Risk Quantification Fails Its Own Test

▶ Watch (5:28)

Shostack opens with a poll. Few hands go up for having the data needed to quantify risk. Fewer still say the quantification led to a decision. The NIST Cybersecurity Framework centers managing cyber security risks, not delivering safe systems. The EU Cyber Resilience Act uses “risk” 178 times, more than once per page. Standards have embedded the word so deeply that questioning it feels like heresy, yet the practice isn’t producing decisions.

Why Risk Numbers Don’t Work in Cyber

▶ Watch (24:12)

Risk depends on iteration: repeated trials that let you estimate and validate. Insurance works for ships because you can run the numbers across thousands of voyages. Cybersecurity rarely gets that. Predicting which of five vulnerabilities will cause 15 minutes of SOC work versus a Jaguar Land Rover-scale event is guesswork. Adversaries adapt and play by no rules. The party making decisions often isn’t the party that bears the cost.

Cost, Not Risk, Drives Real Security Decisions

▶ Watch (27:48)

Shostack pushed the Auto Run fix from Microsoft’s download center to Windows Update. Data showed a reduction of about a million malware cleanups per month by the Malicious Software Removal Tool, one-in-three of all malware instances. He had predicted the reduction and it held. But inside Microsoft, the debate wasn’t about those numbers. It was about behavior change: users who noticed a patch changed something would turn off patching, a consequence even harder to quantify.

What to Do Instead

▶ Watch (33:51)

Shostack proposes four moves. First, acknowledge that risk is broken and embedded in standards through overloaded language. Second, stop using the word: NIOSH’s hierarchy of controls eliminates hazards without calling them risks. Third, standardize the numbers. Nobody knows the acceptable phishing click-through rate; standards bodies could just pick one, the same way the FDA sets acceptable rat parts per food unit. Fourth, use tools that already work, like Microsoft’s security bug bars, built around remote anonymous escalation of privilege.

Public Health as a Model for Cyber

▶ Watch (49:26)

Richard Feynman’s personal appendix to the Challenger report criticized NASA’s wildly varied shuttle loss estimates. His point: engineering frames work better than risk frames. Shostack’s own research proposes borrowing from public health. Public health measures outcomes directly: incidence (new cases per population per year) and prevalence (people living with a condition). Interventions get evaluated by whether they move those numbers. Cybersecurity could track breach rates the same way, measuring whether controls reduce them in a population of systems.

Q&A

If the acceptable phishing click rate is 1 in 100,000 and you have 100,000 employees, one click can compromise the whole company, and would a cost-of-non-fix divided by cost-of-fix ratio be useful? Isolation should limit one click’s blast radius, and the real fix is setting acceptable rates in standards rather than leaving each organization to argue them individually; cost-of-non-fix calculations quickly produce numbers too outrageous to believe. ▶ 52:41

How do you tell a governance, risk, and compliance team to drop the word “risk” from their title? Changing the language inside a company is hard while standards and executive expectations entrench it, but bold organizations publishing threat models are already leading the shift. ▶ 55:54

Security vendors sell “risk reduction” as proof of value, so who represents the leading edge in moving past risk management? Microsoft’s bug bars and the FDA’s decision to treat likelihood as 1 show the leading edge is already there, and frustration with the approach will push more organizations to follow. ▶ 58:02

Notable Quotes

to sum up this section, stop doing risk. Adam Shostack · ▶ 33:19

and he says risk can mean almost everything Adam Shostack · ▶ 16:57

It’s unlikely. Dread was a tool that led Adam Shostack · ▶ 43:53

Key Takeaways

  • Risk quantification requires iteration over many instances, which cybersecurity rarely provides.
  • The party making security decisions often isn’t the one bearing the cost of a breach.
  • Standardizing acceptable thresholds in standards bodies would spare organizations the same arguments every cycle.
  • Bug bars and CVSS already function as non-risk prioritization tools, without requiring likelihood estimates.