Episode 209: Security Chaos Engineering with Game Theory
In episode 209 of Cybersecurity Where You Are, Sean Atkinson argues that most organizations prepare for operational failure like they're bracing for a hurricane while most adversaries are playing chess. Drawing on security chaos engineering and game theory, he walks through a structured approach that blends threat modeling, internal red teaming, and constructive disagreement to empirically test and strengthen a defensive posture.
Here are some highlights from our episode:
- 00:33. The RSA Conference 2025 presentation behind this episode
- 00:48. How artificial intelligence (AI) is only accelerating adversaries' evolution
- 01:23. Hurricanes and chess: Analogies for different types of disaster preparedness
- 04:03. Overview of chaos engineering and game theory
- 05:01. Understanding threat vectors in our environment and how MITRE ATT&CK can help
- 05:50. Why adversaries "need a vote" when planning for failure
- 07:03. Red teaming and the need for penetration testing as part of an internal process
- 07:50. Going beyond technology to understand business objectives and strategy
- 08:51. Continuity as a consideration for continually adapting and updating controls
- 10:12. Transition from three separate threat silos to multidimensional threats
- 10:45. Game theory: It's not just a tabletop exercise (TTX)
- 12:15. Goalkeeper: An analogy for addressing "predictability of weakness"
- 13:52. Testing where our weaknesses are: An important element of chaos engineering
- 14:58. Accounting for biases and finite resources when evaluating strengths and weaknesses
- 17:56. Vulnerability identification: An example of how a strength can become a weakness
- 22:25. The need to resist getting too sophisticated with internal red teaming too quickly
- 24:23. Rigor for pushing back against tired adages like "it's never happened to us before"
- 26:22. An implementation strategy focused on communication
- 27:00. Dr. Tyler Moore's Return on Security Investment and the consequences of doing nothing
- 28:03. Debate and commit: A leadership principle for getting the most out of disagreement
- 30:42. Start small, provide notice to those affected, and consider a "surprise audit"
- 32:12. Minimize the blast radius, build hypotheses, balance bias, and other best practices
- 37:38. Parting thoughts of how to break down this approach
Resources
- Episode 208: Secure Harness Engineering for Agentic AI
- Game Theory Informed Security Chaos
- Book - Security Chaos Engineering: Sustaining Resilience in Software and Systems
- CIS Community Defense Model v3.0: Turning Threat Intelligence Into Action
- CIS Red Team Services and Exploit Demo
- Penetration Testing
- CIS Critical Security Control 18: Penetration Testing
- MS-ISAC Guide to DDoS Attacks
- Episode 121: The Economics of Cybersecurity Decision-Making
- Episode 166: Foundations of Actuarial Science in Cyber Risk
- CIS Leadership Principles
- Netflix TechBlog
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].
As of June 23, 2025, the MS-ISAC has introduced a fee-based membership. Any potential reference to no-cost MS-ISAC services no longer applies.