Security is an Economics Discipline More Than a Technological One

Matt Dinkel · · Read on Medium

This is a blog post I originally wrote in 2013. I eventually ended up abandoning a profession in “security” in part because of the frustrations which can be seen shining through in this post. My general assessment of the state of“security” as a profession has softened somewhat over the years, but I still largely agree with the vision of what this specialization could and should be that I was attempting to capture here. I’m re-posting it now, a decade later almost to the day, with minimal editing.

I spent four years in an undergraduate program which was focused on security. Classes in economics comprised a large part of this curriculum. Many of my peers complained about this at the time, not understanding why a security professional needed to take 400-level economics classes in game theory and insurance market dynamics. Even the name of the program itself — Security and Risk Analysis — was often mocked by students who thought “Risk Analysis” was only there to pad the name just like the economics classes were padding our schedules.

What I eventually realized, however, is that security is all about Economics. Understanding technologies, the vulnerabilities they have, the techniques used to exploit them, or the methods and tools for mitigating these risks is important, but these things are constantly changing. Coming to the professional world, it was the economics skills which were by far the most useful part of my education. What are the incentives to attack your systems? How can we reduce that incentive or create deterrents to counteract it? Is undertaking such an effort worth it to our business? While the tools, technologies and tactics will constantly change, these questions will always be valid.

Obviously, this is not the training that most security professionals receive. While collegiate security-focused programs are on the rise, they are still relatively rare and they were only available relatively recently. Instead, most security professionals came from a more general information technology or computer science background. The problem is that these disciplines are focused on the detailed workings of technology, not incentives, deterrents, and risk postures. This means that the past experiences of many security professionals are likely to lead them to research and master security technologies instead of the more foundational economic concepts.

Unfortunately, security is also not a field that is well suited to on-the-job learning. Compromise is usually a high impact event, so learning from your mistakes is not really an option. Additionally, since compromise is generally a binary event, it is very difficult to gauge your “level” of success. The results-based success paradigms which guide the more general IT and computer science fields simply do not work here. In fact, the high cost of failure actually creates an incentive to over-secure. When security professionals are unable to determine what security posture is economically appropriate, their incentives are not just to over-secure, but to secure as much as possible. This creates the (often unconscious) view that it is the role of a company’s security organization to fight for the most secure environment possible. By taking this stance, security organizations shed the responsibility of deciding what posture is actually appropriate, instead relying on a power struggle between the IT and security organizations to work this out. It is difficult to see how this could be either effective or efficient; however, it is easy to see how this can create the stereotypical adversarial relationship between these two groups.

It seems that many of the most successful security professionals today came from backgrounds in penetration testing. This is probably because pen testing is a great way to build an understanding of technology and its vulnerabilities. Like any discipline, hands-on experience goes a long way (especially when the alternative training is generally little more than a week-long security “bootcamp” class); however, since pen testers choose their targets based on who is willing to pay them, their focus is on how, not if, they would compromise the target environment. This is certainly a valuable skill, but if we believe the common Security axiom that “any system can be compromised”, knowing when someone would choose to do so and what that would mean for your business should be the more valued questions.

This is not meant to undermine the value of technical knowledge, which must certainly be kept up to date, but an understanding of the economic principles is what builds a solid security foundation. It is the foundation because it can be applied regardless of changes in the technology landscape. A skilled security professional who designed medieval castles could apply the same economic security concepts to cyber-brains (when they eventually show up) if he was able to master the technology; however, a security professional who focused entirely on the technology of a cyber-brain firewall would have little ground to stand on if he suddenly found himself designing a castle.