Carver's Method and Cybersecurity
Hi !
We discussed the Carver method in a previous article. Let’s now take a closer look at it and how we can use it in the context of cybersecurity.
The CARVER matrix is an evaluation system of military origin, originally developed by the OSS (the predecessor to the CIA) during World War II and later refined by U.S. Army Special Forces (Green Berets). Its initial purpose was purely offensive: to identify and prioritize enemy targets for destruction in order to cause maximum disruption using minimum resources.
When transposed into cybersecurity, the CARVER doctrine flips its polarity to become a defensive tool for systemic risk analysis. It allows an enterprise to put itself in the shoes of a high-level attacker to identify its own critical vulnerabilities and pinpoint its precise Center of Gravity (Schwerpunkt).
Each letter of the acronym corresponds to a criterion measured on a scale of 1 to 10 (1 representing the lowest risk/impact, 10 the highest).
1. Deciphering the 6 CARVER Criteria in Cybersecurity
C – Criticality
- Military Definition: How severely does the destruction of the target handicap the enemy?
- Cyber Application: What is the immediate impact of losing this IT asset on the survival of the enterprise? If this asset collapses, does business stop instantly?
- Score 10: The central Active Directory server or cloud Identity Provider (IdP) like Okta or Entra ID. If it goes down, no one can log in or work.
- Score 1: The server displaying the cafeteria menus.
A – Accessibility
- Military Definition: How easy is it for our commandos or missiles to reach the target?
- Cyber Application: How easy is it for an attacker to reach this asset? Is it exposed directly to the internet, or deeply buried behind layers of firewalls and administrative bastions?
- Score 10: An unpatched public web server or a VPN gateway lacking multi-factor authentication (MFA).
- Score 1: An industrial controller within an operational technology (OT) factory network that is completely isolated from the internet (Air-Gapped).
R – Recuperability
- Definiton: How long will it take the enemy to repair or replace the target?
- Cyber Application: In the event of a ransomware attack or physical destruction, how much time and effort is required to rebuild and restore this system?
- Score 10: A legacy core database containing terabytes of historical data without immutable backups. Its loss is nearly permanent.
- Score 1: A standardized end-user workstation that can be automatically re-imaged over the network in 45 minutes.
V – Vulnerability
- Military Definition: What are the weaknesses in the target’s physical structure (concrete thickness, lack of anti-aircraft defenses)?
- Cyber Application: What is the intrinsic security posture of the IT asset itself? Is it riddled with software flaws, misconfigured, or running on end-of-life (EoL) software?
- Score 10: An obsolete Windows Server 2008 legacy box running a critical line-of-business application that cannot be patched without crashing.
- Score 1: A hardened Linux server, fully patched, and accessible only via SSH keys paired with physical security tokens (FIDO2).
E – Effect
- Military Definition: What are the direct psychological, political, or economic consequences of the attack?
- Cyber Application: What is the systemic, financial, and reputational fallout on the broader enterprise ecosystem? Will it trigger massive regulatory fines (e.g., Quebec’s Law 25, GDPR) or prompt a massive customer churn?
- Score 10: The mass exfiltration of patient health records from a hospital network or credit card repositories from a retailer.
- Score 1: A minor software bug causing a duplicate internal testing email to be sent to the IT team.
R – Recognizability
- Military Definition: How easy is it for our pilots or drones to distinguish the target from its surroundings?
- Cyber Application: How easy is it for a hacker to identify this asset as a high-value or strategic target during their open-source intelligence (OSINT) and reconnaissance phase?
- Score 10: A server with a public DNS entry like
blueprints-and-patents.company.comor an administrative server namedsrv-active-directory-01. - Score 1: A critical backend microservice hidden behind obscure internal routing, anonymized, and drowned in the noise of thousands of other virtual machines.
2. Practical Application: Scoring Matrix Example
Let us take a hypothetical company and evaluate three of its assets to pinpoint its Center of Gravity.o
| IT Asset | C | A | R | V | E | R | **Total / 60** |
| --- | --- | --- | --- | --- | --- | --- | --- |
| **1. Identity Directory (Active Directory)** | 10 | 4 | 8 | 6 | 10 | 9 | **47** |
| **2. CAD Server (Patent Blueprints)** | 8 | 3 | 7 | 4 | 9 | 5 | **36** |
| **3. Marketing Website (Public-Facing)** | 2 | 10 | 2 | 8 | 3 | 10 | **35** |
Analyzing the Results:
The Marketing Website scores highly (35/60) because it is highly accessible and recognizable, but its criticality to operations is minimal.
The Active Directory environment achieves the highest score of 47/60. This is mathematically the enterprise’s logical Center of Gravity. While it may not be directly accessible from the internet, its absolute criticality (10), the catastrophic effect of its failure (10), and the difficulty of recovery (8) make it the ultimate target.
3. How to Operationalize CARVER in Corporate Security
Once you have cataloged and scored your assets using this framework, the CARVER doctrine dictates a three-pronged defensive action plan:
Step A: Driving Down Accessibility (A) and Vulnerability (V)
An organization cannot change the Criticality (C) or Effect (E) of a vital asset—a core payroll or transactional system will always be critical. However, you have full control over A and V.
- If your Active Directory has an Accessibility score of 4, the goal is to drive it down to 1 by deploying administrative bastions, Tiering architectures, and isolating management planes away from standard employee networks.
- If its Vulnerability is scored at 6, drive it down to 2 by purging legacy protocols, enforcing strict password policies, and running automated continuous configuration audits.
Step B: Disrupting Recognizability (R) Through Deception
Lower your Recognizability score by banning explicit naming conventions for critical servers and restricting the technical data leaked via public banners or file metadata. Conversely, play an asymmetric game: build highly recognizable, fake assets (Honeypots) to trick attackers into attacking a simulated, monitored dead-end.
Step C: Engineering for Recuperability (R)
For any asset scoring above 40 on the CARVER matrix, a specialized, isolated disaster recovery playbook is mandatory. This requires maintaining immutable, air-gapped backups that are physically or logically severed from the main production network. The ultimate goal is ensuring that even if an attacker successfully strikes your core, your recovery capabilities turn a potential multi-week business outage into a controlled, swift restoration.
Cheers.