← Back to list

Uncertainty Yardstick

You must measure and compare your uncertainty with confidence, otherwise prioritization is like throwing darts with a blindfold on and…

Simon Theodore Kun · 2022-04-29 03:43 · 1 claps · 2.2 min read
#risk #automation #cyber-sercurity
Open on Medium ↗

Uncertainty Yardstick

You must measure and compare your uncertainty with confidence, otherwise prioritization is like throwing darts with a blindfold on and expecting to hit a bullseye.

Photo by Niklas Hamann on Unsplash

Photo by Niklas Hamann on Unsplash

You can’t think about Cybersecurity without thinking about risk (or at least I hope you aren’t). The goal we have as cyber security professionals is to mitigate the risk of adverse cyber events as much as we can. A common argument — whether inside the board room or the SOC — is how likely an event is to occur.

“It’ll definitely happen” or “I don’t think it will happen” or “Maybe it will happen” are all qualitative terms that are difficult to compare. Language (especially English) is also extremely good at being ambiguous — one person’s likely is another persons probably — or they may not align at all.

Coming up with a common language within your organization (that suits you, and how you operate) is key to being able to prioritize threats, security initiatives, and day to day activities. Ensuring you have a known agreed language to be able to discuss uncertainty will speed up risk management and cybersecurity activities and help to articulate to stakeholders the necessity of actions and decisions.

Having this shared language and understanding will also mean everyone is on the same page in terms of what the priority is, and which alert or event needs to be addressed first.

I have gone through and used a number of different scales throughout my career, and I hesitate to provide one as there is no ‘one size fits all’. However I figure it’s useful as an example and to add a few extra thoughts below.

Almost Certain > 90%

Highly Likely 70% — 90%

Likely 50% — 70%

Unlikely 20% — 50%

Very Unlikely < 20%

Don’t have a place to sit on a fence. It is either likely or unlikely - think more or, if you don’t have the information to make a decision, get it.

Don’t have too many options. Granularity is useful but you don’t want to fall into the trap of too many options and having the same actions regardless — if you would do the same thing whether it’s 70% or 95% then that can be a single block rather than two.

Don’t develop this scale in isolation. Use it to foster collaboration and have meaningful discussions about risk and cybersecurity with diverse business units.

Automation Applicability

When it comes to automating security processes uncertainty takes on a few extra dimensions, and having a yardstick specifically for automation's may be helpful depending on your situation.

Consider the following:

  • What level of certainty do you require to automatically mark an event as benign or malicious?
  • Would you add in human intervention when marked as malicious or benign? Or perhaps a third category?
  • Is it better to have some level of scrutiny across all events, or higher levels of scrutiny across only some events?

Automation is about augmentation, get the automation to do what it does best, and let the humans focus on the most important things. By utilizing a yardstick to assist in prioritization of alerting won’t guarantee every event will be looked at, but that they will be looked at in an intelligent and more importantly considered order.


메타데이터
post_id
e324922358a1
slug
uncertainty-yardstick-e324922358a1
url
https://medium.com/@kun.simon/uncertainty-yardstick-e324922358a1
canonical_url
https://medium.com/@kun.simon/uncertainty-yardstick-e324922358a1
author_url
https://medium.com/@kun.simon
status
ok
fetched_at
2026-08-21 12:39:01