Research & Articles

Sharing what the data shows us.

Michael Roytman Michael Roytman

For Good Measure: Remember the Recall

We exist in a dualstage testing regime. We are subject to a low prevalence (rare event) environment. To act rationally in this scenario, the first test must remove as many false negatives as it can.

Read More
Jay Jacobs Jay Jacobs

Exploring with a Purpose

We have the better, if harder, problem of the meta-analysis (“research about research”) of many observations, always remembering that the purpose of security metrics is decision support.

Read More
Michael Roytman Michael Roytman

Measuring vs. Modelling

Using CVSS to steer remediation is nuts, ineffective, deeply diseconomic, and knee jerk; given the availability of data it is also passé, which we will now demonstrate.

Read More