The objection that should win
Here is the strongest case against this page before it starts. A detection engineer opens a ticket on a disclosed vulnerability. The advisory gives a CVSS score, a vague exploitability note, and a patch. Nothing else. She cannot know whether this vulnerability is being exploited in the wild, whether her configuration is even reachable by the attack path described, or whether the vendor's own remediation quietly breaks something downstream. She has telemetry, she has a malware corpus, she has configuration drift reports arriving hourly. And still, ninety days later, at the next scheduled audit, the exposure is found sitting open — not because no one looked, but because looking harder never settled the question of whether it mattered enough to act on immediately.
If continuous intake were sufficient to close underdetermination, this should not happen. Telemetry streams in by the second. Disclosure feeds update daily. Malware corpora grow by the hour. And still the gap between "what the data show" and "what we needed to know to act" persists for exactly ninety days, sometimes longer, sometimes forever if no one is looking at the right dashboard. The volume of evidence did not translate into a decision. Worse: analysts routinely produce multiple, mutually incompatible explanations for the same telemetry — a spike is credential stuffing, or it is a scraper, or it is a compromised service account rotating tokens — and the streams that would separate these theories are not obviously coming. Adding more logs sometimes just adds more logs. If more data can leave the tie unbroken, or even multiply the number of things it's compatible with, then the claim that continuous intake is where underdetermination closes looks less like a philosophical result and more like an article of faith about scale.
That is the objection at full strength. It deserves to be taken seriously before any counter-argument is offered.
Duhem and Quine arrive in the SOC
Pierre Duhem noticed in 1906 that a failed prediction in physics never isolates the guilty assumption; it indicts a bundle. W. V. O. Quine generalised this in 1951: any single belief can be preserved by revising something else, so a body of evidence never uniquely determines a theory. Applied to a security operations centre, this reads almost literally. A detection rule fires. The rule embeds assumptions about normal baseline behaviour, about what "anomalous" process ancestry looks like, about which registry keys matter. When the rule produces a false positive, or misses something real, nobody can say from that single failure which assumption was wrong — the baseline, the enrichment logic, the threat intelligence feed that tagged an IP as benign three weeks ago and was never re-checked. The failure indicts the bundle. That is Duhem, exactly, running in a detection pipeline.
Quine's radicalisation matters more here than in most domains, because a detection engineer really can rescue a failing theory by adjusting somewhere else. A rule that keeps firing on a legitimate backup process can be patched with an exclusion, a suppression, an allow-list entry — an auxiliary hypothesis bolted on to save the original theory of what "malicious" looks like. Nothing in the data forces the engineer to instead conclude that the underlying detection logic is wrong. The tie is never broken by any single log line. It is broken, if it is broken at all, by a decision about where to spend the cost of being wrong.
What continuous intake actually buys
The corpus-bound comparison is instructive. A frozen threat model, trained once on a fixed malware corpus and disclosure archive, inherits every ambiguity present in that corpus permanently. It can enumerate rival explanations for a binary's behaviour — packer artefact, benign obfuscation, genuine evasion — and it cannot eliminate any of them, because elimination requires a further observation the frozen model is not permitted to make. This is the Large Language Model's condition applied to security: excellent recall of what has been seen, structurally incapable of resolving what has not yet been distinguished.
A bounded-scene model does better, in the way a live incident response engagement does better than a static report. Given access to one host, one time window, one set of interfaces, an investigator can act: isolate the box, dump memory, wait for the next beacon, force a retry and watch what changes. That is intervention, and Judea Pearl's causal hierarchy is right that intervention breaks ties passive logging cannot. Most incident response is exactly this — a Large World Model's discriminating power, bounded by the duration of the engagement and the extent of the environment under direct control. When the engagement ends, so does the discrimination.
The condition the objection describes — ninety days of open exposure — is not a failure of continuous intake. It is a description of intake that has stopped being continuous. Disclosure feeds updated on day one. Telemetry kept running. But the audit cycle, the human process that turns streams into acted-upon belief, checks in only once a quarter. The underdetermination here is not between rival hypotheses about the vulnerability; the exploitability of that CVE against this configuration is, in principle, resolvable by evidence that is already arriving — exploit-in-the-wild feeds, honeypot capture, EPSS score revisions, scan results against the exact software inventory. What holds the exposure open is that nobody has architected a belief with provenance and decay: a standing claim of the form "this asset is exposed, confidence high, last checked six hours ago, will re-check on next feed update," revised the moment a new stream contradicts it. Ninety days is not evidence that continuous intake fails to close the gap. It is evidence that the organisation's belief state was never actually continuous — it was a quarterly snapshot pretending to be a stream.
What survives the objection
Two objections deserve a direct answer rather than a wave.
The first: Quine's holism is not repaired by volume. True, and worth sitting with. An analyst who wants to keep believing an alert is benign can always add a suppression rule, always find some auxiliary excuse — this is a known scanner, this account is on the exceptions list, this behaviour matches a documented maintenance window. Continuous intake does not make that rescue logically impossible. What it does is make the rescue continuously billable. Every exception, every allow-list entry, every suppressed rule is a standing commitment that must survive tomorrow's telemetry too. The allow-listed IP that turns out to be a compromised jump host does not merely fail once; it fails against every subsequent stream that touches it, and each of those failures is now attributable, because the exception itself has provenance and a timestamp. A frozen corpus never sends that bill. A live one does, repeatedly, until the rescue collapses under its own accumulated cost — the security equivalent of stellar parallax finally overturning an epicycle that had been patched one too many times.
The second: many of the discriminations that matter in security are causal, not observational — did the patch cause the outage, did the exposure cause the breach, or did something else — and Pearl's hierarchy says passive logging alone sits at rung one, correlational, and stays causally blind no matter how much of it accumulates. This is correct for a purely passive collector. It is exactly why the intervention stage of the lineage matters: a system that can isolate a host, force a re-authentication, roll a credential and watch what changes is doing something a dashboard cannot. But most causal interventions in this domain are performed by someone, and that someone's action produces its own stream — patch deployment logs, credential rotation events, firewall rule changes, the blast radius of a kill-switch pull. A belief-holding system with sufficiently wide intake observes the world's interventions even when it performs none itself: rung two, by proxy, weaker than acting directly, and the provenance record should say so plainly rather than pretend the proxy is equivalent.
The residue that no stream retires
If your telemetry is comprehensive enough, surely every incident becomes explicable and every rival hypothesis eventually falls away.
That is the weak reading, and it is false for the same reason Larry Laudan separated weak from strong underdetermination. Some rival explanations in security are empirically equivalent all the way down. Two different threat actors using identical tooling, identical infrastructure providers and identical timing can produce attack telemetry that is genuinely indistinguishable — the observable surface is the same regardless of which actor is behind it, and no volume of packet capture separates them if the actors have converged on the same technique for unrelated reasons. Attribution in that case is not an intake problem. It is a strong underdetermination, the kind Duhem and Quine described, and no amount of continued logging retires it, because the rivals agree on everything that logging could show.
The defensible claim is narrower than "more data solves security." It is this: within the class of ties that observation could ever break — exploitability, exposure, behavioural anomaly, blast radius — an architecture with unbroken intake, provenance and decay closes those ties as fast as they are closeable at all. What is left afterward is not a data problem. It was never going to be solved by a bigger corpus, a longer window, or a fourth generation of model. It is the philosophical residue that was always going to survive, and the honest response to it is not more sensors. It is knowing which gaps are yours to close and which were never closable in the first place.