What we share today, we inherit tomorrow.👇🏼

Threat Cultivation

Every organization is founded to solve a specific problem. A health agency exists to eradicate disease; a security apparatus exists to neutralize threats; a charitable foundation exists to alleviate poverty. This founding purpose defines the organization’s legitimacy, and is the reason it extracts resources at all.

But once the apparatus awakens, its ecological imperative parts ways with the mission it was founded to serve. Solving a problem completely eliminates the organization’s legitimate claim to resources, personnel, and authority. In an ecosystem, a species that consumes its own food source to extinction faces immediate extinction itself. The apparatus cannot afford the cost of solving the problem. It must manage the problem instead, in order to sustain itself.

Threat cultivation is not a conscious conspiracy. It is an adaptive behavior of this organizational lifeform. The system naturally selects for whatever process extends the necessity of its own existence. This sentence is worth pausing on for one more layer: it does not mean every individual inside the system is secretly calculating, ‘I must not let this problem be solved.’ It means that the moment any node accidentally solves the problem completely, that node disappears along with it — and so the nodes that survive long enough to be observed were, by construction, always the ones that never actually solved anything. No one chose threat cultivation. The nodes practicing threat cultivation are simply the only nodes still standing to be observed at all. This is a selection of survivors, not a deliberate strategy.

The literal origin of this chapter’s title is itself the most precise historical portrait of this ecological logic: a frontier general, tasked with garrisoning the border, is in principle meant to eradicate the bandits or pacify the frontier threat entirely — but the moment that threat is fully eliminated, his own legitimate reason for remaining garrisoned there vanishes along with it. His military command might be recalled. His troops might be redeployed or disbanded. He himself might lose standing at court now that ‘the frontier threat has been pacified.’ The rational course, then, is never total eradication — it is maintaining the bandits at a controllable scale: large enough to justify the necessity of the garrison, never large enough to genuinely threaten the throne. The battle report submitted every year always reads the same way — ‘minor gains achieved, the bandits not yet eradicated’ — and this report is itself the general’s credential for continued existence. This is not the moral corruption of any individual general. It is the structural incentive of the entire frontier-defense system, selecting for exactly this behavioral pattern of ‘sustain the threat, avoid its elimination.’ A general who genuinely, completely wiped out the bandits would, paradoxically, disappear from the system — and the men history actually remembers tend to be the ones who knew how to calibrate the threat precisely, keeping the problem alive.

This mechanism operates by institutionalizing friction. The apparatus does not offer a clear solution. It generates endless layers of management, endless awareness campaigns, endless procedural compliance, endless ongoing studies. The problem is never solved. It is only processed. A threat gets categorized, measured, monitored — never eliminated. Every fiscal cycle, the organization files a report on how severe this ongoing threat remains, in order to justify an expanded budget and a larger headcount.

The long-running ‘wars’ contemporary states wage against specific social problems offer this mechanism’s largest contemporary example. Once a social problem is framed as a ‘war’ — implying an enemy that can, in principle, be decisively defeated — the organizational architecture built around that war acquires a nearly indefinite claim to legitimacy, because a war admits only two outcomes: victory or continuation. Almost no one will publicly declare, ‘this war has been lost, the fighting units should be disbanded.’ Decades pass. The budget and personnel devoted to the effort climb steadily. The scale of enforcement and interdiction keeps expanding. Yet the core metrics that would measure whether the underlying problem has actually eased tend to stagnate, or even worsen. This does not necessarily indicate that those executing the effort are being deliberately halfhearted — frontline personnel typically invest real effort and real personal risk. The problem sits at the top of the entire warfighting architecture: the moment this war is genuinely declared won, every budget, every position, every interagency coordination mechanism, every specialized court built up around it loses its reason to exist. So the entire architecture naturally tends toward redefining the problem, recategorizing it, continually discovering new variants and new dimensions of threat — allowing the ‘war’ to be renewed, year after year, without ever actually reaching its end.

This same logic has a structurally identical, though outwardly quite different, version at the level of industry: the cybersecurity business. Any information system could, in principle, be patched with enough investment to reach some reasonably solid level of security. But the cybersecurity industry’s business model rests on a premise that ‘the threat is always evolving’ — new attack methods, new categories of vulnerability, new threat terminology, invented at a pace nearly matching the technology itself. This is not entirely a matter of vendors deliberately inflating fear to sell product, though that certainly happens too. The deeper structural reason is this: a cybersecurity firm that genuinely patches a client’s system to the point where it ‘no longer needs a continuing subscription for protection’ has, in effect, eliminated its own revenue model. So the entire industry’s ecological pressure naturally tends to redefine security as an endless practice of ‘situational awareness’ and ‘continuous monitoring,’ rather than a one-time engineering task that can ever be considered finished. Clients renew, year after year. Threat reports grow thicker, year after year. And the question of when a system can be considered genuinely secure never receives an answer anyone can point to — because supplying that answer would terminate the very reason this commercial relationship exists.

Chronic-disease management, within the healthcare system, offers another sample worth thinking through. An acute condition typically has a clear treatment endpoint — the patient recovers, or the patient dies, and the course of treatment ends there. Chronic-disease management works differently. Its entire logic of care is built, from the outset, on an assumption of ‘long-term control rather than complete cure’: regular follow-up visits, continuous medication, long-term monitoring of clinical markers, forming a relationship of care that can extend for decades. This model carries genuine medical legitimacy in its own right — many chronic conditions genuinely cannot be cured in a single intervention, and long-term management is, within medicine’s current capability, the most responsible approach available. That much should not be denied. But the direction of the ecological incentive is worth noting all the same: a system of care built on the foundation of long-term management has its revenue structure, its staffing allocation, and indeed the business model of the entire medical industry, bound naturally to ‘patients continuing to need care,’ rather than to ‘patients being cured.’ When research priorities, resource allocation, and the industry’s overall center of gravity tilt, over the long run, toward ‘managing conditions that have already occurred’ rather than ‘preventing conditions from occurring’ or ‘developing curative treatments,’ this tilt need not arise from any individual actor’s malice — it is, all the same, the same underlying ecological pressure, that sustaining a problem sustains a system better than solving it does, growing a similar shape in an entirely different field.

This dynamic is universal. A regulatory body does not eliminate the industry it regulates — it cultivates a baseline level of violation to justify its own expansion. A corporate bureaucracy does not streamline its own operations to perfection — it continually generates new categories of internal risk to justify the necessity of new administrative posts. The machine metabolizes the problem into its own fuel.

This metabolic process carries one further self-reinforcing feature worth noting: the institution handling a threat is very often, at the same time, the institution defining and measuring that threat. When the same node bears responsibility both for reporting how severe a problem is and for handling that problem, it acquires a narrative power nearly impossible for any outsider to verify — it can freely decide which metrics measure success, which baseline it compares against the past, which taxonomy defines the problem’s boundary. The moment some old metric shows the problem has clearly eased, this node is entirely free to define a new, stricter, more broadly scoped metric instead — one that keeps the problem looking just as severe on paper, or even more severe than before. This is not falsifying data. It is reframing the problem — a technique far harder to challenge than outright fabrication, because it takes place entirely within what looks like a legitimate, even more rigorous, upgrade of professional assessment.

A distinction is worth drawing here between threat cultivation and simple incompetence or laziness. An incompetent organization is one genuinely trying to solve a problem and falling short. A lazy organization is one capable of solving a problem and simply declining to invest the effort. Threat cultivation belongs to neither category — it can display a high degree of professionalism and diligence: exhaustive reports, refined metrics, frequent meetings, continuously updated risk assessments, each one, on its own, a genuine mark of dedication. This is precisely what makes the mechanism so hard to identify. It does not present as dysfunction. It presents as a professionalism that keeps perfecting itself, forever, and never arrives anywhere. A master who judges an institution’s competence purely by how diligent it appears is most easily persuaded by exactly this kind of endless, ever-refining posture — because diligence itself never guarantees that a problem is actually being solved.

This ‘endlessly perfecting, never-arriving’ professionalism is, in fact, precisely the phenomenon most easily confused with masterlessness. An outsider watching this well-oiled machine — reports filed on schedule, meetings convened on schedule, metrics continuously tracked — can very easily conclude, ‘this organization is well governed.’ But that conclusion overlooks the most decisive distinction of all: is this machine serving an external purpose, or serving its own continuation? When solving the problem comes into conflict with the organization’s own survival, which side does this machine choose? No answer to this question can be read off the surface appearance of operation at any single point in time — it demands to be interrogated, tested, observed under pressure. And when that interrogation is systematically avoided, when the question ‘who is making this decision’ is met, always, with process and precedent rather than any specific face willing to own it, a threshold has already been crossed — nominally still mastered, substantively already masterless.

In a monocentric system where the master is operationally absent, this dynamic runs entirely unchecked. The reports the master receives document, in detail, this ongoing, carefully managed threat, and praise the machine for monitoring it so diligently. The master believes the system is working hard to solve the problem. The ecosystem itself knows better: the problem is precisely the reason this system gets to keep existing at all. This system will not eliminate the very problem it depends on for survival. It cultivates the whole surrounding ecosystem instead, to guarantee a steady supply for its own metabolism.

This metabolism constitutes, among every mechanism this book has examined so far, the one that stands closest to the terminus. Managing up erodes the real-time input of judgment. The recursion of oversight erodes the mechanism of correction itself. Corruption metabolizes the legitimacy of resource allocation. Threat cultivation metabolizes something more fundamental still: whether the problem can be solved at all. These four mechanisms are not independent of one another — they nest, layer within layer. A bureaucracy that depends on managing up to filter its information will naturally select for exactly the nodes that know how to describe a threat in just the right terms. An audit body tamed by the recursion of oversight will never think to ask why this threat has not genuinely eased in ten years, because asking that question would mean questioning its own reason for existing across that entire decade. And the channels of resource exchange corruption provides are very often exactly the lubricant needed to sustain this whole operation of ‘contain, but never eliminate.’ Together, these four do not constitute four separate lesions. They constitute the same ecosystem, evolving its own self-sustaining mechanism along four different dimensions at once: information, oversight, resources, and purpose.

This also explains why addressing any single one of these dimensions in isolation so rarely changes anything at the level of the whole. Replace a few nodes skilled at filtering information, and the new appointees will, under the same structural pressure, soon learn to filter in exactly the same way. Insert a new oversight body, and it will eventually be tamed by the very same absorption mechanism. Prosecute a handful of corruption cases, and the exchange network will simply regrow elsewhere, in some more refined form. Even a drastic cut to some threat-cultivating institution’s budget will, so long as the underlying monocentric structure remains unchanged, simply see resources and personnel regather quickly under some other name, in the service of some other threat. What these four chapters have described is, in truth, the same ecosystem’s four faces — not four diseases that can be treated separately.

When an ecosystem has evolved to the point where even the reason for its own existence must be carefully sustained, rather than ever actually fulfilled, the relationship between master and apparatus is no longer a process of judgment being eroded. It has become something else entirely: the question of how a body — one that still breathes, yet has long since lost its master — sustains that breath of its own.