The Abundance Paradox for Cybersecurity
The Abundance Paradox has many forms but in all of them having lots of something turns out to have downsides in addition to upsides. My cup runneth over (and now the table is wet).
For developing nations we have the Resource Curse in which having abundant natural resources seems to lead to corruption and foreign exploitation and slow economic growth.
For consumers we have the Paradox of Choice in which having too many options doesn't mean that most of get exactly what we want (although some of us do just that) but rather that most of us are paralyzed by the options and end up stressed out and less satisfied than we would have been with fewer choices.
For complex systems we have a bit of a debate: does it make a complex system less reliable to add complexity, even if that complexity is aimed at raising reliability? It is all to often true that adding complexity to a system in order to raise reliability hits a wall, a point after which the additional subsystems raise the number of failure points faster than the subsystems combat failures. It is truer than we would like to admit that rising complexity tends toward sinking reliability,
I assert that cybersecurity (C/S) falls prey to all of these phenomena. This assertion is not as far-fetched as it might first appear because C/S is a vast and sprawling enterprise with overlapping vulnerabilities of technology and human behavior.
I have seen the Resource Curse in C/S when an organization has the latest and greatest of everything, leading its people into a sense of security which is not constantly earned. C/S is like raising small children or chasing extreme fitness: the demands are endless. Resting on our laurels is a terrible idea.
I have seen the Paradox of Choice paralyze even seasoned professionals. There are now so many options, so many embedded firewalls and excess routing tables and other security features that making sure you have turned those features off in the devices which need to NOT help out and turned those features on in the devices which need to do the work is a Herculean task. Validating heterogeneous is even harder. Doing that validation on a regular basis is a career unto itself.
I have see the problem of increased complexity leading to decreased reliability arise again and again. There are exceptions: high availability clusters are great. Advances in back up and restore technology are a big step forward. Load balancing across servers is fantastic when it is properly set up and maintained. However, I have also seen what happens when management takes the belt-and-suspenders approach to C/S and adds all the security. So many basic functions stop working that people in the trenches often just give up in despair. I have seen so many C/S functions simply turned off in field because no one could get them all to work together and people needed to get work done.
(What about AI, I hear you ask. AI is not going to fix this problem, at least not at first. I confidently predict that instead of helping, AI is going to make all of this true in a wide range of new domains. But more on that in the next post.)
So beware the joy of excess and the optimism of plenty. A bit more than you need is good, because needs have a way of suddenly being a little bigger. Lots more than you need can be bad because, as the hippies used to say, at some point you don't own the stuff: the stuff owns you.
Finding this balance is hard, especially when senior management is dazzled by the hype. We can help. Ask us how.
Comments
Post a Comment