by the CVSS formula; claim too little and the ninety-day gap is dismissed as a process hiccup rather than what it is, a structural hole in where justification bottoms out.
The consequence for the lineage
None of this promises an unbounded fleet under total observation; coverage is always partial, and the gap between what is actually sensed and everything that exists is not closeable. But that gap is a matter of scale — more feeds, more trusted sources, longer retention — not a different kind of evidential floor. Once intake has no designated end and every belief keeps a dated pointer to what grounds it, the axis is finished. There is no fourth position past "everything, still arriving." What is left to build is more of it, better attested, for longer. That is a research programme. It is not a new rung.