22. The Weakness That No One Saw
Domain: Vulnerability Management POV: Thread Reading time: ~15 minutes
The weakness had existed for three hundred years, and no one had ever noticed it.
Thread discovered it on a cold morning in the deepest level of the gear-chambers, during a routine inspection of the mechanisms that regulated the flow of water through the city’s aqueduct system. The inspection itself was not routine — nothing had been routine since the Shroud arrived — but it was part of a systematic vulnerability assessment that Thread had been conducting for weeks: checking every mechanism, every door, every access point that could potentially be exploited by an adversary who understood the city’s infrastructure better than the city understood itself.
The weakness was a single gear, deep in the aqueduct control mechanism, that had been installed incorrectly when the system was first built. The gear was functional — it had been turning reliably for three centuries, regulating the water flow without incident — but it was one size too small for its housing. The gap between the gear and the housing was barely visible — a fraction of an inch, no wider than a fingernail. But it was enough. If the gear were to be pushed even slightly out of alignment — by a tremor, by a surge of water pressure, by a deliberate act of sabotage — the entire aqueduct system could seize. And if the aqueduct seized, the gear-chambers would flood, and the city’s primary infrastructure would be destroyed.
“This is a vulnerability,” Thread said, reporting the finding to the council. “A weakness in the system that could be exploited by an adversary. It has existed since the city was built. It has never been exploited because no one has ever tried to exploit it. But it exists. And now that we know it exists, we have to decide what to do about it.”
The vulnerability management process that the fellowship established over the following weeks was the most systematic thing the Citadel had ever attempted.
Step one was identification: finding every weakness in the city’s infrastructure, from the smallest gear to the largest structural support. Thread led this effort, because Thread’s gift for observation was the most valuable tool the city possessed. Every mechanism was examined. Every door was tested. Every seal was checked for wear and corrosion and misalignment. Engineers and archivists and citizen volunteers were trained to recognize the signs of a potential vulnerability — the gear that was slightly too small, the door that did not quite seal, the mechanism that had not been inspected in living memory — and to report their findings to a central registry that Quill had designed.
Step two was prioritization: deciding which weaknesses mattered most and which could be deferred. Kip led this effort, applying the risk calculation methodology he had developed during the defense of the Middle Ring. A vulnerability was important not because it was large — the small ones were often the most dangerous — but because of the threat that could exploit it and the impact if it was exploited. The gear in the aqueduct, for example, was a small vulnerability that could cause catastrophic impact if exploited by a determined adversary who understood its significance. It was prioritized accordingly.
Step three was remediation: fixing the weaknesses, one by one, in order of priority. Sable led this effort, working with Tessa and the engineers to design and implement repairs. The gear in the aqueduct was replaced — carefully, over the course of a single night, while the water flow was temporarily diverted through secondary channels. The misaligned doors were re-hung. The corroded seals were replaced. The mechanisms that had not been inspected in living memory were brought up to current standards.
“We have to keep going,” Thread said, when the initial round of remediation was complete and the council had convened to review the results. “Vulnerability management is not a one-time process. It is a continuous cycle — identify, prioritize, remediate, and then begin again. Every repair introduces the possibility of new weaknesses. Every change to the system creates new attack surfaces. We will never be finished. We will simply be more prepared than we were before.”
The vulnerability that almost destroyed the city was not the one Thread had found. It was one that no one had thought to look for, because it was not a mechanism or a door or a physical weakness at all.
It was a process. A procedure. A routine that had been followed for so long that no one questioned it — the weekly synchronization of the automaton workforce, during which all of the city’s brass workers were temporarily taken offline, their mechanisms reset and recalibrated. The procedure required a single engineer — only one — to access the central automaton control panel, enter the shutdown sequence, and wait for the reset to complete. The procedure had been designed centuries ago, in an era when the automaton workforce was small and the risks of centralized control were negligible. It had never been updated, because it had never been questioned.
Vale’s agents had found the vulnerability, even if Thread and the fellowship had not. On the night of the weekly synchronization, a compromised engineer — one of the insiders that Thread had identified but not yet been able to interview — entered the control panel with instructions that had been prepared by Vale’s network. Instead of the standard shutdown sequence, she entered a sequence that had been modified — subtly, almost imperceptibly — to introduce a backdoor into the automaton control network. The backdoor would allow Vale, or anyone with the correct access codes, to issue commands to the automaton workforce directly, bypassing the human supervisors and the access controls and the verification procedures that had been established over the past months.
Thread caught the compromise not by noticing the engineer’s behavior — she had acted normally, performed her duties without apparent deviation — but by noticing the automata’s behavior the following morning. One of the brass workers in the gear-chambers had hesitated for a fraction of a second before performing a routine task. A hesitation that no one else would have noticed. A hesitation that Thread, who had been watching the automata for weeks, recognized as wrong.
The backdoor was identified and closed. The compromised engineer was interviewed and, like Lissa before her, given the choice between cooperation and consequences. The synchronization procedure was redesigned — two engineers instead of one, independent verification of the control sequence, a third-party audit of every reset — to ensure that the vulnerability could not be exploited again.
“We cannot find every vulnerability,” Thread said to the fellowship, late that night in the shed. “The city is too complex. The systems are too old. The procedures are too numerous. There will always be weaknesses we have not found, procedures we have not examined, assumptions we have not questioned. The goal is not perfection. The goal is to find more weaknesses than the adversary finds, and to fix them faster than the adversary can exploit them.”
“And to keep looking,” Kip said. “Forever. Because the moment we stop looking — the moment we assume that the system is secure and the vulnerabilities have all been found — is the moment the adversary finds the one we missed.”
Thread nodded slowly, the motion almost imperceptible. “That is what vulnerability management is. Not a project with an end date, but a practice — something you do continuously, forever, because the alternative is leaving weaknesses in place and hoping that no one finds them. And hope, as we have learned, is not a strategy.”