A short discussion on the need for a standardised reporting framework in cyber security, and how the lack both of a standard and of a willingness to report increases risk and uncertainty.
allow for good predictive models ▪ Good descriptions of attacks and incidents, reported effectively, let us start building forecasting models ▪ Forecasting models give us more accurate and testable predictions ▪ Testing our predictions lets us define how much uncertainty we have left, and improve our forecasting ▪ Cyber security weather forecasts would benefit everyone
verifiable reporting is needed to give us data Hiding incidents increases uncertainty for everyone We MUST get better at information sharing to benefit everyone