What Schrödinger can teach us about cybersecurity

Recently, I had what I believed to be a unique brainwave. (Spoiler alert: it wasn’t, but please continue reading!)

As a marketing leader at ESET UK, part of my responsibility is to convey how our robust and comprehensive solutions can be utilized to safeguard organizations, in a manner that helps clarify the rationale for upgrading to higher levels of cybersecurity. The need for clarity in this regard is now more pressing than ever.

Cybersecurity experts and organizations, such as the UK’s National Cyber Security Centre (NCSC), often state that cyberattacks are not a matter of “if, but when.” Therefore, it may not be far-fetched to consider every organization as being in a “pre-breach state,” where threats may already exist but remain undetected.

This concept brings to mind Schrödinger’s cat, the famous thought experiment where a cat in a sealed box is simultaneously alive and dead until observed. In cybersecurity terms, your organization could be seen as existing in a similar state: both breached and not breached until investigated. Without visibility, the true state remains unknown, and by the time it is discovered, the damage may already be done.

Accepting this reality requires a shift in mindset and strategy. For organizations lacking the necessary tools for internal threat detection and monitoring of malicious activities, one could argue that they are in a sort of “quantum breach state,” akin to a duality of state encountered in quantum theory.

It was not surprising to discover that my brainwave was shared by others who had used this analogy to highlight the new reality and urge organizations to reassess their cybersecurity strategies. While slightly disappointing from a personal standpoint, it is reassuring to know that this line of thinking resonated with others.

However, I will now critique the analogy while emphasizing the main message.

Randomness and Planning

The original thought experiment, devised by Austrian physicist Erwin Schrödinger almost 90 years ago, relied on the random chance of radioactive decay triggering a series of events leading to the cat’s fate. In contrast, cybercriminals often plan the timing of their attacks meticulously.

For instance, the criminal group Scattered Spider, responsible for breaches at Marks and Spencer and Jaguar Land Rover, operated undetected within their systems for extended periods. The timing of their attacks was strategic and deliberate, rather than random chance.

Therefore, the quantum breach analogy does not entirely hold up. The attackers’ actions were planned for maximum impact, rather than occurring randomly.

Considering statistics from IBM’s Cost of a Data Breach Report 2025, it is evident that organizations are often breached long before they realize it, leading to significant damage.

Solutions: Security Measures and SOCs

If you agree with the notion that your organization is in a pre-breach state, potential solutions include enhancing security measures or implementing EDR or XDR tools for threat detection. The latter option involves actively monitoring and investigating threats, akin to “opening the box” in the thought experiment.

However, relying solely on security measures may not be sufficient, considering the insider threats and sophisticated attack strategies employed by cybercriminals. In such cases, having a Security Operations Center (SOC) staffed with security analysts could be beneficial, though setting up and maintaining a SOC can be costly and time-consuming.

Ultimately, the skill and resources required to operate these tools effectively should not be underestimated, and organizations must carefully weigh their options to ensure effective cybersecurity measures are in place.

Hey there, cybersecurity warriors!

So, picture this: you’ve fixed the breach, you’re now keeping an eye on your systems, but hold up – don’t let your guard down just yet. Feeling safe doesn’t always mean you actually are. It’s like thinking you aced that test, only to find out you missed a whole section because you didn’t have the right skills to analyze the questions.

Now, here’s where it gets tricky. Some cyber insurance policies demand EDR solutions to be in place for coverage. But here’s the catch – you might not have the expertise to operate these tools effectively. It’s a tough spot to be in, right? The pressure in the cybersecurity world can be overwhelming, to say the least.

But fear not, my friends. There’s a light at the end of the tunnel. More and more organizations are turning to vendors for help. Managed detection and response (MDR) services are like having a team of experts on standby, ready to tackle any threat that comes your way. They take the stress off your shoulders, defuse the cyber bomb, and make sure you’re up to speed with insurance and compliance requirements. It’s a game-changer in the fight against those pesky cyber criminals.

Let’s face the facts

  • You might think you’re in the clear, but you won’t know for sure until you see what’s really going on in your systems. Are you absolutely certain you haven’t been breached?
  • If you don’t have the skills to hunt down threats and take action, the tools you’re using could do more harm than good. Do you have what it takes?
  • Even if you manage to set up EDR/XDR solutions on your own, the time it takes to detect and respond to threats will be way longer compared to what a third-party vendor can achieve. Do you know your own response times?
  • Building and maintaining a Security Operations Center (SOC) can be a massive drain on resources. Do you really have the time and money for that?
  • MDR services are a lifesaver for organizations of all sizes – from small startups to big corporations.

References:

  • “Schrödinger’s Cat in Cybersecurity: The Paradox of Uncertainty” – a great read on the importance of proactive monitoring. [linkedin.com]
  • “Schrödinger’s Breach” – sheds light on dwell time and the false sense of security. [advantage.nz]
  • Cyber Strategy Institute – explores trust and risk in cybersecurity using a quantum analogy. [cyberstrat…titute.com]

Leave a Reply

Your email address will not be published. Required fields are marked *