Misleading Metrics

Misleading Metrics

The misuse of statistics for marketing is a bugbear of mine.

  • 'Small businesses are 10 times more likely to be affected by ransomware.'
  • '90% of cyber security incidents are down to human error.'
  • '60% of businesses affected by ransomware fail within 6 months.'
  • 'There are 214,719,292 vulnerable DNS servers.'

I've posted about invented numbers and how to spot them before, and doubtless will again, but this morning I was sent a white paper which annoyed me.

The two key highlights from the report, which appears to be a marketing effort to sell security consultancy (hey, I get it, I like to sell security consultancy too - being able to eat and have a roof over my and my people's heads is one of my favourite things) are about the link between revenue and cyber security. To quote:

  • 91% of companies that lagged in Cybersecurity missed revenue goals
  • 57% of companies that led in Cybersecurity exceeded revenue goals by 7%+

Alarming! Clearly, doing better at cyber security (UK spelling has a space, I get more nitpicky about this every time someone throws a tantrum about something so inconsequential) makes you better at business.

In fact the report reinforces this by talking about how these successful businesses are not only more mature in their security, but more likely to see security as a business enabler. Who wouldn't draw the conclusion that investing in security maturity is the key to success?

Correlation != Causation

I'll give the AT&T white paper points for never using the word causation, even if the language and framing strongly hints that way. They state that there's a correlation, but never use the word causation. Unfortunately while the data and findings are presented fairly, there's a passage in the exec summary which I take issue with:

The goal of the research was to validate if, and to what degree, organizations more in alignment with best practices prescribed by the NIST CSF can help to operate more secure environments and better enable their businesses. - AT&T Business, The Relationship Between Security Maturity and Business Enablement

There is absolutely no relationship between the stated goal, and the outcome of the research. Yes, they've established correlation, but they have not established that the NIST CSF lead to more secure environments, or that more secure environments better enable their business.

Let me put forward an alternate hypothesis. From much later in the report, where people may or may not read to (most readers of white papers don't get past the exec summary, statistically speaking, it's why they exist):

The research points to a relationship between business success and cybersecurity acumen. This connection is likely anchored by trust, communication, and collaboration between people—managers and staff from lines of business (LOB) and cybersecurity teams. - AT&T Business, The Relationship Between Security Maturity and Business Enablement

Could it, just maybe, be that more mature businesses with better trust, communication, and collaboration between different business areas are inherently more successful in terms of revenue targets (or, for a more cynical take, more realistic about their revenue targets - as these were declared by the businesses) and that being more mature in cyber security by the carefully chosen criteria is an outcome of that?

It's a pity that this research has been promoted this way, because if the link between overall business culture and security maturity were actually explored I can see interesting questions coming out of it about the way cyber security is approached and marketed.

Sadly, a lot of the time this research is mostly about marketing and doesn't delve deeper into the areas where it could make a real difference.

Alan C.

InfoSec Professional | Infrastructure Engineer | Tenacious Problem Solver | Manager | Mentor | Geek.

1 年

I know it's not exactly the point you were getting at, but impressive-sounding bogus statistics infuriate me to a degree where my partner will change TV channels rather than have me yelling impotently at L'Oreal adverts. There used to be a safety poster on a bus stop near where I worked, "2 out of 5 thefts from cars happen to unlocked vehicles." Well, damn, 3 out of 5 thefts are from locked cars, I'm leaving mine unlocked in future. There was an ad on telly the other day, something along the lines of "removes up to 100% of stains." Could there be a more nonsense claim? "Up to" does the heavy lifting in a lot of marketing of course. "SALE: UP TO 30% OFF!" could mean that everything is full price, all the ad is saying is that whatever saving you may make it will never be more than 30%. I could claim that putting my keys in my pocket removes 'up to' 100% of stains and I'd be correct; the actual figure is zero but it meets the criterion. But here, "up to 100%" - well, as opposed to what? Does a competing product remove 120% of stains? My new stain remover removes up to 1,000% of stains, I'm going to be rich! It is abject nonsense and we actually pay people to come up with this tripe.

Scott McGready

Maker, Breaker, Fixer, Faker. Focusing on making the world a safer place

1 年

As always, excellently put.

Dr Jack Whittaker

Criminologist (Cybercrime/Fraud)

1 年

Very enjoyable read. Another personal favorite of mine is when cybersecurity companies attempt to estimate the costs of cybercrime to society... as a means of introducing the narrative of fear as a marketing tool. I remember a report by McAfee in 2020 had a figure derived from actual losses (completely fine) and a very weird arbitrary "time lost in monetary terms/opportunity cost" estimated figure.

Alexandre BLANC Cyber Security

Advisor - ISO/IEC 27001 and 27701 Lead Implementer - Named security expert to follow on LinkedIn in 2024 - MCNA - MITRE ATT&CK - LinkedIn Top Voice 2020 in Technology - All my content is sponsored

1 年

Thanks for sharing ! Yes, numbers are easily wrongly lifted, and this happens often.

要查看或添加评论,请登录

James Bore的更多文章

  • Boring On is Going Multimedia

    Boring On is Going Multimedia

    For those who follow my word of the day (and there are enough of you that it convinced me to keep it going) you've…

    2 条评论
  • Customer Insecurity

    Customer Insecurity

    I'm a big fan of taking lessons from one area of security to another, and a recent article about Walgreens[1] was too…

    3 条评论
  • The Thinking Trap

    The Thinking Trap

    We've all seen the posts about how AI can streamline research, accelerate papers, short-circuit decision-making, and…

    16 条评论
  • Can't Think Outside the Box Without a Box

    Can't Think Outside the Box Without a Box

    I recently had a brief conversation which gave me a full-on epiphany about why so many VC-funded, massively successful…

    8 条评论
  • Dropping the Ball

    Dropping the Ball

    It happens to everyone from time to time, both in personal and professional life, but it's much more noticeable when…

    3 条评论
  • Making Policy

    Making Policy

    One of the most common challenges we come across working with clients who have mature management systems is that they…

    3 条评论
  • Defining Objectives

    Defining Objectives

    Last week we talked about building the foundation of our management system - defining who we are and what we are as a…

    2 条评论
  • Starting Over

    Starting Over

    This is a bit of an experiment. We've decided to rebuild our BMS (Business Management System) from scratch.

    3 条评论
  • Informational Flak

    Informational Flak

    I did have another topic planned, but given what I'm already seeing out there this one seemed more timely…

    14 条评论
  • Deepfakes: Solving the Wrong Problem

    Deepfakes: Solving the Wrong Problem

    I first wrote about deepfakes back in 2019 in a textbook for Springer, and made a few predictions. Sadly the publishing…

    27 条评论

社区洞察