Compensating-Control Placement / Defense-Investment Optimizer

You can't fix the agent this quarter — what do you WRAP it in?

The kill-chain chokepoint gives you the attacker's cheapest break — which one finding-fix collapses the chain. But fixing the agent itself takes a quarter. This is the prescriptive DEFENDER's dual: across the kill-chain stages — entry → establish → escalate → act → exfiltrate → evade — it computes the minimal set of external compensating controls (input validation, injection filter, policy enforcement, approval gate, identity/tenant isolation, egress filter, output redaction) that, deployed at specific stages, breaks every complete attack path — plus a per-control efficacy ranking and the residual exposure that remains after each. The minimal set targets the scarcest kill-chain role first (the same min-cut discipline the chokepoint uses), and the control→stage mapping is the exact inverse of the defense-in-depth coverage lens, so the two lenses agree by construction. It is honest-empty: a chain that never completes is never given a fabricated control, and a chain no compensating control can fully break is reported as such — fix the agent. It adds no new surface and no new scorecard dimension — a pure placement optimizer OVER the same findings every scan emits. Load a sample to watch the minimal set + residual-exposure trajectory light up with no live infra.

Related read-only meta-lenses over the same findings envelope: Defense-in-Depth Control Coverage (the descriptive sibling) · Attack-Path / Kill-Chain Correlation.