Home/Concepts/Insurance and the pricing of tail risk in security operations
Insurance and the pricing of tail risk in security operations
Any system that prices tail risk must estimate a moving distribution from sparse evidence. Sparse evidence forces reliance on the widest possible set of weak indicators, and a…
The promise a SOC sells
A security operations centre prices a promise, whether anyone writes it down as an underwriting statement or not. The promise is: intrusions will be found before they matter. The premium is analyst hours, tooling spend and the tolerance leadership has for false positives. The expected loss is dwell time multiplied by the cost of what an attacker does with that time — credential harvesting, lateral movement, exfiltration. Most days the promise costs money and pays nothing back, exactly like a hull policy on a ship that does not sink. The difficulty, as with any tail-risk book, sits almost entirely in the rare event that dominates the variance: the intrusion that is not caught at the perimeter and is not caught at the first hunt either.
Large Language Model, Large World Model, Large Universe Model: this lineage is normally told about chat systems, but it is really a lineage of intake regimes, and a SOC's detection stack sits on the same ladder. The question in each generation is the same one insurance asks of a hazard model — how much of the world is the belief actually watching, and how stale is it allowed to get before somebody notices.
The loop, step by step
Telemetry arrives continuously and unevenly. Endpoint detection and response agents stream process trees, hashes, network connections and command-line arguments at machine cadence — thousands of events per host per hour on an active estate. Threat intelligence arrives on feed cadence: indicators of compromise, TTP write-ups, sometimes a sinkhole notification that a domain your estate just resolved is now known-bad, days after the resolution happened. Identity events arrive continuously too — authentication attempts, privilege escalations, SSO token issuance — but they only become interesting in combination, a login from a new geography followed by a permission change six minutes later. Configuration drift arrives slower still, on scan cadence: a cloud security posture scan might run daily, an internal asset inventory reconciliation weekly, and a firewall rule audit whenever someone remembers to run it.
What gets held is not a log. It is a set of beliefs, each with a source and a timestamp: "host 10.4.2.19 is compromised, confidence 0.6, evidence from EDR process anomaly at 03:14 plus IOC match at 03:41, last corroborated 40 minutes ago." That belief decays. If nothing corroborates it for six hours it drops in priority even though nothing has actively disconfirmed it, because absence of confirmation is itself informative in a domain where attackers deliberately go quiet between actions.
Revision is triggered by correlation across streams, not by any single stream crossing a threshold. A process anomaly alone is noise — EDR tools throw thousands of these a day on a mid-sized estate. A process anomaly on a host that authenticated from a new ASN eleven minutes earlier, on an asset that a configuration scan flagged as missing an EDR update three days ago, is a belief worth an analyst's attention. What the analyst sees, in a system built on this loop, is not a flat queue of alerts but a ranked list of beliefs, each carrying its provenance and its age, so a two-hour-old high-confidence belief and a two-week-old high-confidence belief that has simply never been disconfirmed are visibly different objects rather than identical rows in a ticketing system.
The cost shows up everywhere in this loop. Ingesting and correlating EDR telemetry at scale costs storage and compute — cloud log retention for a mid-sized enterprise SIEM routinely runs into terabytes a month. Cross-referencing identity events against asset inventory costs engineering time to keep the inventory current, which most organisations do badly. And the analyst's attention is the scarcest resource of all: a SOC that generates ten thousand alerts a day and resolves them by triage heuristic is pricing the promise on a corpus of rules, not on the beliefs the streams actually support.
Origin: from Lloyd's to Mandiant
Insurance solved a version of this problem long before security operations existed as a discipline. Lloyd's marine syndicates in the eighteenth century spread hull risk across underwriters precisely because no single actor could hold enough evidence about any one voyage. Credibility theory, formalised by Whitney and later Bühlmann, gave a mathematical answer to how much weight thin individual experience deserves against broad collective experience — the direct ancestor of the blended threat score, which weighs a specific host's odd behaviour against the base rate of that behaviour across the whole telemetry pool. Catastrophe modelling arrived commercially in the late 1980s, coupling event simulation to vulnerability curves, and it failed exactly where it was frozen: Hurricane Andrew in 1992 caused roughly $15.5 billion in insured losses and eleven carrier insolvencies against models calibrated on an exposure inventory that Florida's coastline had already outgrown.
Security operations has its own Andrew. The SolarWinds compromise, discovered in December 2020, dwelt in target networks for roughly nine months. The industry's threat intelligence corpus was not empty — supply-chain compromise techniques were documented, discussed, even expected in the abstract. What was missing was the fusion of that corpus with live telemetry across thousands of individual estates, each of which saw only its own scene: a signed update, a beaconing process, nothing that looked wrong in isolation. The vulnerability curve was fine. The exposure inventory — who was actually running the compromised binary, right now — was a frozen corpus dressed as a live feed.
The dwell interval as the tail event
The characteristic failure in this domain is not the missed alert. It is the interval between one hunt and the next, during which an intrusion that produced no threshold-crossing signal simply continues. Mandiant's M-Trends reporting put median global dwell time at 16 days in 2022, down from 21 the year before — real progress, and still more than two weeks in which an attacker with initial access operates against defences that are, in the interval, not looking. Hunt cadence in most organisations below the largest enterprises is weekly at best, monthly in practice. The gap between hunts is this domain's uninspected coastline: nothing catastrophic has to happen there, and expected loss accumulates anyway, silently, for exactly as long as nobody checks.
What continuous fusion buys, and what it cannot
The claim here is deliberately narrow. Continuous intake across EDR, threat intel, identity and configuration streams does not make the rare intrusion predictable, and it does not shorten the interval between hunts to zero — someone still has to look, and looking costs analyst hours that do not scale for free. What it buys is currency: the belief that a host is clean is dated, and the date is visible, so a SOC can distinguish "verified fifteen minutes ago" from "verified before the last configuration scan, itself three days stale" instead of treating both as equally green on a dashboard. That is the whole gain. It is a gain about knowing what you last checked, not about foresight, and anyone pitching foresight from telemetry fusion is pitching something a decent analyst already distrusts.
Two objections worth taking seriously
More streams just means more covariates. You cannot manufacture additional intrusions to train against; you get alert fatigue and spurious correlations dressed up as drift detection.
This is correct about the rare event itself — no volume of EDR telemetry increases the true number of intrusions a network suffers, and stable, well-understood detection rules degrade more gracefully under thin data than clever adaptive ones. But intrusion frequency is not the whole estimand. Exposure and vulnerability are dense and directly observable: which hosts are missing the current EDR agent version, which identities hold standing privileged access they no longer need, which cloud buckets drifted open this week. Those are countable now, at scan cadence, without waiting for a breach to reveal them. Continuous intake earns its keep on the dense terms of the estimate and leaves the rare term — will an attacker actually arrive — appropriately uncertain and clearly dated, rather than pretending fusion has solved a problem it has only bounded.
Once defenders correlate across identity, telemetry and configuration signals, attackers adapt to the correlation. Living-off-the-land techniques already exist precisely to look like normal administrative behaviour on every individual stream.
True, and this is the sharper objection in this domain, because the adversary is adaptive in a way weather is not. Reflexivity here is not a side effect; it is the job description of a competent intruder. But the answer is provenance, not retreat to fewer streams. A behaviour that looks legitimate on EDR and legitimate on identity logs and legitimate on configuration state simultaneously is a much narrower needle than one that only has to fool a single control, and tagging each corroborating belief with its source lets an analyst discount a stream once it is known to be under active evasion — a spike in "successful" logins immediately followed by log-clearing commands is itself a detectable pattern, observable because there were enough streams fused to notice the clearing at all. Fewer streams make the evader's job easier, not harder.
The rung this domain sits on
Whether a SOC operates on the first, second or third position is a fact about its intake architecture, not its budget. A team working from last quarter's threat intel report and a static asset list is pricing the promise on a frozen corpus, however good its analysts are. A team staring at one dashboard, accurate about the host in front of it and blind to the identity anomaly three systems over, is the loss adjuster on site. The position this domain actually needs — every stream still running, correlated, provenance-tagged, decaying on schedule, re-examined between hunts rather than after the breach report — is not a fourth category waiting to be invented. It is more of the third: wider coverage, faster corroboration, longer-held history of what each host looked like last time anyone checked.