Is Cybersecurity Fundamentally A Physics-Based Problem?

Nic Seeley

S4x24 - ICS Security Conference · Day 3 · Main Stage

Overview

In a thought-provoking presentation at S4, Nic Seeley challenged the conventional understanding of cybersecurity, asking whether it is fundamentally a physics-based problem. This talk delves into the abstract and theoretical underpinnings of our industry, aiming to dissect why practitioners and researchers hold certain beliefs about cybersecurity. Seeley posits that by examining the historical evolution of security concepts and applying principles akin to those found in physics, we can establish a more robust, scientific foundation for cybersecurity, allowing us to affirm some long-held truths and question others.

Watch on YouTube

Visual summary for Is Cybersecurity Fundamentally A Physics-Based Problem? by Nic Seeley
Visual summary for Is Cybersecurity Fundamentally A Physics-Based Problem? by Nic Seeley

Key moments

  1. 0:00 Is cybersecurity fundamentally a physics-based problem?
  2. 2:00 Cybersecurity: engineering without a scientific foundation?
  3. 2:50 Evolution of security research: Trust, trustworthiness, risk
  4. 4:00 Defining security as protection of meaning and value
  5. 5:00 Risk: a more fundamental concept than trust
  6. 6:00 Uncertainty as the fundamental basis for risk

Is Cybersecurity Fundamentally A Physics-Based Problem?

Speakers: Nic Seeley

Conference: S4

YouTube: https://www.youtube.com/watch?v=sI_iZ1IImpM

Overview

In a thought-provoking presentation at S4, Nic Seeley challenged the conventional understanding of cybersecurity, asking whether it is fundamentally a physics-based problem. This talk delves into the abstract and theoretical underpinnings of our industry, aiming to dissect why practitioners and researchers hold certain beliefs about cybersecurity. Seeley posits that by examining the historical evolution of security concepts and applying principles akin to those found in physics, we can establish a more robust, scientific foundation for cybersecurity, allowing us to affirm some long-held truths and question others.

Seeley’s central premise is that while cybersecurity is often treated as an engineering discipline, it notably lacks a clear scientific foundation, unlike traditional engineering fields built upon established scientific laws. He embarks on a journey to explore whether an "F=MA type equivalent" for cybersecurity might exist, starting from an initial skepticism years prior to his current presentation. The talk seeks to convince the audience that this seemingly absurd question holds significant merit and can illuminate fundamental principles that govern the efficacy and limitations of our current security paradigms.

The presentation aims to redefine security from its most basic components, tracing a logical progression from historical concepts like trust to more contemporary ideas such as risk, ultimately arriving at what Seeley argues is the most fundamental concept: uncertainty. By grounding cybersecurity in such foundational principles, he suggests we can move beyond ad-hoc solutions and develop a more coherent, evidence-based approach to protecting digital assets and the meaning and value they represent.

Background

▶ Watch: Is cybersecurity fundamentally a physics-based problem? (0:00)

The evolution of cybersecurity research has seen a progression through several key conceptual frameworks, each addressing the inherent challenges of protecting digital systems. Nic Seeley highlights this historical trajectory, beginning with an early emphasis on trust in the nascent days of computer security. This focus was largely driven by the imperative to secure classified information, where access was predicated on the trustworthiness of individuals. Consequently, early computer systems designed to handle such data were themselves viewed as "agents" that needed to be trusted. This led to extensive work in formal methods, aiming to build provably secure systems—an endeavor that proved immensely difficult to scale and implement practically.

As the field matured, the binary nature of trust—you either trust or you don't—was recognized as insufficient. This led to the development of the concept of trustworthiness, which exists on a spectrum. Rather than a simple yes/no, trustworthiness allowed for degrees of confidence, enabling systems and users to make more nuanced decisions about reliance. However, even this more granular approach proved challenging to operationalize effectively across complex and dynamic computing environments.

The contemporary landscape of cybersecurity research is heavily centered on risk. This paradigm acknowledges that perfect security is unattainable and that organizations must manage the likelihood and impact of potential threats. Risk assessment frameworks, threat modeling, and vulnerability management are all outgrowths of this focus. Seeley argues that this progression from trust to trustworthiness to risk is not merely historical but represents a logical and increasingly fundamental understanding of security. He contends that situations involving trust are, in fact, a subset of situations involving risk. Since risk is a broader concept that subsumes trust, it naturally emerges as a more fundamental principle in the hierarchy of cybersecurity concepts. This historical and conceptual evolution forms the bedrock of Seeley's argument for seeking an even deeper, more fundamental principle.

Key Findings

▶ Watch: Evolution of security research: Trust, trustworthiness, risk (2:50)

Nic Seeley's talk culminates in a series of key findings that challenge and redefine the foundational principles of cybersecurity. His primary contribution is the assertion that uncertainty is the most fundamental concept underlying all cybersecurity efforts, even more so than risk.

Firstly, Seeley proposes a definition of security that is both broad and deeply human-centric: security is the protection of meaning and value. He argues that we protect things because they hold value, and value, in turn, is derived from the meaning we ascribe to them. This definition shifts the focus from purely technical controls to the ultimate purpose of those controls—safeguarding what truly matters to individuals and organizations.

Secondly, he meticulously traces the conceptual progression in cybersecurity research:

  1. Trust: Initially, securing classified information on computers led to treating computers as entities that needed to be trusted, giving rise to formal methods aimed at provably secure systems.
  2. Trustworthiness: Recognizing the limitations of a binary trust model, the field evolved to view trustworthiness as a spectrum, allowing for more nuanced evaluations.
  3. Risk: The current dominant paradigm, risk, is identified as a more fundamental concept than trust. Seeley explains that situations involving trust are merely a subset of those involving risk. If something is certain, there's no need for trust. Therefore, risk is a broader, more encompassing concept.

Finally, and most crucially, Seeley posits that risk itself is not the most fundamental concept; uncertainty is. His argument is straightforward: if everything were completely certain, there would be no risk. The very existence of risk stems from a lack of complete knowledge or predictability about future events, system behaviors, or adversary actions. Without uncertainty, there would be no risk, and consequently, no need for trust. This elevates uncertainty to the foundational principle upon which the entire edifice of cybersecurity, risk management, and trust mechanisms is built. By identifying uncertainty as the bedrock, Seeley opens the door to exploring cybersecurity through a lens that might align more closely with physics-based problems, where inherent uncertainties and probabilistic outcomes are central to understanding system behavior.

Technical Deep Dive

▶ Watch: Defining security as protection of meaning and value (4:00)

While Nic Seeley's talk doesn't delve into specific code, protocols, or architectural designs in the traditional sense of a "technical deep dive," it offers a profound conceptual deep dive into the theoretical underpinnings of cybersecurity. His argument is structured as a logical progression, aiming to identify the most fundamental "physics-like" laws governing our discipline.

The journey begins with the observation that cybersecurity, despite being treated as an engineering discipline, often lacks a clear scientific foundation. Engineering, by definition, applies scientific principles to design and build. Seeley questions what those foundational scientific principles are for cybersecurity, suggesting we haven't yet discovered our equivalent of "F=MA." His hypothesis is that by understanding the root cause of security problems, we might uncover these foundational principles.

Seeley establishes the ultimate goal of security as the protection of meaning and value. This is a critical abstraction. Instead of focusing on protecting data integrity, confidentiality, or availability in isolation, he frames these as mechanisms to protect something more abstract and human-centric: the inherent meaning or value that data, systems, or processes hold for their stakeholders. This definition allows for a more universal framework, applicable across diverse contexts from national security to personal privacy.

The speaker then meticulously deconstructs the historical evolution of cybersecurity concepts to reveal their logical dependencies:

  1. Trust as the Initial Framework: In the early days, particularly with the advent of computers handling classified information, the concept of trust was paramount. The security model was inherently human-centric: if only trusted individuals could access classified documents, then computers processing such documents also needed to be "trusted agents." This led to the pursuit of provably secure systems through formal methods, where mathematical rigor was applied to demonstrate system integrity. However, the complexity of real-world systems quickly exposed the scalability limitations of this approach. Achieving perfect, provable trust in complex software and hardware proved intractable.
  1. From Binary Trust to Trustworthiness: Recognizing the impracticality of a binary "trust/no trust" model for dynamic systems, the concept evolved to trustworthiness. This introduced a spectrum of confidence. Instead of a simple boolean, trustworthiness allowed for degrees of assurance, enabling risk-based decisions on how much to rely on a system or component. A system might be deemed "highly trustworthy" for certain operations but not others, or "moderately trustworthy" based on its design, implementation, and operational history. This shift acknowledged the inherent imperfections and uncertainties in systems.
  1. Risk as a Broader Concept: The contemporary focus on risk management is seen as the next logical step. Seeley argues that situations involving trust are a subset of situations involving risk. If you trust a system, you are essentially assessing a low risk of malicious or erroneous behavior. Conversely, if you don't trust a system, you perceive a high risk. Risk, encompassing both the likelihood of an adverse event and its potential impact, provides a more comprehensive framework for decision-making. It moves beyond the internal state of a system (trust) to consider the external environment, potential threats, and their consequences. The field adopted methodologies like threat modeling and vulnerability assessment to quantify and manage these risks.
  1. Uncertainty as the Fundamental Principle: The most significant leap in Seeley's argument is that risk itself is not fundamental; uncertainty is. He states unequivocally: "If everything were certain, completely certain, there would be no risk." This is the core "physics-like" assertion. If we had perfect knowledge of all system states, all adversary capabilities, all environmental factors, and all future events, then there would be no unpredictability. Without unpredictability, every outcome would be known, and thus, there would be no "risk" in the sense of an unknown potential for loss. Consequently, if there's no risk, there's no need for trust or trustworthiness.

This chain of reasoning positions uncertainty as the ultimate root cause of all cybersecurity challenges and the need for security measures. It's not the presence of malicious actors alone, but the uncertainty surrounding their actions, capabilities, and timing, combined with the uncertainty about system vulnerabilities, human errors, and environmental conditions. This philosophical grounding suggests that any "scientific laws" of cybersecurity would inevitably deal with the management, quantification, and implications of uncertainty. Just as quantum mechanics deals with inherent uncertainties at a fundamental level of reality, Seeley implies cybersecurity might need its own framework for managing the inherent unpredictability of complex, interacting systems and intelligent adversaries. This perspective encourages a shift from seeking absolute, deterministic security to understanding and strategically managing probabilistic outcomes driven by fundamental uncertainty.

Demo / Proof of Concept

▶ Watch: Risk: a more fundamental concept than trust (5:00)

This theoretical and philosophical talk did not include a live demonstration or a proof of concept. The speaker's objective was to lay a conceptual foundation for understanding cybersecurity, rather than showcasing a specific tool, exploit, or system.

Defensive Implications

▶ Watch: Uncertainty as the fundamental basis for risk (6:00)

Nic Seeley's radical re-framing of cybersecurity as fundamentally rooted in uncertainty carries significant implications for defensive strategies, even without direct technical examples. If uncertainty is the bedrock upon which risk and trust are built, then effective defense must pivot from seeking absolute certainty—an impossible goal—to intelligently managing and reducing uncertainty.

Firstly, defenders should embrace probabilistic thinking rather than deterministic models. Instead of striving for 100% prevention or detection, which is unrealistic in a world of inherent uncertainty, security teams should focus on improving the probability of detection, the probability of successful prevention, and the probability of rapid recovery. This means shifting resources towards resilience and adaptability. Systems designed to tolerate and recover from compromise, rather than merely prevent it, become paramount. This includes implementing robust backup and recovery strategies, building fault-tolerant architectures, and practicing incident response extensively.

Secondly, the emphasis on uncertainty highlights the critical need for threat intelligence and contextual awareness. Reducing uncertainty about adversaries (their tactics, techniques, and procedures – TTPs), vulnerabilities (known and unknown), and the specific value of assets helps in making more informed risk decisions. Defenders should invest heavily in collecting, analyzing, and operationalizing threat intelligence to narrow the scope of the unknown. This includes proactive hunting, behavioral analytics, and leveraging frameworks like MITRE ATT&CK to map potential adversary actions against defensive capabilities, thus quantifying and reducing uncertainty about attack paths.

Thirdly, this perspective underscores the limitations of formal methods and provably secure systems in highly complex, evolving environments. While valuable for critical components, the inherent uncertainty introduced by human interaction, integration complexities, and novel attack vectors means that perfect security proofs often break down in practice. Defenders should adopt a defense-in-depth strategy that acknowledges the likelihood of control failures. This involves layering security mechanisms, assuming compromise, and continuously verifying the effectiveness of controls through penetration testing, red teaming, and continuous monitoring.

Finally, by defining security as the protection of meaning and value, defenders are prompted to align their efforts more closely with business objectives. Instead of merely securing "systems," the focus shifts to understanding what value those systems enable and what meaning their disruption would have. This helps prioritize defensive efforts based on the actual impact of uncertainty on critical business functions, intellectual property, or human safety. It encourages a more holistic view of security, where technical controls are means to an end, ultimately serving to preserve the organization's core mission in the face of pervasive uncertainty.

Key Takeaways

  • Cybersecurity lacks a clear scientific foundation: While treated as an engineering discipline, cybersecurity has yet to establish fundamental, physics-like laws similar to "F=MA."
  • Security is the protection of meaning and value: A broad, human-centric definition that frames cybersecurity's ultimate purpose beyond technical controls.
  • Conceptual progression: Trust → Trustworthiness → Risk: Cybersecurity research has evolved from binary trust to a spectrum of trustworthiness, culminating in risk as a broader, more fundamental concept.
  • Uncertainty is the most fundamental concept: Risk exists solely due to uncertainty. If everything were certain, there would be no risk and no need for trust, making uncertainty the bedrock of all cybersecurity challenges.
  • Embrace probabilistic thinking in defense: Given pervasive uncertainty, defenders should shift from seeking impossible absolute certainty to managing and reducing probabilities of compromise and impact.
  • Focus on resilience and adaptability: Strategies should prioritize systems designed to tolerate and recover from compromise, supported by robust threat intelligence and continuous validation of controls.

About the Speaker(s)

Nic Seeley is a researcher who, along with his colleagues, has been deeply exploring the fundamental questions surrounding cybersecurity. His work focuses on understanding the underlying beliefs and principles that drive the field. He has experience in computer security research, having previously expressed skepticism about a physics-based approach to cybersecurity, only to later come to believe in its potential validity and present on the topic. The talk indicates his engagement in long-term, abstract research aimed at grounding cybersecurity in more fundamental concepts.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

This isn't your typical technical deep dive, but it's a profound conceptual exploration that challenges the very foundations of cybersecurity. Seeley meticulously deconstructs our understanding from trust to risk, ultimately positing uncertainty as the bedrock principle. It's original, intellectually rigorous, and forces a re-evaluation of how we approach defense, moving us towards probabilistic thinking and resilience. This kind of foundational work is rare and essential for advancing the field beyond ad-hoc solutions.

Heather Calloway (CISO) — STRONG ACCEPT

Nic Seeley's presentation challenges the very foundation of cybersecurity, arguing that uncertainty, not risk or trust, is the bedrock principle. This conceptual reframing provides a critical lens for security leaders to re-evaluate how they govern risk, design programs, and communicate business exposure. By pushing beyond conventional wisdom, the talk offers a compelling argument for embracing probabilistic thinking and building resilience, moving the conversation from reactive measures to a more scientifically grounded, strategic approach to protecting organizational value.

→ Top-rated talks at S4x24 - ICS Security Conference

All talks from S4x24 - ICS Security Conference