
In 1902, French colonial administrators in Hanoi discovered rats swarming the city's newly built sewer system. Alarmed by the public health risk, they launched a bounty program: locals would be paid for every rat tail they turned in.
At first, the numbers looked great. Thousands of tails poured in. But city officials started noticing something strange: rats were still everywhere. Then reports came in that people were breeding rats. Others clipped the tails and released the rats back into the wild, free to breed and be harvested again. Some even smuggled rats in from outside the city just to cash in.

The bounty created the illusion of progress while making the problem worse. It was a textbook case of perverse incentives, where the rewards encouraged the very thing the program was meant to stop.
Perverse Incentives in Cyber Risk
Maybe five years ago, I would’ve told you that cyber risk quantification was on the brink of going mainstream. Leaders were waking up to the flaws in traditional methods. Standards bodies were paying attention. Things felt like they were moving.
Now I’m not so sure.
The deeper I go into this field, the more I see how powerful the gravitational pull is to keep things exactly the way they are. It turns out that cybersecurity is riddled with perverse incentives, and they’re built into the system itself. Nearly 25 years ago, Ross Anderson made this point in his classic paper Why Information Security Is Hard, arguing that cybersecurity is a microeconomics problem as much as a technology problem. Incentives between users, vendors, insurers, consultants, and regulators are often misaligned, which makes building secure systems even harder. When the people making security decisions aren’t the ones who bear the consequences, we all suffer.
Cyber risk management today is our own version of the Hanoi rat bounty. On paper, it looks like we’re making progress: reports filed, audits passed, standards met. Beneath the surface, it's a system that rewards activity more than outcomes, and it keeps itself going without improving.
The Risk Ecosystem Is Built on Circular Incentives

Companies start with good intentions. They look to frameworks like NIST CSF, ISO/IEC 27001, or COBIT to shape their security programs. These standards often include language about how risk should be managed, but stop short of prescribing any particular model. That flexibility is by design: it makes the standards widely applicable. But it also leaves just enough latitude for organizations to build the easiest, cheapest, least rigorous version of a risk management program and still check the box.
So boards and executives give the directive: “Get a SOC 2,” or “Get us ISO certified.” That becomes the mission. The mission, among many other things, includes an end-to-end cyber risk management program.
Enter the consulting firms, often the Big Four. One comes in to help build the program. Another comes in to audit it. Technically, they’re separate firms. But functionally, they’re reading from the same playbook. Their job is to get you the report. The frameworks they implement are optimized for speed, defensibility, and auditability, and insight, accuracy, and risk reduction come second.
So we get the usual deliverables, such as heat maps, red/yellow/green scoring, and high/medium/low labels, in programs built for repeatability.
The heatmap has become the de facto language of risk. The standards don’t demand more and the auditors don’t ask for more, so nobody builds more.
Where the Loop Starts to Break
Things start to wobble because the same ecosystem that builds your program is also judging whether you’ve done it “right.” Even if it’s not the same firm doing both, the templates, language, and expectations are virtually identical.
It's like asking a student to take a test, but also letting them write the questions, choose the answers, and let their buddy grade it. They’ll make the easiest test that still counts as a win.

The programs are often built to meet the bare minimum, the lowest common denominator of what’s needed to pass the audit that everyone knows is coming. The people involved usually mean well, and the system rewards efficiency, defensibility, and status-quo deliverables.
The goal becomes checking the box.
So we get frameworks with tidy charts and generic scoring systems that fit nicely on a slide deck and are designed to look like we’re managing risk.
These programs satisfy auditors, regulators, and boards, so nobody asks the hard question: “Is this helping us reduce real-world risk?”
The Rat Tail Economy
NIST, ISO, and similar frameworks are foundational. But when the same firms design the implementation and define the audit, and when the frameworks are optimized for speed rather than depth, you get a system that’s highly efficient at sustaining itself and deeply ineffective at solving the problem it was created to address.
It’s a rat tail economy, where we count the symbols of progress while the real risks keep breeding in the shadows.
A Word for Teams Still Using Heat Maps
If you’re working in a company that relies on qualitative assessments, such as heat maps and color scores, and you feel like you should be doing more, take a breath.
Plenty of good analysts are in the same spot.
The pressure to maintain the status quo is enormous, and you’re surrounded by it. Most organizations are content with a system that satisfies auditors and makes execs feel covered.
But that doesn’t mean it’s working.
The result is a system that:
- Measures what’s easy to measure
- Prioritizes passing audits over reducing real risk
- Funnels resources into checklists
- Incentivizes doing just enough to comply, but never more
So How Do We Stop Being Rat Catchers?
We probably won’t fix the whole system overnight, but we can start acting differently inside it.
We can build toward something better, even if we have to work within its constraints for now.
A few years ago, a friend vented to me about how their board only cared about audit results. “They don’t even read my risk reports,” he said.
I asked what the reports looked like.
“Mostly red-yellow-green charts,” he admitted.
That’s when it clicked for me that the first step is giving the board something worth caring about.
So start there:
- Take baby steps. Meet your compliance obligations, but begin quantifying real risks in parallel. Use dollar-value estimates, likelihoods, and impact scenarios. Start small and pick one or two meaningful areas.
- Translate risk into decisions. Show how quantified information can justify spending, prioritize controls, or reduce uncertainty in a way that matters to the business.
- Tell better stories. Frame your findings around real-world impact, trade-offs, and possible futures, and use charts to support them.
- Push gently. When working with auditors or consultants, ask: “What would it look like if we wanted to measure risk more rigorously?” Plant the seed.
We can’t tear down the bounty system in a day, but we don’t have to breed more rats, either. We can step outside the loop, see it for what it is, and try something different.
Leave a Reply