The objection that should win
Here is the strongest version of the case against this page, and it deserves to be stated without hedging. A fraud lead does not have the luxury of an option-pricing seminar. Every week a suspicious pattern is left unresolved, it keeps transacting. Real options theory, transplanted from oil leases and pharmaceutical trials, assumes you can wait cheaply while volatility resolves itself. Fraud does not wait cheaply. A mule network that clears £40 in test transactions on Monday can be moving £400,000 by Friday. The "value of waiting for more information" that Dixit and Pindyck priced for an offshore platform assumes the underlying asset does not actively adapt to being watched. Fraud rings do. They probe detection thresholds, learn the review cadence, and route around anything that looks like patience. Calling continuous transaction and device intake an "option" dignifies what is often just organisational lag: the pattern was there in the network graph in March, flagged by no one, and confirmed only in June when the chargebacks arrived and someone finally looked. That is not deferral value. That is failure dressed in economics.
This is a fair hit, and it is worth sitting with before answering it.
Where the objection is right
The literature on real options is genuinely full of this abuse. Dixit and Pindyck's own irreversibility framework has been used by capital committees to justify indefinite non-decision, because "the option to wait is valuable" is a sentence that never runs out of ways to justify not deciding. Fraud operations have their own version: a case sits in a queue because the model score is "borderline," the analyst is "waiting for more signal," and three weeks later the account is drained. If real options language just supplies fraud leads with a more sophisticated way to say "we'll get to it," the theory is worse than useless here — it is a narrative laundering machine for inertia.
It is also true that financial options pricing assumes a tradable underlying and no strategic response from the thing being priced. Fraud rings are not Brownian motion. They are adversarial. A model that waits for its confidence interval to tighten is handing the adversary exactly the interval in which to move the money and close the mule accounts. Pre-emption is not a footnote in fraud detection; it is the whole game. Any framework that treats "wait for more data" as a free action is empirically wrong in this domain and needs saying so plainly.
What survives
The correction the objection demands is not to abandon the option framing but to price it honestly, and the honest price includes decay. A real option's value depends on two things: how much uncertainty remains, and how much you expect to learn before the decision must bind. In fraud, the decision typically binds at the moment of authorisation — that is the deadline, not some arbitrary review date. Waiting past authorisation without learning anything is not holding an option. It is just being late, and the fraud lead's instinct that "we got this the quarter after it drained the account" is a failure is exactly the economics of an option whose premium was paid but whose right expired unexercised. The theory does not excuse that. It explains it.
The correct move is to shorten the deferral window to the length of genuine information arrival and no longer. A device signal — new SIM, emulator fingerprint, velocity of app reinstalls — can resolve real uncertainty about a single transaction within milliseconds. A network-graph signal — this device now shares a card BIN and a delivery address with four accounts opened last week — can resolve uncertainty about a ring within hours, once enough edges accumulate. A chargeback feed resolves uncertainty about a merchant category weeks after the fact, because chargeback windows themselves run to 45-120 days by card scheme rule. These are not the same option. They have different maturities. The mistake the objection correctly attacks is treating them as one long, comfortable deferral. The fix is not "stop deferring." It is "know which stream is short-dated and act on it at its own maturity," and hold the option open on the ones that are genuinely still resolving.
This is also where the theory answers the pre-emption point directly rather than dodging it. Dixit and Pindyck already built competitive erosion into the model: it shortens the optimal wait, it does not eliminate the option's value, because the alternative to waiting-with-monitoring is not waiting-without-monitoring, it is acting blind. A fraud lead who freezes a device the instant it shows one adversarial signal, rather than waiting for a full case file, is exercising the option early precisely because continuous device and network intake told her the marginal information from waiting further was negative-expected-value against an adversary in motion. That is a system correctly pricing zero-or-negative option value and closing the position. It looks like speed. It is actually the same calculus as the offshore operator sanctioning a field the moment forward curves clear the hurdle rather than holding out for a peak that pre-emption makes unlikely to arrive.
The second objection, and its narrower answer
There is a related complaint worth taking on directly: most of a transaction stream is redundant, and watching everything continuously is expensive theatre if six well-chosen indicators would catch the same fraud. This is true of the bulk of any feed. Most device pings confirm nothing. Most graph edges are benign shared Wi-Fi. The overwhelming majority of chargeback codes recur in patterns any six-variable model already captures.
The asymmetry the fraud lead should hold onto is that redundancy is discovered after the fact, never predicted reliably in advance. The card-testing pattern that later revealed a $2 million skimming ring routed through a single compromised point-of-sale vendor did not announce itself in the six indicators anyone was already watching; it showed up as three-cent authorisations scattered across merchant categories that looked, individually, like noise. No fraud team knew in January which of its dozen feeds would carry the signal that mattered in March. The economic argument here is for breadth of permission with sparse, disciplined weighting of attention — watch the transaction stream, the device graph, the network graph and the chargeback feed all continuously, but do not process them all with equal cost or equal urgency. Provenance is what makes this affordable: record which observation moved which belief, so that after the ring is caught you can trace the decisive signal back to its stream and re-weight going forward. Breadth governs what is recoverable at all. Cost discipline governs what gets expensive attention. Conflating the two is the error the objection is right to flag; separating them is the answer.
The claim that holds
None of this rescues an unlimited licence to wait. What it rescues is a narrower, more defensible position: the option to defer a fraud decision has value only up to the point where the relevant stream stops delivering resolving information, and a Large Universe Model configuration — transaction, device, graph and chargeback data held as continuously revisable, provenance-tagged belief rather than a quarterly batch review — is what lets a fraud lead find that point correctly instead of guessing it. It does not make the ring stand still. It does not make monitoring free. It makes the deadline visible, stream by stream, so that deferral is exercised only where it is still buying information and closed out everywhere else. That is a smaller claim than "watch everything and you'll never be surprised." It is also, unlike that larger claim, true.