Improving cybersecurity in the private sector will require more than better technology. It will take better consumers who can create a market for better technology.

Bill Jackson, Principal Writer, Tech Writers Bureau
Bill Jackson, Principal Writer, Tech Writers Bureau
Follow Bill on twitter @TheCybereye

How can we fix a cybersecurity infrastructure that by most measures does not seem to be working? The problem is apparent in the constant stream of announcements of hacks and breaches, and the U.S. Government Accountability Office has included national cybersecurity in its list of high-risk challenges 2017.

At its root, the problem is not technical but economic say two industry leaders. Fixing it will require a better-informed workforce and customers who can create a market for better technology. When buyers have the knowledge and the market clout to demand better security products and services, the cybersecurity industry will have the incentive to produce them.

Organizations are not ignoring cybersecurity. Analysts at MarketsandMarkets predict that spending on cybersecurity products and services will grow to $248.6 billion by 2023. But despite this growing investment, high profile data breaches continue to occur. In one of the most recent and widespread examples, numerous U.S. government and private sector organizations were breached by Russian and Chinese agents exploiting flaws in IT infrastructure management software from a third-party vendor.

Cybersecurity professionals are not optimistic that things will improve. In a recent research report from the Enterprise Strategy Group (ESG) and the Information Systems Security Association (ISSA) released in July 2020, two thirds of cybersecurity professionals interviewed said that their adversaries have a big advantage over them in the fight to protect IT systems.

Cybersecurity will always be challenging, but it is not impossible. The security industry can provide the products and services needed for the job if they are given the economic incentive, said Henry Harrison, CSO of Garrison, a U.K.-based provider of hardware-level IT security.

“The industry has been very successful in providing what people will buy,” he said. But too often those products are heavy on promises and light on performance. He believes the industry can be just as successful in providing highly effective tools when customers demand them. This requires that customers have the knowledge to make informed decisions about the quality and effectiveness of the technology and services they are buying.

That knowledge currently is in short supply. Too many organizations assume that they can simply transfer their cyber risk to a technology or service provider, said Ralph Sita, president and co-founder of Cybrary, a provider of hands-on cybersecurity training. “The reality is that you cannot transfer your cyber risk. Organizations own this risk just like they own other risks.”

Accepting this ownership and dealing effectively with risk does not begin or end with the purchase of a security product. It requires continuous development of professional cybersecurity skills so that employees fully understand the needs of their IT systems, know what security tools do and how they do it, and can evaluate whether the tools meet their needs. This knowledge must also be communicated to senior management who are making policy and buying decisions.

The Market for Lemons

Harrison believes that a lack of understanding of cybersecurity technology puts organizations at the mercy of vendors when making buying decisions. Decisions are made primarily on the basis of price and vendor claims rather than on a product’s efficacy. This, he says, has created a “market for lemons.”

The concept of a market for lemons predates cybersecurity, originating in a 1970 paper by Nobel-winning economist George Akerlof. In his paper Akerlof argues that buyers without enough information to distinguish the quality of products and who are focused on price alone end up being sold only lemons by sellers who are focused on maximizing profit and keeping costs low. This puts a premium on lemons—substandard products—and squeezes better products out of the market. In short, buyers get what they demand and no more.

Harrison does not fault cybersecurity vendors for this. “That’s the way the market works,” he says. Successful capitalism does not always work in the buyer’s favor. “Capitalism can always get broken,” and when markets don’t work the way we want, they must be fixed.

“There are some good products out there, but not very many,” he said. If enough buyers evaluate and vet products before buying and demand better performance—and are willing to pay for the improved performance—vendors will produce better products, Harrison believes. But the market for high-quality products must be large enough to make it worthwhile for vendors to produce them at scale. The private sector market for cybersecurity, though large, is too fragmented for this to happen now. Even large corporations are too small to move the market acting alone, Harrison said.

National governments are an example of market movers who can demand and get high-quality cybersecurity products, Harrison said.

“There is a high degree of coherence across government,” he said, and agencies such as the National Security Agency (NSA) have the expertise and budget to drive quality in the marketplace. They form trust relationships with vendors and as a consequence have more effective cybersecurity than much of the private sector. Government cybersecurity is not perfect, but Harrison argues that high-value targets such as classified national security systems are benefitting with improved security through high-quality products from trusted vendors.

Should private companies just trust government and piggyback on their trusted vendors? Harrison notes it’s not that simple.

Many organizations cannot afford that technology, and “not everybody trusts the NSA,” he said. “And the NSA doesn’t trust everybody.” So adopting their standards can be problematic.

Governments are becoming more active in promoting security standards for commercial products. The NSA’s Center for Cybersecurity Standards collaborates with industry to ensure that off-the-shelf commercial products meet its needs. In the U.K., the National Cyber Security Centre has recently published security principles for cross-domain solutions. But although these efforts can help raise the quality of cybersecurity, the impact on the private sector has not been great, Harrison said.

Fixing the Problem

Although he is a capitalist, Harrison does not object to government regulation in principle. “Capitalism can always get broken,” he said. But he does not think government regulation of a global cybersecurity market is likely to succeed. Working within the buying community is a better route.

The solution for the cybersecurity market is two-fold:

  • Correcting the information asymmetry that allows vendors to sell products that don’t meet customers’ needs.
  • Creating a cohesive private sector market that can move the cybersecurity industry.

The shortage of cybersecurity skills is a long-standing problem. The 2020 ESG and ISSA study reported what the IT industry already knows. Seventy percent of ISSA members said their organization has been hurt by a cybersecurity skills shortage, and 45% said the shortage is getting worse. Prospects for improvement are not great, according to the report. “There is a continuous lack of training, career development and long-term planning,” researchers found.

This makes it difficult for organizations to find the expertise they need to protect their IT systems, and also handicaps them in making decisions when acquiring products and services. Too often, they rely on the fallacy of “security by compliance,” said Cybrary’s Sita.

“They think checking the boxes on a compliance standard is equivalent to security,” he said. “Companies also tend to think that the latest technology will solve their security problems when the issues are often rooted in poor cyber hygiene in general.”

Avoiding this trap requires knowledge not only for frontline cybersecurity practitioners but for executives who make buying decisions. “Leaders have to be sure who they’re doing business with,” Sita said. “Take time to understand the risks and know that a checkbox doesn’t equal security.”

As with many problems, identifying a solution for cybersecurity is simpler than executing it. The cybersecurity landscape is constantly and rapidly evolving. “Traditional educational systems have a hard time keeping pace with it,” Sita said. “Acquiring the needed skills takes a significant investment in time and money.”

Private sector investment is tied to business outcomes, and businesses still are learning how cybersecurity enables corporate objectives. “It’s often difficult to quantify potential benefits and risks in cyber initiatives,” Sita said. “Leaders of all stripes have some growing to do if we hope to get there.”

Harrison believes that existing business organizations are likely to be more effective than government regulation in influencing the cybersecurity market, and he sees a model in the international banking community.

“I think the leadership of the financial industry has gotten the message that cybersecurity is critical to their business,” he said. “I think it is going to be incumbent on the big banks to work through the existing regulations they now have” to set industry standards for cybersecurity. This would not only help the banking industry, but could also set an example for other sectors, he noted.

Significant change will not come quickly, he said. “It takes hard work to build cybersecurity,” and it takes scale to make the effort pay off. But if major industry sectors become more knowledgeable consumers of cybersecurity, they can begin to turn around the market for lemons where they are currently shopping.

FedInsider-Logo-250