Episode 209: Security Chaos Engineering with Game Theory

 

 

In episode 209 of Cybersecurity Where You Are, Sean Atkinson argues that most organizations prepare for operational failure like they're bracing for a hurricane while most adversaries are playing chess. Drawing on security chaos engineering and game theory, he walks through a structured approach that blends threat modeling, internal red teaming, and constructive disagreement to empirically test and strengthen a defensive posture.

Here are some highlights from our episode:

  • 00:33. The RSA Conference 2025 presentation behind this episode
  • 00:48. How artificial intelligence (AI) is only accelerating adversaries' evolution
  • 01:23. Hurricanes and chess: Analogies for different types of disaster preparedness
  • 04:03. Overview of chaos engineering and game theory
  • 05:01. Understanding threat vectors in our environment and how MITRE ATT&CK can help
  • 05:50. Why adversaries "need a vote" when planning for failure
  • 07:03. Red teaming and the need for penetration testing as part of an internal process
  • 07:50. Going beyond technology to understand business objectives and strategy
  • 08:51. Continuity as a consideration for continually adapting and updating controls
  • 10:12. Transition from three separate threat silos to multidimensional threats
  • 10:45. Game theory: It's not just a tabletop exercise (TTX)
  • 12:15. Goalkeeper: An analogy for addressing "predictability of weakness"
  • 13:52. Testing where our weaknesses are: An important element of chaos engineering
  • 14:58. Accounting for biases and finite resources when evaluating strengths and weaknesses
  • 17:56. Vulnerability identification: An example of how a strength can become a weakness
  • 22:25. The need to resist getting too sophisticated with internal red teaming too quickly
  • 24:23. Rigor for pushing back against tired adages like "it's never happened to us before"
  • 26:22. An implementation strategy focused on communication
  • 27:00. Dr. Tyler Moore's Return on Security Investment and the consequences of doing nothing
  • 28:03. Debate and commit: A leadership principle for getting the most out of disagreement
  • 30:42. Start small, provide notice to those affected, and consider a "surprise audit"
  • 32:12. Minimize the blast radius, build hypotheses, balance bias, and other best practices
  • 37:38. Parting thoughts of how to break down this approach

Resources

If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].

As of June 23, 2025, the MS-ISAC has introduced a fee-based membership. Any potential reference to no-cost MS-ISAC services no longer applies.