
I have just been reading Scott Patterson’s (WSJ) Chaos Kings, about Nassim Nicholas Taleb and Mark Spitznagle’s background, development, and experiences related to risk management and development of a new investment vehicle for investors to hedge, looking to mitigate risk in their portfolios. They refer to what Taleb coined the term, Black Swan event, based upon the Black Swan theory (defined as “the black swan theory or theory of black swan events, a metaphor that describes an event that comes as a surprise, has a major effect, and it is
Start writing today. Use the button below to create your Substack and connect your publication with Tim’s Substack
often inappropriately rationalized after the fact with the benefit of hindsight.”)
Some of the main points of their investment approach I took away:
It is a ONE (1). The future event that will negatively impact your investments will occur. It is not an if, but when.
Predictive analysis is a waste of time and money. The expending of effort on predicting the future is not protecting against the event. It does not provide any mitigation against the risk the future event will cause.
Diversifying ensures nearly maximum losses or even total ruin (given the opportunity cost compared with achieving higher gains in other investment areas/types)
Become okay with losing some money every day. Universa Investments’ hedging strategy involves acquiring very low-cost options that provide HUGE payoffs if/when big stock market drops occur. But this requires purchasing these low-cost options (expenses) throughout the year(s). Investing in the hedge, e.g., downside risk mitigation, is well before an inevitable future event.
The pace of these Black Swan events is quickening. There are more significant unprecedented events happening more often. The volume of yet again unprecedented and exceptional events is rising.
Today, while driving down to the U.S. Passport Office in San Francisco to expedite picking up my new passport, I considered whether there is a way to apply this hedging approach to enterprise cybersecurity. Can a positive impact be produced to save an enterprise significant time and money associated with anticipated cyber attacks?
Thinking through enterprise cybersecurity, I can come up with some correlations associated with the underlying drivers that cause such hedging strategies for Black Swan events to pay off and return significant returns versus firms being ruined.
First, we need to look at the impact of cybersecurity events on an enterprise. The most devastating effect is on ongoing business operations. When such cyber events stop operations, the business can’t continue to operate, produce products or services, and generate revenue and profit. So, the most significant impact of a cyber attack is the interruption of operations.

Now, going back to the correlations of enterprise cybersecurity to underlying drivers of the Black Swan theories of hedging:
Cyber attacks are definitely a ONE (1). It is not if, but when.
Predictive analytics applied to cybersecurity, given the limited resources, primarily time, but money too, doesn’t provide the requisite ROI. These technologies are a shiny new tool, but do they have a real, positive impact? These tools are expensive to acquire and then train to operate.
Diversity: defense in depth, adding yet another layer of security to defend, is a generally limited strategy for enterprise cybersecurity. Hence, the U.S. government’s push via CISA for enterprises to implement zero-trust architectures and security models where one expects its adversaries already to have access to its systems and begin to attack its systems from inside their network. Additional investments in perimeter defenses will not produce the desired impact. Even as I write this piece, there is news of successful cyber attacks levied against the MGM Grand and Caesar’s casinos in Las Vegas. They gained access to their OKTA authentication system and then their VM hypervisors. This is yet another example where we see that attackers regularly adapt their techniques to defeat the individual security layers and find ways to circumvent the entire structure of the layered defense.
Become okay with making regular investments in cybersecurity throughout the year to hedge and mitigate unexpected/expected cyber events. Budgets for enterprise operational resilience usually don’t provide much for resourcing for cybersecurity best practices and procedures (ISO 27001 requires cybersecurity best practices and procedures to be implemented).
There is strong evidence to show an acceleration in cyber attacks, with ransomware being the primary attack being deployed. Cyber insurance is becoming much more expensive and covering much less because the loss rates experienced by insurers were significant over the last three years.
So, it definitely looks like there are some strong correlations between the drivers for Black Swan hedging strategies and cybersecurity, but how would one “hedge” in enterprise cybersecurity? Where could one find another “investment vehicle” that could ensure production and operations during a cyber event? Is this even possible?
When considering such hedging strategies, the primary focus should be maintaining operations. Focusing on operational resilience, an anti-fragile approach for your business operations with a keen view toward operational resilience and implementing robust cybersecurity controls and processes, including the operations lifecycle and recovery.
Make the investments in people, processes, and technology that make a real difference when the cyber event occurs.
It might be good to ask a series of questions when assessing your enterprise's operational resilience. Enterprise resilience refers to an organization’s ability to adapt and respond to various challenges, disruptions, and changes in the business environment. Here are some questions to help you evaluate your organization’s resilience:
How well does your organization identify and assess potential operational risks and threats?
What strategies and plans are in place to mitigate and manage identified risks?
How effectively does your organization communicate and collaborate across different departments and teams during a crisis?
Are there clear roles and responsibilities for employees during a crisis, and are they well-trained to handle their responsibilities?
How quickly can your organization recover from a disruption and return to normal operations?
Are there backup systems and processes in place to ensure business continuity during a disruption?
How well does your organization learn from past incidents and implement improvements to its resilience strategies?
Are there regular reviews and updates to your organization’s resilience plans and strategies?
How effectively does your organization monitor and respond to changes in the external business environment?
Does your organization have a culture of resilience, with employees encouraged to be proactive and adaptive in the face of challenges?
These questions can help you assess your organization’s resilience and identify areas for improvement. Addressing these aspects can strengthen your enterprise’s ability to withstand and recover from disruptions, ensuring long-term success and stability.
To hedge against a cyber ransomware attack before it happens, an enterprise can take several proactive measures:
Educate employees on cybersecurity and phishing awareness to prevent them from falling for scams and inadvertently introducing malware into the system. Require ongoing training on best practices, such as using strong passwords (hopefully migrating to certificate-based authentication methods S/MIME), verifying email senders, and avoiding suspicious links or attachments.
Implement cybersecurity plans and policies, including an incident response plan (IRP) that outlines possible scenarios, responses, and notification procedures.
Implement disaster recovery systems and processes. Establish routine network backups and updates to ensure data can be restored in case of an attack. Regularly practice and demonstrate these disaster recovery (DR) systems and processes. Are they multi-regionally based, as well as online, immutable, and offline (cold storage)?
Keep systems patched and updated to minimize vulnerabilities that ransomware attackers can exploit.
Conduct regular audits of ports, protocols, and services required to support business operations and implement a deny-all policy for unneeded services. Adopt a practice of PEN Testing, as well as more robust testing and challenges of defenses of your systems and services, including policies and procedures, with RED and PURPLE teams.
Implement a zero-trust-based approach to your users, systems, and services. Implementing zero-trust in all of your operations and practices. One can’t rely upon layered security defenses. Once attackers gain access to an admin’s credentials, they can access critical systems, and it becomes incredibly difficult to interdict, isolate, and stop them. Consider implementing certificate-based PKI across all critical systems so one’s passwords are all that is required for authentication and access.
Consider purchasing a cybersecurity insurance policy covering ransomware attacks, ransom payments, extortion-related expenses, repair costs, and operational impacts. Although policies are more expensive than ever and cover less, they are still a worthy investment to hedge against cyber attacks.
By implementing these measures and making these regular investments in effort, time, and money, an enterprise can materially reduce the risk of falling victim to a ransomware cyber attack and minimize the potential damage and loss of operations if an attack occurs.
Thanks for reading Tim’s Substack! Subscribe for free to receive new posts and support my work.