Cyber Threshold Effects Require Stochastic Modeling
Dr. Karen Guttieri · Dr. Sam Savage
Threshold functions are nonlinear. By Jensen’s inequality, averaging inputs to a nonlinear function does not yield the correct output. Yet cybersecurity decisions routinely rely on mean-based metrics such as mean time to detect or expected annualized loss.
This app illustrates a threshold structure in which exploitation must occur before detection. Static mode uses averages, which indicate no chance of loss. Stochastic mode unleashes 10,000 trials from a SIPmath JSON Library. When exploit precedes detection, loss accumulates according to:
Loss = IF(Days_to_Exploit < Days_to_Detect,
(Days_to_Detect − Days_to_Exploit) × Daily_Loss, 0)
The controls reduce Detect Time or Daily Loss by a selected percentage. The ChanceOmeter measures the chance that Loss exceeds the selected Threshold.
Threshold effects such as overlap, branching, accumulation, and state-change can systematically invalidate decisions based only on averages. SIPmath preserves the distributions needed to measure exceedance probabilities directly.