Where does threat modeling's rational cost-versus-gain assumption about attackers break down?
answer
- the model assumes a buyer with a budget
- some payoffs are not denominated in money
- someone else can fund the attempt
- near-zero cost clears any gain
- test becomes: holds under unbounded effort
basics
~20 sCost-versus-gain reasoning only describes an attacker spending their own budget for profit. It fails when the payoff is personal, when a third party funds the attack to impose loss on you, and when per-target cost is near zero.
solid answer
~50 sThe model assumes an attacker who prices an attempt against what a success is worth to them, and walks away when it stops paying. Three cases break it. First, non-economic motive: someone pursuing one specific person's location data on a fitness-tracking app will spend unbounded effort for zero revenue, so every price you set is a price they pay. Second, the funded saboteur — a competitor paying to take a ticketing platform down during a rival's on-sale window — whose gain is denominated in your loss and whose costs are someone else's money. Third, sunk or near-zero cost: indiscriminate scanning makes any nonzero payoff worth it, which is why "there is no money in attacking us" is unsafe. For those threats the acceptance test changes from a price to whether the control holds under unbounded effort.
go deeper
Know that the cost-versus-gain rule describes a money-motivated attacker, and that some attackers are not motivated by money at all. Avoid saying a system is safe because it holds nothing valuable.
Be able to name the breakdown cases and explain why the two usual levers, raising cost and devaluing proceeds, do nothing against a personally motivated attacker or a funded saboteur.
Demonstrate the switch in acceptance test: for these threats you argue from capability and consequence, choose data minimisation and defaults over friction, and design assuming the attempt lands at the worst moment.
Own the policy that decides which threats are exempt from economic triage across the organisation, and defend the cost of protecting a small number of threats that no cost-benefit calculation would justify.
## What the assumption actually says Cost-versus-gain reasoning models an attacker who is *economically rational*: they hold a budget, they price an attempt, they compare it to what a success is worth to them, and they walk away when the numbers stop working. Under that model a control is judged by the price it sets. The assumption is a good one for most volume crime, and it is the reason friction, rate limits, devalued loot and fast clawback are effective at all. It is still an assumption, and a threat model that never states it will quietly apply it to attackers it does not describe. There are four recognisable ways it breaks. ## 1. The gain is not denominated in money Consider a fitness-tracking social app with route sharing and a followers graph. One user wants one specific other user's location history, and that person is an acquaintance with a legitimate account. There is no resale market and no revenue; the payoff is personal, and the effort budget is whatever the person is willing to spend, which can be effectively unbounded. Every price you set is a price they will pay. Worse, the asset is not a data record whose loss you can absorb — it is where someone sleeps, and the consequence is physical safety. For this threat "we made it expensive" is not an answer. The controls that hold are the ones that do not depend on effort: not collecting or not retaining precise location, coarsening it by default, never exposing exact start points, defaulting sharing to closed rather than open, making the audience of every field explicit and revocable, and giving the victim a way to sever a follower's access completely. Notice these are data-minimisation and default choices, not friction — the attacker with legitimate access cannot be priced out, so you remove the data they would obtain. ## 2. Someone else pays the bill, and your loss is the payoff A competitor-funded actor wants a ticketing platform unavailable during a rival's on-sale window. The gain here is denominated in *your* loss: the value of the attack is the revenue and reputation you do not get, which is a number you can compute and the attacker cannot capture. There is no theft to devalue and no proceeds to claw back, so the two normal levers are both inert. The attacker's cost is also not theirs — it is funded, so raising it spends someone else's money. What survives is capability-and-consequence reasoning: assume the attempt happens at the worst possible moment, and ask what the platform does under it. That points at capacity headroom, shedding load gracefully, keeping the queueing path independent of the paying path, and having a practised response for the specific window rather than a control that hopes to deter. ## 3. Cost is already sunk, or rounded to zero Indiscriminate automated scanning has a per-target cost that rounds to nothing: the tooling was written once, the infrastructure is often already compromised and free to the operator, and the marginal cost of adding your host to the sweep is a packet. When cost is approximately zero, *any* nonzero gain clears the bar — a host to relay from, a bit of compute, a credential to test elsewhere. This is the reasoning error behind "there is no money in attacking us, so nobody will bother." Low value does not protect you when the price of finding out is nothing. ## 4. The attack is its own reward Ideological actors, people demonstrating a capability, and insiders acting out of grievance all generate gain that never appears on a balance sheet. The same treatment applies: the deterrent is consequence and detection, not price. ## How to handle it in the model Do not throw the economics away — most of your threat list still obeys it. Instead mark the ones that do not, and change the acceptance test for those: | Economically rational threat | Non-economic threat | | --- | --- | | Test: cost per attempt above realisable gain | Test: control holds under unbounded effort | | Levers: raise friction, devalue proceeds | Levers: remove the data, hard invariants, isolation | | Detection reduces retained gain | Detection buys response time and evidence | | Residual exposure is a price | Residual exposure is a consequence you must survive | The cheapest tell at design-review time is the **asset**, not the attacker. If the harm is physical safety, silencing someone, personal privacy, or a rival's loss, the payoff is not the attacker's revenue and pricing is the wrong instrument. If the harm is money or resaleable data, economics is usually the right instrument and the pricing conversation is the productive one. The failure mode this prevents is the most expensive one available in threat modeling: a team correctly reasons that an attack is not worth an attacker's while, deprioritises it, and finds out that the one attacker who matters was never doing arithmetic.
- At design-review time, how do you spot a threat that needs the non-economic treatment?Look at the asset rather than the attacker. If the harm is physical safety, personal privacy, silencing someone, or a rival's commercial loss, the payoff is not the attacker's revenue and pricing is the wrong instrument. Any feature that ties an account to a real location, a real identity, or a time-critical revenue window deserves that second read before you deprioritise its threats on cost grounds.
- Does economics still tell you anything useful about these attackers?Some. You can still add time and legal exposure, and detection still matters — but its value shifts from shrinking the attacker's retained gain to buying response time and evidence. What changes is the acceptance test: instead of a price above the payoff you need controls that hold regardless of effort, which in practice means not holding the data, hard invariants, isolation, and a practised response.
- Why is "we're too small and boring to be a target" a dangerous conclusion?It assumes gain means money and that the attacker pays real per-target costs. Indiscriminate automation costs almost nothing per host, so any nonzero payoff — relay capacity, compute, a credential to try elsewhere — clears the bar. And a saboteur's payoff is your loss, which every organisation has regardless of how interesting its data is.
saying these in an interview costs you the question
- Assumes every attacker weighs cost against their own financial gain
- Concludes low asset value means nobody will attack the system
- Treats a stalker or saboteur as just a low-likelihood variant
- Prices deterrence for an attacker whose costs are already sunk
- Answers a personal-safety threat with added friction