Risk Models as Mediating Artifacts: A Postphenomenological Analysis of the CIIM Framework in Cybersecurity Practice
This paper uses postphenomenological theory to analyze the CIIM risk model, arguing that its mathematical design—specifically its treatment of systemic collapse—functions as a mediating artifact that reshapes how cybersecurity practitioners perceive threats and engage in ethical decision-making.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
The "Dashboard" Problem: Why Your Security Tools Might Be Lying to You
Imagine you are driving a car on a long, dark highway. You have a dashboard in front of you. Most of the time, it works fine: it tells you how fast you’re going and how much gas you have left.
But imagine if your dashboard was designed in a very strange way. It only tells you how fast you are going right now, but it refuses to tell you that you are heading straight for a cliff. Or, even worse, as you get closer to the edge, the speedometer starts "smoothing out" the numbers so that instead of showing you the terrifying drop-off, it just says, "You are going 60mph... 60mph... 60mph..." even as you fly into the abyss.
In this paper, Dr. Rommel Salas-Guerra argues that cybersecurity tools are doing exactly that to the people trying to protect our digital world.
1. The "Blindfold" of Current Tools
Most cybersecurity experts use a system called CVSS. Think of CVSS like a weather report that only tells you if it is raining at this exact second.
If a hacker finds a hole in a company's security, CVSS gives it a score (like a 9.8 out of 10). But that score is "blind" to three huge things:
- The Future: It doesn't tell you where the storm is heading; it only tells you the current raindrop.
- The Context: It treats a leak in a tiny garden hose the same way it treats a leak in a massive dam.
- The Breaking Point: It doesn't tell you how close the whole system is to collapsing.
Because these tools are "static," the people using them start to see the world in a flat, lifeless way. They aren't seeing a moving, breathing, dangerous environment; they are just looking at a list of numbers.
2. Enter the CIIM: The "Predictive Navigator"
The author introduces a new model called CIIM. If the old tools are a simple speedometer, CIIM is a high-tech GPS with a crystal ball.
Here is how CIIM changes the game:
- It looks at "t+1" (The Crystal Ball): Instead of saying "This is the risk now," it says, "Based on how things are moving, this is the risk you will face in the next moment." It turns the analyst from a person looking at a photo into a person watching a movie.
- It respects the "Cliff" (The Singularity): This is the most radical part. In most math models, if a number gets too close to zero (like a company's ability to defend itself), engineers use a trick to "smooth it out" so the computer doesn't crash. The author says this is a mistake! He argues that when a system is about to collapse, the math should "break" on purpose. It should scream, "Warning! We are hitting a wall!" rather than pretending everything is fine.
3. The "Brain" Inside the Machine (Machine Learning)
The CIIM doesn't just use math; it uses different types of Artificial Intelligence that act like different "senses":
- One part acts like Memory, looking at what happened in the past to predict the future.
- One part acts like a Judge, categorizing risks into "Low" or "Critical" so humans can make quick decisions.
- One part acts like a Strategist, suggesting the best way to fix a problem without spending too much money or breaking the company's workflow.
4. The Big Idea: The "Phenomenology of Collapse"
The author introduces a fancy term: "Phenomenology of Collapse."
In plain English, this means: We need tools that are honest about their own limits.
Most tools are designed to be "robust"—meaning they try to keep working even when things go wrong. But the author argues that this "robustness" actually hides the truth. If a tool is too "polite" to show you that the system is disintegrating, it is actually making you less safe. We need tools that "break" or "glitch" when the world is breaking, so that the human in charge realizes, "Wait, this isn't just a small problem; the whole world is changing right now."
The Bottom Line
The paper is a plea to the people who build security software: Stop building tools that just give us numbers. Start building tools that help us feel and understand the reality of the digital world we are living in. We don't just need better math; we need better "eyes."
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.