A new economics of cybersecurity
Cyber-risk rests on two false axioms
A prudent man sees evil and hides himself, the naive proceed and pay the penalty.
The last forty years have demonstrated the intellectual bankruptcy of prevailing cybersecurity theory. Present methods for constructing cybersecurity strategy use the economics of insurance. Practitioners assign a value to each digital asset under management. Leveraging experience, they estimate the probability of loss for each asset. Finally, these numbers are multiplied per asset and sorted. This approach is simple and quantitative. Unfortunately, it fails miserably in practice.
The cyber-risk economic model of cybersecurity rests on two false axioms: first, digital assets have a discoverable price; second, the probability an asset will be compromised can be learned from past experience. This essay proposes a rejection of these axioms in favor of a superior methodology derived from the theories of poker, surprise (Information Theory), and falsifiability (Philosophy of Science). With sounder intellectual foundations, Christian leaders can protect their personnel and organizations efficiently and effectively without arcane knowledge and experts.
A thought experiment
Consider the following thought experiment: An AI company has developed an extremely powerful model that will grant a monopoly in its market. It has developed this model at a cost of one hundred million dollars. The company follows cybersecurity best practices. A practitioner arrives to approximate the cyber-risk for this company in order to implement a strategy to protect its competitive advantage.
How might the practitioner value the AI model, training data, and methods? Most practitioners would apply an intrinsic value, like one hundred million dollars, akin to Ricardo’s Labor Theory of Value. More sophisticated practitioners might look at the market capitalization of the company, reflecting something akin to Menger’s Subjective Theory of Value. However, do either of these theories make sense for digital assets? How might one discover the true price of something when it is secret and information is hidden? Moreover, if economics is ultimately the study of choice under scarcity, how might one value something that can be copied and pasted billions of times a second?
If a troy ounce of gold is stolen, it cannot be copied ad infinitum amongst thieves. Furthermore, the Law of One Price, that a troy ounce of gold is worth the same to the thief and the merchant, is untrue in the case of data stolen by two threat actors. Disclosure of the AI model to a hacktivist who reveals it renders it worthless in one blow. Disclosure of the model to a competitor who commercializes it has immense value over time.
The first false axiom
The first false axiom of the cyber-risk economic model of cybersecurity is that digital asset compromise has a discoverable price.
Returning to our thought experiment: consider this company’s cybersecurity hygiene and the countermeasures with which it protects its competitive advantage. Assume all users have been adequately trained, software is up-to-date, hardware is new, and the best experts have been brought in to secure the crown jewels. How likely is it the company will suffer a catastrophic breach? Intuitively, it cannot be zero. The existence of unknown unknowns, like secret vulnerabilities (“Zero Day Vulnerabilities”), new discoveries in cryptography, supply-chain issues, or the vicissitudes of human beings (e.g., a disgruntled employee accrues debts), demonstrate a kind of Law of Diminishing Marginal Returns, where the probability asymptotically approaches an optimal beyond which it cannot be reduced.
Is that point closer to zero or one hundred percent? Empirically, from the high-profile leaks seen over the years, from the world’s most secure and sophisticated institutions, it would seem that the optimum point probability is much higher than cybersecurity CEOs would admit on a quarterly earnings call.
Suspending this painful reality for a moment, how might they quantitatively determine the probability this asset will be taken within the next eighteen months (i.e., Moore’s Law eliminates the company’s competitive advantage)? This AI model is something new, a common occurrence in the technology sector. No comparable company has been hacked or equivalent asset stolen to anchor our prior belief. Should they synthesize a probability using widely known statistics like “the number of technology companies hacked in the previous year?” If a company with similar countermeasures to the AI company gets hacked, should they use that fact to update their prior belief? If that similar company has a different product in a different market with different threats, how much should they update their prior belief? Quickly, the mathematical rigor becomes subjective, replaced by the reading of augurs.
The second false axiom
The second false axiom of the cyber-risk economic model of cybersecurity is that digital assets have a discoverable probability of compromise.
With digital assets having neither a discoverable price nor probability of compromise, estimating cyber-risk functions is no better than guessing, a result demonstrated by the horrendous return on investment generated by the cybersecurity industry. Cybersecurity has become another manifestation of the adage, “He who lives by the crystal ball soon learns to eat ground glass.”
Cybersecurity as poker
Suppose cybersecurity were redefined away from calculations of risk and instead expressed as an economic game using the language of poker (a game of decision-making with imperfect information). Take the following new fundamental definition of cybersecurity: A game where defenders labor to guarantee they would have made the same decisions in hindsight, regardless of whether or not an adversary is successful in the future. Conversely, it is the game where defenders force adversaries to make incorrect decisions, those they would not have made with perfect information about the victim. This is analogous to making the same bets in poker that would have been made with perfect information about the opponents’ hands.
Since cybersecurity is zero-sum, incorporates secrecy, and uses deception, poker is a much better analogy than insurance. Arguably, the poker model of cybersecurity is more economic, realistic, and deductive, despite being far less quantitative. This new definition for cybersecurity reasoning eschews a false veneer of mathematical rigor in favor of honest plausible reasoning about resiliency, strategy, and hiding decision-making information.
Using this new definition, how might the AI company play a game that, regardless of whether or not the model is stolen, they make the same decisions in the present because an incident is immaterial? How might the company force adversaries to expose their identities and spend extreme amounts of compute or financial resources? How might the company diminish the usefulness of the asset when stolen? These sets of strategic questions net far more than questions regarding price points to purchase security appliances and antivirus.
However, jettisoning quantitative measures in favor of an approach that is more qualitative leaves something to be desired. A world where two competing strategies cannot be compared against one another hardly seems better. Thankfully, surprise from Information Theory provides qualitative tools to sort strategies from best to worst.
Surprise
In 1948, American scientist Claude Shannon wrote A Mathematical Theory of Communication, one of the most important papers of the twentieth century. He explored how to quantify information and presented a simple mathematical formalism that evolved communications, cryptography, processors, and more. At a high level, useful information captures some notion of surprise. Intuitively, telling someone something he or she already knows seems useless. The correct contrarian, the piece of information that significantly drives belief toward reality, is valuable.
Implicit in the discussion of the AI company is the notion that the model is surprising. If it were the same as the status quo or replicable, it would not be valuable. Consider the Russian invasion plans of Ukraine: A strategy that might have left the intelligence community surprised would strictly have been better than one where the invasion was obvious. Even though Russia lied about its intentions before the invasion, it is hard to imagine Ukraine taking different actions had Russia declared war beforehand.
Similarly, practitioners ought to qualitatively maximize an adversary’s surprise when observing a defender’s actions and minimize their surprise from an asset compromise. Surprise provides an intelligible qualitative metric for scoring assets in counterfactuals. While not quantitative, it creates a more accurate view of reality, as it lends itself more easily to plausible reasoning than guessing about financial losses. Additionally, should quantitative reasoning be necessary to make a convincing case, practitioners can ask simpler and more accurate questions. For example, “How much does X strategy force the adversary to spend to adapt versus Y?”
Nonetheless, while surprise provides insight into future strategy, the question of how to integrate past information has not been solved. Here, falsifiability from the Philosophy of Science provides a helpful framework for discovering efficacy of strategy over time.
Falsifiability
In 1934, Karl Popper in The Logic of Scientific Discovery presented the concept that a theory is falsifiable if it can be proven false. For example, take the theory that “resurrecting oneself from the dead is not possible.” Almost all empirical evidence seems to indicate that people do not resurrect after dying. Yet one example of someone resurrecting themself from the dead has proven this statement false. Another example, “there are multiple universes,” is not falsifiable because only this universe can be observed.
Since whether or not the AI company gets hacked is ultimately probabilistic, the distinction between luck and good security hygiene might be difficult to prove. A common joke in cybersecurity is a Chief Information Security Officer (CISO) first blames his or her budget after the first intrusion, blames the staff after the second, and prepares a resignation letter after the third. With poorly constructed hypotheses and experiments that require a hack to update prior belief, no wonder the average CISO blames others to buy time to work out kinks.
Practitioners must use falsifiable theories about adversaries and mitigations that help disambiguate between luck and useful effort without requiring an incident to update prior belief. Consider the hypothesis “education reduces success of phishing tests sent from auditors thirty percent.” It is not equivalent to “resistance to real phishing email attempts improved thirty percent.” Yet it is a defensible heuristic that can be falsified against objective metrics. For the AI company, the hypothesis “current policies and monitoring prevent models from being copied offsite” is either true or false. If proven false, the reason can be investigated, the system improved, and a new hypothesis tested.
Even though the probability an asset can be stolen is undiscoverable, the success and failure of these sorts of falsifiable experiments generate a set of data points that draw a trendline toward good or poor security hygiene. As Yogi Berra eloquently said, “You can observe a lot just by watching.” When companies form a habit to construct cybersecurity experiments in a falsifiable fashion without requiring intrusions, they begin to develop a deep understanding of the risks and advantages of their specific operational processes. They no longer require cybersecurity practitioners to design plans based on what others are doing since the leader’s intuition and data reflect reality.
What the model asks of leaders
The poker model of cybersecurity makes fewer truth claims than the quantitative cyber-risk model. Nonetheless, the claims it makes, when done well, are deductive and trustworthy. Furthermore, what it does not know for certain is explicit and open to plausible reasoning. When dealing with creative adversaries and ever-evolving technology, humility regarding the boundaries of what can be known and wargamed is essential. While practitioners are experts in technology, they are not experts in a particular business’ operations and battlespace.
Christian leaders can use the poker model of cybersecurity to defend themselves, applying their own insights and wisdom regarding their institutions. John 16:33 (NASB95) quotes Jesus, saying, “In the world you will have tribulation, but take courage; I have overcome the world.” With a more effective and efficient machine for iterating on cybersecurity strategy, believers can courageously and wisely operate in a digital world with ubiquitous and increasing tribulation.