Applying Public Health Systematic Approaches to Cybersecurity: The Economics of Collective Defense
This paper argues that cybersecurity suffers from market failures similar to those historically addressed by public health systems and proposes the establishment of a national Cyber Public Health System to enable coordinated, evidence-based defense through standardized data, measurement, and government intervention.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine the United States in the year 1900. Life was short, and diseases like cholera and smallpox were rampant. Doctors were guessing about what caused sickness, blaming "bad air" or "miasma." They didn't have a system to count how many people were sick, where the germs were spreading, or which treatments actually worked. It was a chaotic, reactive mess.
Then, something changed. Scientists started mapping outbreaks (like the famous story of John Snow and the London water pump), they started counting cases, and they realized that clean water and vaccines didn't just help one person—they helped the whole neighborhood. The government stepped in to build a Public Health System. They created rules, collected data, and coordinated responses. The result? We now live 30 years longer than our great-grandparents did.
The authors of this paper, Josiah Dykstra and William Yurcik, are asking a simple but profound question:
"If we could organize our fight against germs to save millions of lives, why aren't we doing the same thing to fight computer hackers?"
Here is the breakdown of their argument using simple analogies:
1. The Problem: We Are Flying Blind
Right now, cybersecurity is like a doctor trying to treat a patient without a thermometer, a blood test, or a map of the virus.
- We don't know the "Population": In public health, we know exactly how many people live in a city. In cybersecurity, we don't even know how many "cyber citizens" (devices, users, networks) exist or who is most at risk.
- We don't have a "Ruler": We can't measure if we are getting safer. We don't know how many data breaches actually happened last year because companies hide them or count them differently. It's like trying to lose weight without a scale; you just guess.
- We don't know how the "Virus" spreads: Doctors know that flu spreads through coughs and colds spread through water. Cybersecurity experts are still guessing how malware jumps from one computer to another. Is it a bad email? A weak password? A supply chain? We are fighting in the dark.
2. The Economic Trap: The "Free Rider" Problem
This is the most important part of the paper. The authors explain that cybersecurity is a Public Good, just like a lighthouse or a clean park.
The Analogy:
Imagine a neighborhood where everyone has to pay to build a giant fence to keep burglars out.
- If Neighbor A builds a super-strong fence, the burglars might get scared off and move to the next street. Neighbor A paid for the fence, but Neighbor B (who didn't pay) also got safer.
- Because Neighbor B gets the benefit without paying, they have no reason to build their own fence.
- Eventually, nobody builds a fence because everyone is waiting for someone else to pay first. The neighborhood stays unsafe.
In Cybersecurity:
When a company spends millions to stop hackers, it makes the whole internet safer. But that company can't charge everyone else for that safety. So, companies only spend enough to protect themselves, not enough to protect the whole system. The market fails to provide enough security because the "benefits" spill over to everyone else for free.
3. The Solution: A "Cyber Public Health System"
The paper argues that we need the government to step in, just like they did with public health in the 1900s. We need a National Cyber Public Health System.
Here is what that would look like in everyday terms:
- The "Census Bureau" for Hackers: Instead of guessing, the government would create a standard way to count every cyber attack, every vulnerability, and every defender. We would finally know the "body count" of our digital world.
- The "Vaccine Trials" for Software: Just as we test vaccines rigorously before giving them to kids, we would test security tools to see if they actually work before we tell everyone to use them.
- The "CDC" for Cyber: We need a central agency (like the Centers for Disease Control) that collects all the data, spots the trends (e.g., "Hey, a new virus is spreading through email!"), and tells everyone how to stop it immediately.
- The "Herd Immunity" Strategy: Just as vaccines protect people who can't get vaccinated, strong security in one part of the internet protects everyone else. The government would fund the "vaccines" (security research and infrastructure) that private companies won't pay for because they can't make a profit on them.
Why This Matters
The authors point out that unlike human bodies, computers can be fixed. If a computer gets a virus, you can wipe it clean and start over. This is a superpower public health doesn't have. It means we can run experiments, learn from mistakes, and fix things quickly.
The Bottom Line:
We are currently fighting a war against hackers with a patchwork of individual efforts, no central map, and no way to measure if we are winning. The paper suggests that by borrowing the playbook from public health—collecting data, standardizing rules, and coordinating a national response—we could stop guessing and start actually winning the war for our digital safety.
It's time to stop treating cybersecurity like a private IT problem and start treating it like a national health crisis that requires a coordinated, evidence-based solution.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.