In lieu of a full blog post this week, here's some thinking out loud about why a la carte security so often fail, and what to do about it:
1/ A short thread on why this sort of "pick and choose" approach to cybersecurity is troubling using lessons learned from decision science, finance, game theory and strategy.
— Rob Terrin (@RobTerrin) April 17, 2020
2/ Even if every business faced the same threat model (they really don’t), there is no static ranking of controls (https://t.co/tspEK3PApq). Security is a property of a system, not a set of features. It has to be evaluated as a whole.
— Rob Terrin (@RobTerrin) April 17, 2020
3/ To know which controls to choose, we have to know what the budget is, not only in the present, but also the likely budget in the future. But budgets are hard, because they are endogenous.
— Rob Terrin (@RobTerrin) April 17, 2020
4/ “Tell me what my Value at Risk is and I’ll tell you how much we have to spend.” (check out https://t.co/MSP8GaGPxw by @dseverski) Then take this complicated game and play it for multiple rounds into the future.
— Rob Terrin (@RobTerrin) April 17, 2020
5/ Now discount these future costs and benefits using the time value of money. Budgeting is hard, but forecasting a budget is even harder!
— Rob Terrin (@RobTerrin) April 17, 2020
6/ At this point, most reasonable people would throw up their hands, and say, “Hell with it! What are my peers doing?”
— Rob Terrin (@RobTerrin) April 17, 2020
7/ This leads to “best practices” and bundles. “…there’s only two ways I know of to make money: bundling and unbundling…” - Jim Barksdale
— Rob Terrin (@RobTerrin) April 17, 2020
8/ For the last few years, we’ve been inundated with too many a la carte security options. In an environment with too many choices, the bundles gain advantage, aided by consolidation among cloud providers... but eventually the pendulum will swing back: https://t.co/fkGnBPg8O4
— Rob Terrin (@RobTerrin) April 17, 2020
9/ I’ll close with a gift, a lesson & a warning:
— Rob Terrin (@RobTerrin) April 17, 2020
Gift - If you need any free advice, email me at Robert dot Terrin at tailrisk dot com.
Lesson - Optimize for goals of your cybersecurity program, not inputs.
Warning - Don’t make the perfect the enemy of the good.