🛡 Philosophy 05 of 05 · Secure · added August 2026
Nothing you own fails on its own.
Secure is the verb for keeping yourself, your people and your work out of harm. It is the newest of the five and the smallest — 27 capabilities, carried by 14 classes, running from order 7 to order 13. It is also the least finished, and the rest of this page is the accounting.
! Start here, because a security page that flatters itself is worthless. Of the 27 capabilities below, 10 are taught in a class with a session on the calendar. 10 are written into classes with no date on them. 7 have no class behind them at all. Every one of those numbers is on this page, marked, in the grid further down.
- Capabilities
- 27
- Classes carrying
- 14
- Complexity
- 7 → 13
- Top stage
- Metasystematic
- Bookable now
- 10 / 27
- Defence video
- 1.0 h
- Paths leaning on it
- 7
- Recurring hour
- Secure Hour
- Lead
- Liz
- Cadence
- not set
Secure Hour exists in the plan with Liz named as lead. It has no day, no time and no cadence recorded, so the school's own validator flags it on every run. Until that changes, treat the hour as a promise rather than a thing you can turn up to.
The dependency chain
The phone is gone. Walk what goes with it.
Security advice is a list until it is a chain. Six questions about your own setup, answered honestly, and the chain gets drawn as yours: which links hold, which snap, and what is left standing at the far end. Each break names the class that closes it.
- 01 · given The phone Left in a taxi, taken off a table, does not matter which. Lost
- held the second factor
- 02 Your second factor The codes, the prompt, the thing that proves it is you. ?
- guards the email
- 03 Your email Not a mailbox. A key ring. ?
- recovers everything else
- 04 Everything it recovers Bank, domain, cloud, the group chat your family trusts. ?
- and then the money
- 05 · far end The account your customers pay through The one you would have to ring people about. ?
Answer these about your own setup. With scripting off you get the whole list at once, with every remedy under it — which is the same information, in a less theatrical order.
-
Question 1 · the second factor
Was the only copy of your second factor on the phone that just went? Authenticator app with no export, push prompts to that handset, codes you never printed.
Digital Identity Defense $60 · liveorder 9 configure recovery that survives losing the device
What you have to showRecovery codes printed and stored off any device, a password manager on every device, SMS removed as a recovery method, and a written account of what happens if the phone is gone.
-
Question 2 · the number
Can a text message to that number still reset the password on your main email? Check rather than guess. Most people who say no have an old fallback switched on.
Digital Identity Defense $60 · liveorder 9 configure recovery that survives losing the device
What you have to showRecovery codes printed and stored off any device, a password manager on every device, SMS removed as a recovery method, and a written account of what happens if the phone is gone.
-
Question 3 · the phone call
Somebody rings claiming to be your carrier, confirming the replacement SIM. Does your household have an agreed way to check that does not involve trusting the caller? A number you ring back on. A code phrase. Anything that is not the caller's own word.
Scam and Fraud Home Defense $60 · liveorder 9 operate a callback rule against incoming contact
What you have to showA household agreement in writing including a code phrase, and one real incoming contact you broke off and called back.
-
Question 4 · the device you forgot
Is there a device you no longer really control still signed into that email? The handset you handed down, the tablet in the kitchen, the laptop at a parent's house.
Consumer Device Rescue and Defense $60 · liveorder 7 follow a device hardening checklist
What you have to showThe router or device admin pages before and after — default password changed, remote administration off, automatic updates on — with one line per item on what it closes.
-
Question 5 · the blast radius
Could you name every device on your home network right now, without looking? The phone knew your wifi. So does everything else that is still on it.
Home Network Defense $60 · liveorder 8 locate every device on your own network
What you have to showA device inventory taken from the router, with each entry identified or explicitly listed as unidentified.
-
Question 6 · the only one that settles it
Have you ever tried to take over your own accounts from the outside — the recovery flow, the help desk, the lot? Every answer above is a claim about a system you have not tested. This is the question that turns them into evidence.
Digital Identity Defense $60 · liveorder 11 falsify your own account recovery by attempting it
What you have to showA written attempt log against your own accounts, the furthest step reached, and the control you added because of it.
Trace log · every answer prints here, including the questions your earlier answers make pointless. Nothing is sent anywhere; the walk runs in this tab and is forgotten when you close it.
Order matters
Identity defence comes after scams, and it took a rewrite to notice.
The ontology records that falsify your own account recovery by attempting it composes from classify an incoming contact as genuine or pretext. That is not a preference about syllabus order. Falsifying your own account recovery means ringing your own provider and pretexting yourself: inventing a plausible story, in a plausible voice, and seeing how far it gets. You cannot write a convincing pretext until you can read one.
An earlier version of this curriculum ran the other way round — identity first, because it felt more foundational, and scams later because they felt like a consumer topic. Students arrived at the recovery drill with no way to tell a good story from a bad one, and produced attempts too weak to prove anything. The order on the page now is the corrected one.
Scam and Fraud Home Defense → Digital Identity Defense. Both $60, both on the calendar.
Inventory, marked
All 27 capabilities, and which of them you can actually get.
One cell per capability, in complexity order. The colour is the honest part.
- 10 bookable Taught in a class with a date on the calendar, so there is a seat to book.
- 10 written, unscheduled A class exists and holds the material; there is no date on it, so you cannot enrol.
- 7 with no class The ontology claims the capability. No class in the catalogue binds it yet. This is intent, not a product.
-
7Preoperational
follow a device hardening checklist
bookable Consumer Device Rescue and Defense · AI-Assisted Attacks: What Actually Happened
The router or device admin pages before and after — default password changed, remote administration off, automatic updates on — with one line per item on what it closes.
-
8Primary
execute a security playbook in a drill
unscheduled Field Opsec
A completed drill — a cold-phone bring-up, a dead-drop site selection, a doxx scrub of yourself — with the steps that did not survive contact and what you did instead.
-
8Primary
locate every device on your own network
bookable Home Network Defense
A device inventory taken from the router, with each entry identified or explicitly listed as unidentified.
-
8Primary
locate the standard that governs a system you are building
unscheduled AI Security: Governance, Standards and Safety Cases
One system, the governing instrument named, and the specific requirement it places on you.
-
9Concrete
configure an assistants memory and outside connections
bookable Critical Thinking and Creativity with AI
Memory on with one fact it retained across a fresh conversation, one connector enabled with the scopes it was granted written out, and one source you deliberately did not connect with the reason.
-
9Concrete
configure recovery that survives losing the device
bookable Digital Identity Defense
Recovery codes printed and stored off any device, a password manager on every device, SMS removed as a recovery method, and a written account of what happens if the phone is gone.
-
9Concrete
operate a callback rule against incoming contact
bookable Scam and Fraud Home Defense · Digital Identity Defense
A household agreement in writing including a code phrase, and one real incoming contact you broke off and called back.
-
9Concrete
operate a mesh network that carries messages without infrastructure
bookable Solarpunk Automation
A message delivered node to node with the internet off, reporting the distance covered and the number of hops it took.
-
9Concrete
produce a list of where untrusted input enters a system
bookable Agentic SDLC · Blue Team Common Certification · Agentic AI Security: Securing What You Build
An enumerated list against a real codebase or system, including one entry point that is not an obvious form field.
-
9Concrete
produce a refusal boundary that fires on cases you did not list
no class yet No class in the catalogue teaches this yet.
Three declines on cases absent from the boundary text, three accepts on near neighbours you did want, and the near miss that made you rewrite it.
-
9Concrete
produce a threat model for your own situation
unscheduled Field Opsec
Your own tier model, naming the adversary and capability at each tier, with the specific practice each tier changes.
-
9Concrete
transform an incoming message into ask deadline and claimed sender
no class yet No class in the catalogue teaches this yet.
Three real messages from your own inbox split into the three parts, with the ask restated in your own words and the deadline named as invented or genuine.
-
10Abstract
characterise an applications injection surface
bookable Agentic SDLC · Blue Team Common Certification · Agentic AI Security: Securing What You Build
A written surface map for a real application naming the query, template or shell interpreter behind each entry point.
-
10Abstract
characterise how an ai assisted attack unfolded
unscheduled AI-Assisted Attacks: What Actually Happened
One documented incident traced end to end, with the model's contribution distinguished from what conventional tooling could already do.
-
10Abstract
characterise what a publication reveals about its source
no class yet No class in the catalogue teaches this yet.
A draft publication with the identifying details enumerated — including the ones only an insider would notice — and the redactions made, reviewed by someone who did not write it.
-
10Abstract
characterise what breaks when you cut the connection
unscheduled Keep It Running
A planned outage exercise with what was predicted beforehand, what actually failed, and the gap between the two.
-
10Abstract
classify a situation into the playbook it calls for
unscheduled Field Opsec
Three situations routed to playbooks with the deciding tier named for each, including one where the alarming option was the wrong one.
-
10Abstract
classify an incoming contact as genuine or pretext
bookable Digital Identity Defense · Scam and Fraud Home Defense
Five real examples classified with the tell named for each, including one genuine message that looked like a pretext.
-
10Abstract
classify which framework applies where you are in the lifecycle
unscheduled AI Security: Governance, Standards and Safety Cases
Three systems at different lifecycle stages, each routed to the framework that governs it, with the stage that decided it named.
-
10Abstract
classify your channels by what removes them
no class yet No class in the catalogue teaches this yet.
Your group's channel list with the actor who can remove each — carrier, platform, state, power company — and the fallback tested at least once.
-
11Formal
falsify an applications defences against a named attack class
unscheduled The Dark Arts (Red Team) · AI-Assisted Attacks: What Actually Happened
A working input that reaches the interpreter, the fix, and a regression test that is red before the fix and green after.
-
11Formal
falsify your own account recovery by attempting it
bookable Digital Identity Defense
A written attempt log against your own accounts, the furthest step reached, and the control you added because of it.
-
11Formal
justify a safety case for a system that acts without you
unscheduled AI Security: Governance, Standards and Safety Cases
A written safety case for one autonomous system, with its falsifying condition stated and the evidence that would settle it.
-
11Formal
verify a community system survives a cut you did not choose
no class yet No class in the catalogue teaches this yet.
An unannounced cut chosen by someone else — uplink pulled, battery disconnected, a node removed — with what the community could still do counted in messages delivered and decisions made rather than in uptime, and the thing you had believed was resilient that was not.
-
12Systematic
design a community information system that survives losing the internet
no class yet No class in the catalogue teaches this yet.
A system serving a real group through at least one unplanned failure, the absorbed failure named per component with the cost of each choice stated, the features it shed rather than the minutes it was down, and the written rule for reconciling work done while disconnected.
-
12Systematic
design a household security posture for people who did not choose it
no class yet No class in the catalogue teaches this yet.
A posture in place across at least three people who did not set it up, and one protection that held when someone did the wrong thing anyway.
-
13Metasystematic
reconcile security with what people will actually do
unscheduled Field Opsec
A requirement people were bypassing, the revised version they follow, and evidence the revision still closes the original threat.
What is in the box
There is almost no video. Here is what there is instead.
3 of the nine paths in this school can lead with recordings. This one cannot, so it will not.
across the 10 classes of the defence path — one clip, in the red team class, which is not scheduled either.
53.8 hours of video sit in the 14 classes that carry a Secure capability, but 48.9 of those hours are the two AI classes that happen to teach secure habits alongside their own subject. Buying for the recordings means buying those, not these.
exercises across the carrying classes, and a live session with a person in it. Defence is a practice with proof requirements, not a lecture: every capability on this page names the artefact you have to produce.
- Live teaching, at $60 a class
- Proof requirements written before the class, printed above
- Reference apps you keep
reference apps across the whole defence path, shared between its classes:
Not one of them is a guided tool that walks you through the work; they are references you read. The 13 other apps in the 14 carrying classes belong to the AI and solarpunk classes and are about their own subjects.
On the calendar
Four classes, 10 capabilities, $60 each.
In this order, and the order is argued: your network, then the devices on it, then the people who ring them, then the accounts those people are after.
Home Network Defense
$60- order 8locate every device on your own network
Consumer Device Rescue and Defense
$60- order 7follow a device hardening checklist
Scam and Fraud Home Defense
$60- order 9operate a callback rule against incoming contact
- order 10classify an incoming contact as genuine or pretext
Digital Identity Defense
$60- order 9configure recovery that survives losing the device
- order 11falsify your own account recovery by attempting it
- order 10classify an incoming contact as genuine or pretext
- order 9operate a callback rule against incoming contact
Where else it turns up
Secure is cross-listed into paths that are not about security.
Of the nine paths, 7 carry at least three Secure capabilities, and only one of them is a security path. That is deliberate, for two reasons worth saying out loud.
A solo founder is the company's single point of failure. “configure recovery that survives losing the device” is filed under security, but for one person carrying a business it is business continuity: the difference between a bad afternoon and telling your customers why nobody can bill them.
People who build things that provoke draw attention they did not plan for. A project that gets noticed brings an audience you did not choose. That is a threat model arriving after the fact, which is the worst time to write one.
Disqualifiers
Who should not buy this.
- Anyone in immediate danger. If somebody is in your accounts right now, or you are being followed, this is a course schedule and you need help today. Ring the people whose job that is.
- Anyone who wants a certificate. The blue team certification class exists and has 24 exercises written for it. It has no session on the calendar and no date to give you.
- Anyone who wants offensive security. The red team class holds the school's single recorded hour on this subject and is not scheduled. This philosophy is defence.
- Anyone who needs recordings. The defence path has 1.0 h of recorded video in total. Buy on the strength of the live session and the proof requirements, or do not buy.
Where this stands today
Four doors are open. The rest are drawn on the wall.
| What | State | What that means for you |
|---|---|---|
| Four home defence classes | live | $60 each, on the calendar, in the order argued above. This is the part you can buy today. |
| 10 capabilities in unscheduled classes | written, no date | Field opsec, blue team, red team and the three AI security classes are written and carry 48 exercises between them. You cannot enrol in any of them. |
| 7 capabilities | no class | Household posture, community comms, channel analysis and the rest. Stated in the ontology, taught nowhere. Do not buy anything expecting them. |
| Secure Hour | no cadence | Led by Liz on paper. No day, no time, no cadence recorded. Make, Own and Influence each have an hour with days against it; this one does not yet, so do not plan a week around it. |
That is the whole position. The four live classes are genuinely good and genuinely narrow: they will leave your household harder to take, and they will not make you a security professional. If the rest of the list is what you came for, take the four, and put your name on the defence path so the unscheduled six get scheduled for a reason.