{"id":7215,"date":"2025-02-05T14:17:16","date_gmt":"2025-02-05T20:17:16","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/why-cybersecurity-needs-probability-not-predictions"},"modified":"2025-02-05T14:17:16","modified_gmt":"2025-02-05T20:17:16","slug":"why-cybersecurity-needs-probability-not-predictions","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2025\/02\/05\/why-cybersecurity-needs-probability-not-predictions\/","title":{"rendered":"Why Cybersecurity Needs Probability \u2014 Not Predictions"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltd88da2ad28bce58a\/67a3a37b3ad81b7f7bf56472\/Probability_%281800%29_Agata_G%C5%82adykowska_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/why-cybersecurity-needs-probability-not-predictions.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/why-cybersecurity-needs-probability-not-predictions.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Many cybersecurity leaders kick off each new year with predictions for the year to come. You may have seen a deluge of them over the last month or so: &#8220;Cyberattacks will continue to be a problem.&#8221; &#8220;This certain country will ban ransom payments.&#8221;&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">But as a cybersecurity company founder and CEO, as well as a licensed insurance broker, I believe that, instead of predictions, what we really need to protect ourselves is a better understanding of <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">probability<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Why? Predictions do not inspire solutions. Probabilities do.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">To understand why probability is so important in cybersecurity \u2014 and why it makes non-data-driven predictions highly impractical \u2014 let&#8217;s look at what probability actually is.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Understanding the Nuances of Probability\">Understanding the Nuances of Probability<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Traditional understandings of probability tend to be misguided. Many treat it as simply the frequency of events over many trials (think: flipping a coin). This requires extremely large datasets, and those datasets must be stable and consistent. Fighting threat actors, though, is famously neither a stable nor a consistent endeavor. Cybersecurity is thus inherently dynamic and uncertain; we require a more nuanced paradigm.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Bayesian probability, which views probability as a &#8220;degree of belief&#8221; based on available data and expert judgment, allows for the flexibility and adaptability needed in cybersecurity. While data may be limited and conditions evolve quickly, we can still use this approach to build risk models for a company&#8217;s unique threat surface. These risk models combine the aforementioned data-driven probabilities with variables like control maturity, cyber-insurance claims data, and business and industry-specific factors to create accurate, up-to-date risk assessments. This Bayesian probability model is thus what I refer to when I say &#8220;probability.&#8221;&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Learning From Insurance&nbsp;\">Learning From Insurance&nbsp;<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">We can glean a lot about cyber-risk and probability from what may sound like a surprising source: insurance data. Because my company provides <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/cyber-insurance-strategy-requires-ciso-cfo-collaboration\">cyber insurance<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> as well as risk management strategies, we have visibility into just how many insurance claims actually become &#8220;material&#8221; to a company. In other words, we can see not only the number of attacks our clients faced \u2014 but also what the real financial impacts were. While we saw the frequency of claims rise by nearly 35% in 2024, these <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.linkedin.com\/pulse\/threatonomics-newsletter-november-resilience-cyber-nshdc\/\">claims actually became material at a lower rate<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> than we saw in 2023.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">What does this mean? At the most granular level, it means that companies in our portfolio aren&#8217;t losing as much money from cyberattacks as they could have. That&#8217;s encouraging in itself, but it also suggests a broader, encouraging trend: cybercrime is here to stay, but companies are getting better at withstanding the worst of the effects. And we&#8217;re not alone in seeing this positive trend: Coveware <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.coveware.com\/blog\/2024\/11\/1\/law-enforcement-doxxing-raises-risk-profile-for-threat-actors\">recently reported<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> a major decline in ransom payment rates, while Palo Alto Networks <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.paloaltonetworks.com\/blog\/2024\/11\/unit-42-predicts-top-threats-in-2025\/?utm_source=newsletter&amp;utm_medium=email&amp;utm_campaign=newsletter_axioscodebook&amp;stream=top\">predicts a shift<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in the effectiveness of ransomware demands as organizations increasingly invest in not only better security postures, but more cyber resilient architectures overall.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Whether through risk management strategies, a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/how-to-get-your-board-on-board-with-cybersecurity\">more cyber-aware and proactive board<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, investments in cyber insurance and best-in-class security tools, or a combination of these, companies are growing more resilient, even as cyber criminals get smarter and faster.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Putting Data and AI to Work\">Putting Data and AI to Work<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">These improvements in mitigating damages from cyberattacks over the past year are not happening in isolation. They are a result of a renewed, better focus on putting security and risk data to work. When we have the right data \u2014 and the right probability models \u2014 we can adopt a far more informed understanding of what&#8217;s to come in the future, and what the potential impacts are.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For us, that means building a complex model based on the data we have. Our models are constructed as a network of event triggers and input signals; taken together, they inform the probability that losses will occur, the range of losses when they do occur, and the probabilities associated with the size of the losses in the range. We do this according to the kind of perils that can materialize into those losses, including business disruption, data breach, fraud, and extortion.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The rate at which perils result in losses is influenced by the maturity of the security controls that our customers have. We tune the relationship between these signals, their level, and their output based on our experts&#8217; degrees of belief, cyber claims data, and firmographic data. This large network facilitates our probabilistic reasoning \u2014 and the results we observe tend to be quite accurate.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Resisting the FUD Mentality\">Resisting the FUD Mentality<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Fear, uncertainty, and doubt (FUD) often cloud our vision when it comes to cybersecurity decision-making and future projections. That&#8217;s understandable: Cyberattacks on large organizations have affected many of us directly. Maybe you couldn&#8217;t get a prescription in time after the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/unitedhealth-reveals-100m-compromised-change-healthcare-breach\">Change Healthcare attack<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Or perhaps you received a notice that <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.nbcnews.com\/news\/us-news\/t-says-hackers-stole-records-nearly-cell-customers-calls-texts-rcna161507\">your data had been breached<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> as a result of an attack on AT&amp;T. Even if you haven&#8217;t been personally affected, an onslaught of doom-and-gloom headlines can make it tempting to look to the future and assume disaster is imminent \u2014 or worse yet, that there&#8217;s nothing we can do about it.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">But when we remove our FUD glasses and look at the cold, hard data, those assumptions become glaringly incorrect. That&#8217;s why assessing risk with a probabilistic model can give us far better insight into not only what&#8217;s likely to happen, but what the actual impacts may be. And when we better understand potential impacts, we can conceptualize far more effective solutions. Think: choosing comprehensive security tools that protect whatever a company identifies its &#8220;crown jewels&#8221; to be; building a full team behind a company&#8217;s chief information security officer (CISO) and adding new cyber-savvy board members; and even investing in cyber insurance.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Furthermore, it&#8217;s probability \u2014 not predictions lacking hard data \u2014 that helps us quickly make important decisions under pressure and uncertainty. While probabilities may be based on subjective information, when used in an objective framework, they demonstrate an effective way to improve the value of the hard decisions we make. And when we feel more confident in these decisions, we get better solutions that can make us essentially invincible to whatever cybercriminals may throw our way this year.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/why-cybersecurity-needs-probability-not-predictions\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY Many cybersecurity leaders kick off each new year with<\/p>\n","protected":false},"author":12,"featured_media":7216,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-7215","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/why-cybersecurity-needs-probability-not-predictions.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/why-cybersecurity-needs-probability-not-predictions.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/why-cybersecurity-needs-probability-not-predictions.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/why-cybersecurity-needs-probability-not-predictions.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/why-cybersecurity-needs-probability-not-predictions.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/why-cybersecurity-needs-probability-not-predictions.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/why-cybersecurity-needs-probability-not-predictions.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/why-cybersecurity-needs-probability-not-predictions.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/why-cybersecurity-needs-probability-not-predictions.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/why-cybersecurity-needs-probability-not-predictions.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/why-cybersecurity-needs-probability-not-predictions.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/7215","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=7215"}],"version-history":[{"count":1,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/7215\/revisions"}],"predecessor-version":[{"id":7219,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/7215\/revisions\/7219"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/7216"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=7215"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=7215"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=7215"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}