# A-009

- **Artifact ID:** A-009
- **Status:** RETIRED
- **Public record:** https://record.cybersecurityhq.com/assumptions#A-009
- **Machine-record SHA-256:** `45b9e4686bb25f46a9fd5f305844a619a0afee6242d64411d69ca0d7fb58be45`

## Complete structured record

```json
{
  "id": "A-009",
  "statement": "Credential freshness bounds attacker utility more than attacker automation bounds defender reaction time",
  "status": "RETIRED",
  "category": "Retired",
  "ledger_references": [],
  "retirement_date_bound": "On or before 2026-03-13. INFERRED — upper bound from CHQ-PM-2026-002 (issued 2026-03-13), which treats the retirement as a prior fact. Exact retirement date: UNRECOVERABLE. No earlier record names a specific date.",
  "retirement_rationale": "AUTOMATION SIDE OVERTOOK. The comparative claim collapsed because attacker automation compressed defender reaction time below the threshold at which credential freshness provides any meaningful operational bound on attacker utility. Contemporaneous evidence (CHQ-PM-2026-002, citing CrowdStrike 2026 Global Threat Report): average eCrime breakout time 29 minutes; fastest observed breakout 27 seconds from initial access to lateral movement; 82% of detections malware-free, relying on stolen credentials and legitimate tooling; 89% year-over-year increase in AI-enabled adversary operations. A freshness constraint that would need to operate in under 27 seconds to matter is not a useful control — it is a reductio that shows the comparison frame failed, not that freshness is a lever worth shortening. Tag-versus-evidence note: CHQ-PM-2026-002 labels the retirement as '(retired, credential freshness bounds attacker utility).' This is the assumption's label, not a verdict on which side failed. The breakout time data is the operative evidence and it resolves the comparison toward the automation side. Confidence: INFERRED from contemporaneous evidence. The data file contained no explicit retirement rationale at time of reconstruction (2026-06-09). PERMANENT GUARDRAIL: The automation-side resolution is a reductio, not a design recommendation. This retirement establishes that the freshness-versus-automation comparison collapsed because automation won. It does not establish that credential lifetime is a consequential control. The breakout evidence is about speed of lateral movement after initial access — not about how long harvested credentials remain valid after theft. These are structurally different claims. No credential-lifetime assumption, position, memo, exhibit, or docket may cite this retirement as supporting evidence for lifetime as a consequential control.",
  "supersession_pointer": "NONE. The surviving half of A-009 — that attacker automation bounds (compresses) defender reaction time — is real and evidenced but orphaned. It exists as context in CHQ-PM-2026-002 (forces_eroding entry, CrowdStrike breakout data) and is adjacent to CHQ-P-2026-007 (ROTATION_AS_ASSURANCE class), but no assumption, position, or condition carries it as a primary claim. P-2026-007 occupies the same assumption class but is narrowly about certificate lifetime compression not addressing hardware trust architecture — it does not absorb A-009's comparative claim about attacker utility versus defender reaction time. The orphaned half should be formally claimed before any new artifact in this domain is created. Confidence: INFERRED — full search of assumptions, positions, memos, and structural conditions at time of reconstruction (2026-06-09).",
  "related_positions": [],
  "retirement_evidence_state": "ESG-SUFFICIENT NON-POSITION EVIDENCE (RECONSTRUCTED)",
  "retirement_audit": "COMPLIANT BY ALTERNATE INSTRUMENT — CHQ-PM-2026-002 preserves the contemporaneous, independently sourced evidence. CHQ-P-2026-007 is not retirement provenance."
}
```
