
Sign up to save your podcasts
Or


In IT security, offensive problems are technical - but most defensive problems are political and organisational. Attackers have the luxury to focus only on the technical aspects of their work, while defenders have to navigate complex political and regulatory environments. In a previous talk ("Rearchitecting a defendable internet") Thomas Dullien (aka Halvar Flake) discussed what technical measures would yield defendable devices - and intentionally omitted the political and economics side. This talk explored the economics and incentive structures in IT security: Who is incentivized by who to do what - and how these incentives fail to produce the security level we desire.
The talk discusses different players in IT security: CISOs, security product vendors, computer manufacturers, cyber insurances - and examine their economic incentive structures, their interplay, and reasons for failure. The talk also discusses an alternate reality where things work smoothly, and examine the differences to our current (2017) reality.
By In IT security, offensive problems are technical - but most defensive problems are political and organisational. Attackers have the luxury to focus only on the technical aspects of their work, while defenders have to navigate complex political and regulatory environments. In a previous talk ("Rearchitecting a defendable internet") Thomas Dullien (aka Halvar Flake) discussed what technical measures would yield defendable devices - and intentionally omitted the political and economics side. This talk explored the economics and incentive structures in IT security: Who is incentivized by who to do what - and how these incentives fail to produce the security level we desire.
The talk discusses different players in IT security: CISOs, security product vendors, computer manufacturers, cyber insurances - and examine their economic incentive structures, their interplay, and reasons for failure. The talk also discusses an alternate reality where things work smoothly, and examine the differences to our current (2017) reality.