• Home
  • News
  • Coins2Day 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechChanging Face of Security

This 1 Simple Equation Describes Cybersecurity in a Nutshell

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
May 14, 2016, 11:35 AM ET
German Comprehensive School
GOETTINGEN, GERMANY - SEPTEMBER 19: Posed scene: student writing a mathematical equation on a blackboard at the Georg-Christoph-Lichtenberg-Gesamtschule IGS Goettingen on September 19, 2014, in Goettingen, Germany. The Georg-Christoph-Lichtenberg-Gesamtschule is a comprehensive school. Photo by Thomas Trutschel/Photothek via Getty Images)***Local Caption***Thomas Trutschel—Photothek via Getty Images

A version of this post titled “The risk equation” originally appeared in the Cyber Saturday edition of Data Sheet, Coins2Day’sdaily tech newsletter.

How do you calculate risk?

It’s simple, according to Michael Hayden, former head of the U.S. National Security Agency and later the Central Intelligence Agency. The ex-spy boss boiled the concept down to its basics at a computer security conference earlier this week. Here’s the formula he presented on a slide:

Risk = threat x vulnerability x consequence

The equation is nothing new in the world of risk management, nor is it particularly precise—at least as a mathematical model for information security. (Hell-bent hacker x unpatched software x 17 =???) It is, however, a useful shorthand for understanding the factors that expose systems to danger. Nudge a little here, take a little there, and it gives you a sense for how a person might best manage their defenses. Think of it as an “ideal gas law” of sorts, except for digital attacks instead of chemistry.

“Most of the history of what we call cybersecurity has been in that middle factor—vulnerability reduction,” Hayden said on stage. That means maintaining firewalls, perimeter barricades, software patches, and good passwords. In other words, stop the bad guys from getting in. Reduce the attack surface. Fortify.

For more on cybersecurity, watch:

In the new paradigm, however, consequence is what matters most, Hayden continued. Breaches are an inevitability. “They’re going to get in,” he said of hackers. “Get over it.”

To cope with the new circumstances, defenders must invest time and energy getting to know what data is worth protecting, who should access what, when, and from where. Authentication—validating identity—becomes key. What good is a wall, after all, if your adversary can open the gate from inside?

Hayden knows this predicament better than anyone. Just ask Edward Snowden—or, ahem, as Hayden referred to the NSA mega-leaker on stage: “Voldemort.”

Speaking of which, Hayden’s reaction to the new Snowden film trailer is worth a watch—even if the trailer itself isn’t. And with that, enjoy the weekend. More news here.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon
Rankings
  • 100 Best Companies
  • Coins2Day 500
  • Global 500
  • Coins2Day 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Coins2Day Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Coins2Day Brand Studio
  • Coins2Day Analytics
  • Coins2Day Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Coins2Day
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Coins2Day Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Coins2Day Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.