Why 99 Percent Can Be Deceptive

Bayes Instead of Gut Feelings


Bayes Instead of Gut Feelings: Why 99 Percent Can Be Deceptive Comment

"Our system detects 99 percent of all attacks", announces the head of IT security. The CFO nods with relief: "So does that mean an alarm is a real attack 99 percent of the time?" Unfortunately, no. In our example, the figure is just 50 percent. The software isn't defective. It's just the conclusion that needs an update.

Suppose that out of 10,000 login attempts, 100 are actually attacks. The system detects 99 percent of them—that is, 99. At the same time, it falsely triggers an alarm for one percent of the 9,900 harmless attempts: another 99 alarms. Out of a total of 198 alarms, therefore, only 99 are genuine attacks. The probability we're looking for is 50 percent, not 99 percent. Anyone who confuses the detection rate with the attack probability after an alarm ignores the base rate of attacks. This base rate problem has been scientifically described in the context of attack detection (see Axelsson 2000).

Bayes: Learning Instead of Being Right

Bayes' theorem provides the appropriate calculation formula:
P(attack | alarm) = P(alarm | attack) × P(attack) / P(alarm)

In the example, P(attack) = 1%, P(alarm | attack) = 99%, and P(alarm | no attack) = 1%.

Thus, P(alarm) = 0.99 × 0.01 + 0.01 × 0.99 = 1.98%.

According to Bayes, P(Attack | Alarm) = 0.99 × 0.01 / 0.0198 = 50%.

The system's high hit rate should therefore not be confused with the probability that a specific alarm actually indicates an attack.

Bayesian statistics turns this into a principle of learning: prior knowledge is formulated as a prior distribution. This prior knowledge can be derived from previous observations and documented expert estimates. The likelihood describes how probable the observed data are given the respective assumptions. Together, these yield the posterior distribution—that is, the updated state of knowledge. New evidence can increase or decrease a risk assessment. Changing one's own opinion is not a loss of face here, but rather an integral part of the method [see Romeike / Wieczorek 2026, p. 460]. 

Cyber risks rarely occur in isolation

When it comes to cyber risks, however, a single probability does not go very far. A Bayesian network describes multiple uncertain variables and their assumed dependencies: nodes represent variables, and directed arrows connect them. Directed circles are excluded. Conditional probabilities are assigned to nodes with direct predecessors, while unconditional probabilities are assigned to root nodes. Romeike and Wieczorek discuss these models in "Data Analytics in Risk Management" (2026) as a tool of predictive analytics. 

Practical Example: Ransomware in a Manufacturing Company

Suppose the security team at a manufacturing company receives a credible report of a credential leak involving a privileged VPN account. At the same time, no phishing-resistant multi-factor authentication is active for this account. In this deliberately illustrative model, this increases the probability that the privileged account is actually compromised from an assumed prior probability of 6% to a posterior probability of 35%. This example illustrates the core principle of Bayesian updating: New evidence modifies our state of knowledge; it does not replace it.

However, the potential attack path does not end with the account takeover. The EDR system isolates the affected endpoint within 15 minutes, and network segmentation isolates critical production zones. Under these model assumptions, the posterior probability of lateral movement is still 9.4%. In this example, this translates to a 3.5% probability of an admin or backup account being compromised and a 4.4% probability of a successful ransomware deployment. The protective measures thus take effect at different points along the attack path.

Risk management becomes particularly interesting when technical events are linked to their consequences. The model yields a 3.3% probability of a production outage. A successfully tested immutable backup subsequently reduces the modeled probability of an outage lasting more than 24 hours to 0.5%. For a financial loss of more than €1 million, the example yields a posterior probability of 0.46%. In a comparative scenario with the same initial evidence but without effective EDR isolation, segmentation, and immutable backups, this value is approximately 3.36%.

Figure: Illustrative Bayesian network for a real-world ransomware scenario. The percentages are model parameters for illustrative purposes and are not empirical cyber risk benchmarks.Figure: Illustrative Bayesian network for a real-world ransomware scenario. The percentages are model parameters for illustrative purposes and are not empirical cyber risk benchmarks.

From the Attack Path to the Distribution of Damage

This real-world example demonstrates why a mere probability of compromise is insufficient for corporate risk management. A Bayesian network can integrate technical states, control effectiveness, and business consequences into a consistent risk profile. To do so, the reference period and financial impacts must be explicitly modeled—such as recovery costs, business interruption, contractual penalties, or lost contribution margins. Links between attack paths and financial consequences are also being investigated in research on Bayesian attack graphs (see Zhang, Xu, and Zhao 2025).

It is not just the expected value that matters. Two scenarios can have the same average loss yet still exhibit very different extreme risks. For cyber risks, therefore, exceedance probabilities, quantiles, and severe, rare loss sequences are also relevant. The Bayesian network provides the conditional probabilities for this; the financial loss distribution must be supplemented as appropriate for the specific use case.

On this basis, measures can be compared: What impact does phishing-resistant MFA have? To what extent does segmentation reduce the probability of lateral movement? How does a tested recovery plan influence downtime and, consequently, the financial loss distribution? Such a model can translate technical security information into a language that is compatible with risk management, budgeting, and management decisions.

No Oracle with Decimal Places

However, an arrow does not prove causation. Anyone seeking to deduce the effect of a protective measure from a model needs well-founded causal assumptions. "We observe less damage in companies with this measure" is not automatically equivalent to "This measure causes less damage." Observation and intervention are distinct issues. (see Pearl 2009).

Nor does Bayes transform poor input data into sound insights. Assumptions should be documented, estimation uncertainty should be disclosed, and results should be tested against new observations and sensitivity analyses. The goal is not the most impressive decimal place, but a transparent decision made under uncertainty.

Bibliography and Further Reading

  • Romeike, Frank / Wieczorek, Gabriele (2026): Data Analytics in Risk Management – Descriptive Analytics – Diagnostic Analytics – Predictive Analytics. Springer Gabler, Wiesbaden. DOI: 10.1007/978-3-658-48843-7
  • Zhang, Xiaoyu / Xu, Maochao / Zhao, Peng (2025): Pricing Cyber Risks Over Modern Networks via Bayesian Attack Graphs. Variance, 18. DOI: 10.66573/001c.133952
  • Axelsson, Stefan (2000): The Base-Rate Fallacy and the Difficulty of Intrusion Detection. ACM Transactions on Information and System Security, 3(3), pp. 186–205. DOI: 10.1145/357830.357849.
  • Pearl, Judea (2009): Causal Inference in Statistics: An Overview. Statistics Surveys, 3, pp. 96–146. DOI: 10.1214/09-SS057.

 

[ Source of cover photo: Generated with AI ]
Risk Academy

The seminars of the RiskAcademy® focus on methods and instruments for evolutionary and revolutionary ways in risk management.

More Information
Newsletter

The newsletter RiskNEWS informs about developments in risk management, current book publications as well as events.

Register now
Solution provider

Are you looking for a software solution or a service provider in the field of risk management, GRC, ICS or ISMS?

Find a solution provider
Ihre Daten werden selbstverständlich vertraulich behandelt und nicht an Dritte weitergegeben. Weitere Informationen finden Sie in unseren Datenschutzbestimmungen.