Like all great presentations, it includes a Seinfeld reference :-)
Showing posts with label risk. Show all posts
Showing posts with label risk. Show all posts
Monday, May 4, 2020
S4x20 Video: Lessons Learned from Norsk Hydro on Loss Estimation and Cyber Insurance
I gave a talk at S4X20 in January on the Norsk Hydro ransomware attack. The full video has now been posted on YouTube:
Like all great presentations, it includes a Seinfeld reference :-)
Like all great presentations, it includes a Seinfeld reference :-)
Wednesday, April 1, 2020
Splattered Swan: Collateral Damage, Friendly Fire, and Mis-fired Mega-systems
![]() |
| Like Curly from the "Three Stooges" said, "I'm a victim of circumstances!" |
I call this type "Splattered Swans".
Context: Rethinking "Black Swans"
This post is nineth in the series "Think You Understand Black Swans? Think Again". The "Black Swan event" metaphor is a conceptual mess.Summary: It doesn't make sense to label any set of events as "Black Swans". It's not the events themselves, but instead they are processes that involve generating mechanisms, our evidence about them, and our method of reasoning that make them unexpected and surprising.
Definition
A "Splattered Swan" is a process where:- The generating process involves a very powerful force (i.e. penal, constraining, or damaging force) with less than perfect aim.
- The evidence are official rules, specifications, or scope, or experience that is limited what is intended;
- The method of reasoning are based on the assumption that the aim will be perfect and error-free, or that errors will be "well behaved".
Main Features
A Splattered Swan arises when a very powerful system is prone to misfiring in very bad ways, causing damage to some entities that are considered "safe" or "out of bounds" by normal reasoning. That these outcomes are extreme or surprising are basically due to failures to understand the total system and the ways it can fail.Two key features of Splattered Swans are 1) critical error conditions are excluded from reasoning on principle and 2) those errors are potentially severe, even the first time. A lot of systems adapt by trial and error, but that only works of the magnitude of errors (i.e. aim) is relatively small and the magnitude of collateral damage is also relatively small. Consider airplane bombers from World War II aiming to kill enemy troops that are located near allied troops. Even though they had bomb sights, the bombers were notoriously inaccurate. With ordinary large bombs, the risk of "friendly fire" (i.e. killing your own troops) is high. If the bomber is carrying a single atomic bomb, then the risk of "friendly fire" becomes extremely high, because you only get one chance to aim and drop and there is no feedback from previous attempts. Plus the damage process is extreme. In the other direction, if there are several bombers, and the first bombers drop flairs instead of bombs, then the cost of error is small and the opportunity of corrective feedback has the potential to dramatically reduce the risk of "friendly fire".
Another important feature of Splattered Swans are the blind spots created by the "official" or "intended" definition of the system of interest. This can lead analysts and decision-makers to never even consider the possibility of collateral damage or unintended consequences.
One Example
"Offensive cyber" , a.k.a. "hack back" is an example from the domain of cyber security. There are many flavors of offensive cyber, but the most extreme involve damaging the targets, either physically or digitally or both. Such extreme attacks might also be considered acts of war, a.k.a. "cyber war". Putting aside the ethics or advisability of offensive cyber, there is immense potential for collateral damage. First, it might be hard or impossible to attribute a given attack to the "real" threat agents or groups (a.k.a. "Black Hat"). They might operate through affiliates, mask or disguise their tools and infrastructure, and might even intentionally implicate a different agent or group in the "Indicators of Compromise" and other forensic evidence. Even if you can correctly identify the attacking group, it may be hard to attack them in a way that doesn't also do harm to socially-important entities or resources (e.g. cloud computing resources, networks, etc.). Finally, in corner-case situations there is also a non-zero potential for self-harm, where an offensive cyber attack backfires on the "White Hat" attacker.From a planning and on-going management viewpoint, it is much harder to anticipate and control the side-effects of cyber attacks than it is for physical attacks.
How to Cope with Splattered Swan
It is relatively simple to cope with Splattered Swan systems. Don't take the "official" or "intended" system as a strict definition of what behavior or outcomes are possible. Use Scenario Planning or "What If?" analysis to look outside the "official" or "intended" to identify potential for collateral damage.Then look for ways to introduce error-correcting feedback or damage mitigations for the collateral damage. Another good mitigation is to reduce the intensity of the damage/punishment process.
Swarm-as-Swan: Surprising Emergent Order or Aggregate Action
![]() |
| A flock of swans in swan-shaped formation |
Emergence is a common characteristic of such systems. But that alone doesn't qualify them as a "Swan". It requires several other factors that could, under the right circumstances, yield very surprising or cataclysmic outcomes. I call this the "Swarm-as Swan", since swarming behavior (birds, fish, insects) is one well-known type of emergent phenomena, but this category is explicitly not limited to swarm phenomena.
Context: Rethinking "Black Swans"
This post is eighth in the series "Think You Understand Black Swans? Think Again". The "Black Swan event" metaphor is a conceptual mess.Summary: It doesn't make sense to label any set of events as "Black Swans". It's not the events themselves, but instead they are processes that involve generating mechanisms, our evidence about them, and our method of reasoning that make them unexpected and surprising.
Definition
A "Swarm-as-Swan" is a process where:- The generating process involves a large-scale Complex Adaptive System that has regions in the state space where collective and/or emergent phenomena become dominant, leading to collective behavior that is dramatically different from the behavior in the "normal" regions of state space.
- The evidence are patterns of system behavior and interaction at various scales (individual, group, collective) and especially surprisingly different patterns, including downward causation and varieties of self-organization and information processing;
- The method of reasoning are mental models of the system, whether formal or informal, sophisticated or common sense, and the implications of those models on what behaviors are "normal" and expected vs. what is surprising.
Main Features
The field of Complexity Science has grown and blossomed over the last 30 years. This Wikipedia article gives a good summary, along with the central theme of Complex Adaptive Systems (CAS). From that article, the common characteristics of CAS:- The number of elements is sufficiently large that conventional descriptions (e.g. a system of differential equations) are not only impractical, but cease to assist in understanding the system. Moreover, the elements interact dynamically, and the interactions can be physical or involve the exchange of information
- Such interactions are rich, i.e. any element or sub-system in the system is affected by and affects several other elements or sub-systems
- The interactions are non-linear: small changes in inputs, physical interactions or stimuli can cause large effects or very significant changes in outputs
- Interactions are primarily but not exclusively with immediate neighbors and the nature of the influence is modulated
- Any interaction can feed back onto itself directly or after a number of intervening stages. Such feedback can vary in quality. This is known as recurrency
- The overall behavior of the system of elements is not predicted by the behavior of the individual elements
- Such systems may be open and it may be difficult or impossible to define system boundaries
- Complex systems operate under far from equilibrium conditions. There has to be a constant flow of energy to maintain the organization of the system
- Complex systems have a history. They evolve and their past is co-responsible for their present behavior
- Elements in the system may be ignorant of the behavior of the system as a whole, responding only to the information or physical stimuli available to them locally
- Level 1: Emergent behavior -- behavior of large numbers of individuals becomes interdependent and mutually influencing, far beyond the range of causal and information interaction, including some downward causation where the collective shapes the individuals. Examples: flocks of birds, schools of fish.
- Level 2: Emergent functional structures -- the formation of stable networks of individuals that constitute functional subsystems. "Functional" means they do some work beyond just collective behavior of Level 1. An excellent example is the "glider" phenomena in Conway's Game of Life (a type of cellular automata).
![]() |
| A single Gosper's glider gun creating "gliders" |
- Level 3: Emergence against a model -- similar to Level 2, but the "stable functional subsystems" have information processing and self-sustaining capabilities (including possibly metabolizing energy and repairing/regenerating structures). In a real sense, Level 3 systems "take on a life of their own", at least for an extended period. Example: emergent subsystems that function as regulators (e.g. thermostat), communication systems (e.g. encoding, decoding, transmission), pattern matching, optimization, etc. The human immune system has some of these capabilities.
Like all of the "...Swans", it's just as important to understand the evidence that we use to understand these systems (i.e. CAS), and also our methods of reasoning. It's the combination of all three that give rise to the surprising/shocking/extreme behavior that we associate with "...Swans".
The most common evidence people pay attention two is either individual-based behaviors and interactions and the most common collective behavior patterns and distributions. If the states of the CAS are in "low complexity" regions of the state space (i.e. not in one of the three Levels, above), then people may not even recognize that the CAS is capable of complex emergent phenomena. The reverse is also true. If the CAS is normally in a highly coherent, highly functional state then people may not observe or understand the micro-level behavior that supports that phenomena. The evidence we need most is the location of "phase transitions" in state space, where the CAS shifts dramatically from one regime to another. Unfortunately for us mortal humans, it's almost impossible to know in advance where the important phase transitions are in CAS, especially the Level 2 and 3 CAS.
Our methods of reasoning about CAS fall into three categories: 1) Intuitive (i.e patterns of "normal" behavior with small deviations, naïve causal models, "folk wisdom", etc.); 2) Linear Models (i.e. the standard tools of science up to ~1990); 3) Non-linear Models, including Agent-based Modeling.
Methods 1) and 2) are most common, and work well in "normal" circumstances, but are very prone to catastrophic failures of reasoning when the CAS enters a new, unfamiliar regime of emergent behavior. Method 3) is specifically designed to understand CAS in all their complexity, but they aren't a "magic bullet" that completely eliminate the potentials for surprise or extreme outcomes.
One huge difference between Method 2) "Linear Models" and Method 3) "Non-linear Models" is that the that Method 3) usually does not yield a forecast or prediction of system behavior in the same way that Method 2) does. Instead it can help us understand when and why the CAS will change regimes, which is still very useful information to understand potential surprises.
Examples
In the previous section I mentioned some illustrative examples. But here I'll mention two "biggies".The modern economy has been characterized and studied as a Complex Adaptive System (CAS), especially to understand innovation and crises, especially societal/economic collapse. Some of the first books published by the Santa Fe Institute in the late `80s were titled "The Economy as a Complex Adaptive System".
Mass uprisings and mass revolutions are other classes of phenomena that benefit from study as CAS. I won't go into detail here, but if you are curious, you might read up on these cases:
How to Cope with Swarm-as-Swan
The first step is to recognize that the system you are dealing with has the characteristics of a Complex Adaptive System. Start with the Wikipedia page, then read some of the general references listed at the bottom. This will give you the basic knowledge plus some exposure to many types of CAS.The second step is to characterize the types of emergent behavior and structures that are within the "possibility space" of the CAS. But stay away from "magical thinking" and "conspiracy theories".
The third step is to apply modeling tools that are appropriate to the complexity of the CAS. Linear models are fine for what they do, but don't try to use them to identify "phase transitions" from simple to complex behavior, etc.
If you aren't mathematically inclined or are not comfortable programming your own Agent-based Models (ABM), you can at least read books and papers that utilize these models and learn from the pros who built them and analyzed them. Even better, you can play with them yourself using the Model Library that comes with NetLogo (free and open source). Each model is controlled by sliders and buttons, and comes with documentation that guides you how to use it, how to interpret it, and how to explore it.
Monday, November 25, 2019
Talk Like a Cyber Insurance Risk Analyst
In a recent class on catastrophe risk modeling, I learned the definition of terms that are common in insurance but not so well understood elsewhere:
- Peril
- Exposure
- Hazard
- Ground-up Loss
- Risk
Sunday, March 31, 2019
A 12 Year Quest -- My Story
![]() |
| On a quest, through the desert. (credit: Assassin's Creed – Origins; Thick Skin Side Quest – Crocodile, Hyena, Vulture Locations) |
I don't normally post personal stories on this blog (or elsewhere) but today feels like the right time for this particular personal story. I'm writing this as a way of connecting to my community, many of whom have shared the ups and downs of this journey. I don't have any big lessons or advice. Even so, some readers may find this story instructive or inspirational, even indirectly. I hope so.
Caveats: In this post, I don't individually acknowledge and thank all the people who have helped me along the way. There are so many, so I will do that separately, both in one-on-one communications and later blog posts. I'm also going to discipline myself not to write about all the details, all the events, all the feelings along the way. That would be too long. I aim is to have a post that is readable and still specific enough to be meaningful.
Even so, it's a long blog post. If this suits you, the story continues below.
Tuesday, December 18, 2018
Does Modern Portfolio Theory (MPT) apply to cyber security risks?
Many months ago, my colleague David Severski asked on Twitter how Modern Portfolio Theory (MPT) does or does not apply to quantified cyber security risk:
I replied that I would blog on this "...soon". Ha! Almost four months later. Well, better late than never.
Short answer: No, MPT doesn't apply. Read on for explanations.
NOTE: "Cyber security risk" in this article is quantified risk -- probabilistic costs of loss events or probabilistic total costs of cyber security. Not talking about color-coded risk, categorical risk, or ordinal scores for risk. I don't ever talk about them, if I can help it.
I replied that I would blog on this "...soon". Ha! Almost four months later. Well, better late than never.
Short answer: No, MPT doesn't apply. Read on for explanations.
NOTE: "Cyber security risk" in this article is quantified risk -- probabilistic costs of loss events or probabilistic total costs of cyber security. Not talking about color-coded risk, categorical risk, or ordinal scores for risk. I don't ever talk about them, if I can help it.
Wednesday, March 7, 2018
The Swan of No-Swan: Ambiguous Signals Tied To Cataclysmic Consequences
![]() |
| What do you see? colored blocks, or a Black Swan, or both? This is figure-ground reversal, a type of ambiguity. |
Surprisingly, historians are still struggling to understand what caused the war.
One of the biggest causal factors was ambiguous signals that precipitated cascading actions and reactions. When tied to cataclysmic consequences, this represents a distinct class of "Black Swan" systems.
(Here are some great lectures for those interested in a full analysis of causes of the Great War: Margret MacMillan, Michael Neiburg, Sean McMeekin)
Rethinking "Black Swans"
As I have mentioned at the start of this series, the "Black Swan event" metaphor is a conceptual mess. (This post is seventh in the series "Think You Understand Black Swans? Think Again".)It doesn't make sense to label any set of events as "Black Swans". It's not the events themselves, but instead they are processes that involve generating mechanisms, our evidence about them, and our method of reasoning that make them unexpected and surprising.
Definition
A "Swan of No-Swan" is a process where:- The generating process is some set of large opposing forces that can be triggered by a set of signals or decisions tied to ambiguous signals;
- The evidence are signals -- communications, interpreted actions, interpreted inaction, rhetoric/discourse, irreversible commitments -- that have ambiguous interpretations, either intentionally or unintentionally;
- The method of reasoning either rational expectations (normative Decision Science) or biased expectations (Behavioral Psychology and Economics). The key feature is lack of attention or awareness that one might be mis-perceiving the signals, combined with a strategic preference for precautionary aggressiveness.
Main Features
First, let us recognize that ambiguity is pervasive in social, business, and political life. Ambiguous signals and communication have many pro-social functions: keeping our options open, saving face, avoiding insult or offense, optimistic interpretation of events, and so on. They are especially prevalent in the lead-up to major commitments -- romance+marriage in personal life and big ticket sales in commercial life.
Most of the time, ambiguity has a smoothing effect. It reduces the probability of extreme/rare events because of the flexibility of action and response associated with ambiguous signals. Therefore, most people would not associate ambiguous signals with any type of "Black Swan" phenomena.
But when tied to "large opposing forces", things change and that's why this deserves to be a separate type of Black Swan. Ambiguous signals become dangerous when they are linked to cataclysmic processes via certain types of reasoning processes. It's not rational vs. biased. Instead, it's committed self-confidence vs. self-aware fallibility. In committed self-confidence, there is lack of attention or awareness that one might be mis-perceiving the signals, combined with a strategic preference for precautionary aggressiveness. "Shoot first, ask questions later".
Examples
Military forces leading to total war are the obvious case, and most common in history. But we are now in a new age -- the Cyber Age! (Yes. I said it. Cyber) Here are some cyber examples.- Offensive cyber capabilities -- By "offensive" I mean everything from "hack back" to punitive or disabling cyber attacks on critical infrastructure. If it becomes common for nation states and various non-nation actors to develop and deploy offensive capabilities, they everyone faces the strategic dilemma as to when and how much to deploy/trigger each capability. This depends critically on the ability of each actor to detect and accurately interpret a wide variety of signals and evidence related to normal and abnormal activity, including breach events, threat actor attribution, signs of escalation, and so on. These are all swimming in ambiguity, including intentional ambiguity (spoofing, camouflage, etc.)
- Remote kill switches -- What if Internet of Things (IOT) makers build "remote kill switches" in their devices? After all, we'd like to prevent our toaster, pacemaker, automobile, or drone from doing harm in the case when it starts malfunctioning catastrophically. Are there scenarios where one or more IOT manufacturers decide to remotely kill at the same time? What if their monitoring instruments make it appear that some threat actor(s) are making self-driving cars intentionally crash into crowds of people? Out of an abundance of caution, they might remotely kill the IOT devices to cut off the apparent disaster as it is unfolding. But maybe the threat actor is only spoofing the signals because they pwned the monitoring devices and infrastructure. Or maybe it's the precautionary action of some other IOT device system owner that is causing your monitoring system to go bonkers. I could go on but you get the idea.
How to Cope with Swan of No-Swan
It would be good to decouple the generating process if possible. Avoid the arms race to begin with. (Give peace a chance!)
Absent that, the best antidote is to treat evidence and signals pluralistically, which means avoiding the tendency to commit to one interpretation or another too early. This is very hard to do within one person or even one cohesive team. It's easier to assign different "lenses" to different people or teams who then proceed with their analysis and decision recommendations independently.
Finally, the decision makers who can "pull the trigger" should seek strategy alternatives to the preference for precautionary aggressiveness ("Shoot first, ask questions later"). While decision makers may feel like this is their only choice (and it may be), there is great advantage if more flexible alternatives can be found.
Wednesday, October 19, 2016
Orange TRUMPeter Swans: When What You Know Ain't So
Was Donald J. Trump's political rise in 2015-2016 a "black swan" event? "Yes" is the answer asserted by Jack Shafer this Politico article. "No" is the answer from other writers, including David Atkins in this article on the Washington Monthly Political Animal Blog.
My answer is "Yes", but not in the same way that other events are Black Swans. Orange Swans like the Trump phenomenon is fits this aphorism:
It doesn't make sense to label any set of events as "Black Swans". It's not the events themselves, but instead they are processes that involve generating mechanisms, our evidence about them, and our method of reasoning that make them unexpected and surprising.
![]() |
| Orange Swan |
"It ain't what you don't know that gets you into trouble. It's what you know for sure that just ain't so." -- attributed to Mark TwainIn other words, the signature characteristic of Orange Swans is delusion.
Rethinking "Black Swans"
As I have mentioned at the start of this series, the "Black Swan event" metaphor is a conceptual mess. (This post is sixth in the series "Think You Understand Black Swans? Think Again".)It doesn't make sense to label any set of events as "Black Swans". It's not the events themselves, but instead they are processes that involve generating mechanisms, our evidence about them, and our method of reasoning that make them unexpected and surprising.
Saturday, March 8, 2014
Mining only 'digital exhaust', Big Data 1.0 won't revolutionize information security
I was asked during this interview whether 'Big Data' was revolutionizing information security. My answer was, essentially, 'No, not yet'. But I don't think I did such a great job explaining why and where the revolution will come from, if it comes.
Basically, Big Data 1.0 in information security is today focused on mining 'digital exhaust' -- all the transactional data emitted and logged by computing, communications, and security devices and services. (The term "data exhaust" was probably coined in 2007 by consultant Jerry Michalski, according to this Economist article.) This can certainly be useful for many purposes but I don't think it is or will be revolutionary. It will help tune spam filters, phishing filters, intrusion detection/prevention systems, and so on, but it won't change anything fundamental about how firms architect security, how they design and implement policies, and it does almost nothing on the social or economic factors.
Here's a great essay that explains why Big Data 1.0 isn't revolutionary, and what it will take to make it revolutionary. Though it's not about information security, it doesn't take much to extend his analysis to the InfoSec domain.
Highlighting somewhat different themes in the context of Digital Humanities, Brian Croxall presents an insightful blog post called "Red Herrings of Big Data", which includes slides and this 2 minute video:
Here are his three 'red herrings' (i.e. distractions from the most promising trail), turned around to be heuristics:
Basically, Big Data 1.0 in information security is today focused on mining 'digital exhaust' -- all the transactional data emitted and logged by computing, communications, and security devices and services. (The term "data exhaust" was probably coined in 2007 by consultant Jerry Michalski, according to this Economist article.) This can certainly be useful for many purposes but I don't think it is or will be revolutionary. It will help tune spam filters, phishing filters, intrusion detection/prevention systems, and so on, but it won't change anything fundamental about how firms architect security, how they design and implement policies, and it does almost nothing on the social or economic factors.
Here's a great essay that explains why Big Data 1.0 isn't revolutionary, and what it will take to make it revolutionary. Though it's not about information security, it doesn't take much to extend his analysis to the InfoSec domain.
Huberty, M. (2014). I expected a Model T, but instead I got a loom: Awaiting the second big data revolution. Prepared for the BRIE-ETLA Conference, September 6-7, 2013, Claremont California.Huberty points toward Big Data 2.0 which could be revolutionary:
"...we envision the possibility of a [Big Data 2.0]. Today, we can see glimmers of that possibility in IBM’s Watson, Google’s self-driving car, Nest’s adaptive thermostats, and other technologies deeply embedded in, and reliant on, data generated from and around real-world phenomena. None rely on “digital exhaust”. They do not create value by parsing customer data or optimizing ad click-through rates (though presumably they could). They are not the product of a relatively few, straightforward (if ultimately quite useful) insights. Instead, IBM, Google, and Nest have dedicated substantial resources to studying natural language processing, large-scale machine learning, knowledge extraction, and other problems. The resulting products represent an industrial synthesis of a series of complex innovations, linking machine intelligence, real-time sensing, and industrial design. These products are thus much closer to what big data’s proponents have promised–but their methods are a world away from the easy hype about mass-manufactured insights from the free raw material of digital exhaust.
[...]
The big gains from big data will require a transformation of organizational, technological, and economic operations on par with that of the second industrial revolution. " [emphasis added]
Highlighting somewhat different themes in the context of Digital Humanities, Brian Croxall presents an insightful blog post called "Red Herrings of Big Data", which includes slides and this 2 minute video:
Here are his three 'red herrings' (i.e. distractions from the most promising trail), turned around to be heuristics:
Main message
Don't be naïve about Big Data in information security. To drive a revolution, it will need to be part of a much more comprehensive transformation of what data we gather in the first place and how data analysis and inference can drive results. Just mining huge volumes of 'digital exhaust' won't do it.Friday, February 14, 2014
What analysis do we really need to guide vulnerability management?
This is the first of a series of posts on the topic of doing quantitative risk analysis in the face of intelligent and adaptive adversaries. Later posts will dig into research topics like combining risk analysis with game theory, but this first post is mostly a reaction to what other people have said recently.
Rafał Łoś recently posted an article, and then followed with a guest post from Heath Nieddu, with this general theme (paraphrasing and condensing):
I'm also appearing on Rafał's podcast, Down the Rabbit Hole, along with some other SIRA members. I'll let you know when it is posted for listening.
Rafał Łoś recently posted an article, and then followed with a guest post from Heath Nieddu, with this general theme (paraphrasing and condensing):
It's senseless and distracting to attempt to use quantitative risk analysis to make decisions about vulnerability remediation, and even for information security as a whole. Uncertainties about the future are too great; adversaries too agile and intelligent; and the whole quant risk endeavor is too complicated. Keep it simple and stick with what you know for sure, especially the basics.In this post I'm going to address some of the issues and questions this skeptical view raises, but I won't attempt a point-by-point counter argument. For the record, there are many points I disagree with, plus many ideas that I think are confused or just mis-stated. But I think the discussion will be best served by keeping focused on the main issues.
I'm also appearing on Rafał's podcast, Down the Rabbit Hole, along with some other SIRA members. I'll let you know when it is posted for listening.
Tuesday, January 28, 2014
Estimating your organization's risk appetite, starting from scratch
On Twitter recently, Phillip Beyer (@pjbeyer) asked: "how do you measure risk appetite in program early stages?". I gave my answers in a series of tweets, but this question comes up a lot so I think it's worthy of a blog post.
[Edit: Feel free to substitute the term "risk tolerance" for "risk appetite". They have slightly different origins, but their interpretation in this context is the same.]
First, some people have an aversion to the concept of "risk appetite" and others deny that it even applies to information security (or more broadly to cyber security). The argument goes that no rational manager or organization desires to take on information security risk if they could avoid it, and therefore there is no such thing as an appetite for risk. A different argument against it is based on belief that risk in information security is not quantifiable, and therefore attempts to quantify risk appetite are similarly impossible or meaningless.
I believe these two positions are mistaken. The first objection is a misunderstanding of what "risk appetite" really means and how it applies to information security. I'll explain and clarify, hopefully, Also in this post, I'll also address the second objection to show how risk appetite can be reliably quantified.
[Edit: Feel free to substitute the term "risk tolerance" for "risk appetite". They have slightly different origins, but their interpretation in this context is the same.]
First, some people have an aversion to the concept of "risk appetite" and others deny that it even applies to information security (or more broadly to cyber security). The argument goes that no rational manager or organization desires to take on information security risk if they could avoid it, and therefore there is no such thing as an appetite for risk. A different argument against it is based on belief that risk in information security is not quantifiable, and therefore attempts to quantify risk appetite are similarly impossible or meaningless.
I believe these two positions are mistaken. The first objection is a misunderstanding of what "risk appetite" really means and how it applies to information security. I'll explain and clarify, hopefully, Also in this post, I'll also address the second objection to show how risk appetite can be reliably quantified.
"How Complex Systems Fail" Richard Cook, 30min video
This is a wonderful 30 minute lecture that should be interesting to anyone in information security, risk management, operations, and especially CIOs and CISOs. He gives very good explanations about why agility and learning are so important to resilience.
Friday, November 22, 2013
"Prediction" vs "Forecast"
![]() |
| The "Bonds Shift" was based on a forecast. In contrast, the decision to intentionally walk him so often (120 times in 2004) was based on a prediction that the shift wouldn't work well enough. |
Most recently, this topic was debated by the hosts of the Risk Science Podcast Ep. 9, (31:10 to 55:00).
Summarizing the debate: two hosts say there’s no meaningful difference between “prediction” and “forecast” because they are both probabilistic statements about the future -- plus real people don’t care. In contrast, two hosts disagree, saying there is a meaningful difference and real-world people do care.
I side with the people who say there is a meaningful difference, but I’m not sure the essence of the difference came out in the podcast conversation. I do think that Jay’s statement at 31:10 is the best jumping off point.
The main difference between "prediction" and "forecast", in my opinion, has to do with what actions you take based on the information and what uncertainty is communicated.
Monday, October 21, 2013
preso: Big 'R' Risk Management - from concept to pilot implementation
Here's the presentation (pdf) that I'm giving Monday at SIRAcon in Seattle. This extends the ideas presented in the post "Risk Management: Out with the Old, In with the New!". This presentation presents some specifics on how to get started implementing the Big 'R' approach. It's even got a illustrative case toward the end featuring patch management and exceptions, shown in this figure (click to enlarge)
![]() |
| Example of Causal Dynamic Analysis, in this case Patch Management & Exceptions (click to enlarge) |
Wednesday, October 2, 2013
Out-of-the-Blue Swans: Megatsunami, Supervolcanos, The Black Death, and Other Cataclysms
![]() |
| The Out-of-the-Blue Swan is out there waiting to ruin our day, month, year, decade, or century. |
Sunday, September 8, 2013
Mr Langner is wrong. Risk management isn't 'bound to fail'. But it does need improvement and innovation.
In "Bound to Fail: Why Cyber Security Risk Cannot Simply Be 'Managed' Away" (Feb 2013) and a recent white paper, Ralph Langer argues that risk management is a fundamentally flawed approach to cyber security, especially for critical infrastructure.
Langner's views have persuaded some people and received attention in the media. He gained some fame in the course of the investigation of the Stuxnet worm capabilities to exploit Siemens PLCs (programmable logic controllers). Specifically, Ralph was the first to assert that Stuxnet worm is a precision weapon aimed at sabotaging Iran's nuclear program. Langner also gains institutional credibility as a Nonresident Fellow at the Brookings Institute, who published the "Bound to Fail..." paper. I'm guessing that Brookings PR department has been helping to get press attention for Langner's blog post critiquing NIST CSF and his proposed alternative: RIPE. They were reported in seven on-line publications last week alone: here, here, here, here, here, here, and here. (Note to self: get a publicist.)
In this long post, I'm going to critique Mr. Langner's critique of risk management, pointing to a few places where I agree with him, but I will present counter-arguments to his arguments that risk management is fundamentally flawed.
In the next post, I'll critique Mr. Langner's proposed alternative for an industrial control system security framework, which he dubs "Robust ICS Planning and Evaluation" (RIPE).
Langner's views have persuaded some people and received attention in the media. He gained some fame in the course of the investigation of the Stuxnet worm capabilities to exploit Siemens PLCs (programmable logic controllers). Specifically, Ralph was the first to assert that Stuxnet worm is a precision weapon aimed at sabotaging Iran's nuclear program. Langner also gains institutional credibility as a Nonresident Fellow at the Brookings Institute, who published the "Bound to Fail..." paper. I'm guessing that Brookings PR department has been helping to get press attention for Langner's blog post critiquing NIST CSF and his proposed alternative: RIPE. They were reported in seven on-line publications last week alone: here, here, here, here, here, here, and here. (Note to self: get a publicist.)
In this long post, I'm going to critique Mr. Langner's critique of risk management, pointing to a few places where I agree with him, but I will present counter-arguments to his arguments that risk management is fundamentally flawed.
- TL;DR version: There's plenty of innovation potential in the modern approach to risk management that Langner hasn't considered or doesn't know about. Therefore, "bound to fail" is false. Instead, things are just now getting interesting. Invest more, not less.
In the next post, I'll critique Mr. Langner's proposed alternative for an industrial control system security framework, which he dubs "Robust ICS Planning and Evaluation" (RIPE).
Tuesday, August 27, 2013
Red Swans: Extreme Adversaries, Evolutionary Arms Races, and the Red Queen
![]() |
| The Red Swan of evolutionary arms races, where the basis for competition is the innovation process itself. As the Red Queen says: "...it takes all the running you can do, to keep in the same place." |
In addition to the usual definition and explanations, I've added a postscript at the end: "Why Red Swans Are Different From Ordinary Competition and Adversarial Rivalry".
Monday, August 26, 2013
Risk Management: Out with the Old, In with the New!
![]() |
| While the House of Cards metaphor is crude, it gets across the idea of interdependence between risk factors, in contrast to the "risk bricks" of the old methods. |
Here's my main message:
- Existing methods that treat risk as if it were a pile of autonomous "risk bricks" is the wrong direction for risk management. ("Little 'r' risk")
- A better method is to measure and estimate risk as an interdependent system of factors, roughly analogous to a House of Cards. ("Big 'R" Risk")
I call the first "Little 'r' risk" because it attempts to analyze risk at the most granular micro level. I call the second "Big 'R' Risk" because the focus is on risk estimation at an organization level (e.g. business unit), and then to estimate the causal factors that have the most influence on that aggregate risk. With some over-simplification, we can say that Little 'r' risk is bottom-up while Big 'R' Risk is top-down. (In practice, Big 'R' Risk is more "middle-out".)
This new method isn't my idea alone. It comes from many smart folks who have been working on Operational Risk for many years, mainly in Financial Services. For a more complete description of the new approach, I strongly recommend the following tutorial document by the Society of Actuaries: A New Approach for Managing Operational Risk.
For readability and to keep an already-long post from being even longer, I'm going to talk in broad generalities and skip over many details. Also, I'm not going to explain and evaluate each of the existing methods. Finally, I'm not going to argue point-by-point all the folks who assert that probabilistic risk analysis is futile, worthless, or even harmful.
Friday, August 9, 2013
Green Swans: Virtuous Circles, Snowballs, Bandwagons, and the Rich Get Richer
![]() |
| The Green Swan of cumulative prosperity. The future's so bright she's gotta wear shades. |
Taleb includes the Internet and the Personal Computer among his prime examples of Black Swan events. In this post I hope to convince you that these phenomena are quite different than his other examples (e.g. what I've labeled "Grey Swans") and that there is value in understanding them separately.
Thursday, August 1, 2013
Grey Swans: Cascades in Large Networks and Highly Optimized/Critically Balanced Systems
![]() |
| A Grey Swan -- almost Black, but not quite. More narrowly defined. |
I'll define and describe each one, and maybe give some examples. Most important, each of these Shades will be defined by a mostly-unique set of 1) generating process(es); 2) evidence and beliefs; and 3) methods of reasoning and understanding. As described in the introductory post, it's only in the interaction of these three that Black Swan phenomena arise. Each post will close with section called "How To Cope..." that, hopefully, will make it clear why this Many Shades approach is better than the all-lumped together Black Swan category.
This first one is named "Grey" because it's closest to Taleb's original concept before it got hopelessly expanded and confused.
Subscribe to:
Posts (Atom)
















