Cyber protection is only effective only if we can predict what might happen. Outside of the known-known (we know what we have known), the inverse is the unknown-unknown. This is a back hole because it is outside our imagination.

Practically, we establish cyber protection measures against the known (predictable) threats with certain risk acceptance level. For the rest, there is no point to impose controls to deal with hypothetical cyber threats because each control has its TCO (Total Cost of Ownership). An example is deploying a firewall in an isolation system that has no external network connections with routable protocols. It is not just an one-off investment but the resources at the back to sustain its effectiveness, keep evidence to prove you have done per design to auditor or regulator.

What should we do? The optimal approach is to have system baseline to spot anomalies. Then, well-tested resilience or recovery capability to continue with business.

Leave a Reply