A few observations. Make of them what you will.
Basic fraud is still 100x larger of a problem than the more exotic/interesting cybersecurity problems. Former Facebook CSO Alex Stamos had a convention talk[1] about this. The average cybersecurity problem is still of the template like:
- Nigerian 419 scam (or similar social media fake account used to pull heartstrings)
- Romanian spam email e-commerce
- 12 year old boy steals parents credit card info to pay for $100s in Fortnite (or similar vidya game) customizations
- 15 year old girl is convinced to give her website credentials to her friend for fear of social reprisals
- Harvesting of contact info + Open Source Intelligence for more traditional phone scams
There is an arms race in just about every aspect of cybersecurity:
- Detection of fraud versus bypass
- IDS/WAF attack signatures
- Email spam filters
- Endpoint malware detection signatures
- Behavior detection (like conditional challenges via ReCaptcha or for Google authentication)
- Math+security researchers try hard to break cryptographic hash schemes (using techniques more efficient than just brute force)
Game theory is a large part of cybersecurity, because it's largely a human endeavor (even if it's executed by software/bots). The paid bug bounty programs are an interesting exercise in economics and markets (as a bug bounty hunter how they choose a target from all of the possible companies that participate in bug bounty programs).
Cybersecurity is an asymmetric game, as it is currently set up. The attacker "only has to be right once", whereas the defender "has to be right all the time". IT teams "think in lists", whereas hackers "think in graphs".
It's easier than ever to automate security and updates, but increasingly it takes more and more cognitive effort to set up those systems (which inevitably slow down business) so the long-term-optimal is frequently abandoned for the short term convenience.
The massive explosion of social media in the past 10 years could have compromised OpsSec for an entire generation of computer operators. When we post credit card details on Twitter[2], it's clear that the average person needs to have better OpsSec.
OpsSec is bad even when not on social media, as shown when hackers saw account credentials on a desk in the background of a television interview[3]. Kids are conditioned by their parents to share their passwords, then develop the bad habit of sharing passwords as a sign of affection for their social peers[4].
AI/ML and Quantum Computing have the potential to cause a massive shift in the current attack/defense posture and current security practices, but when it might show up in practical applications is anyone's guess.
There are legal+policy questions about whether we should try and entrust secret keys to all smart devices to the manufacturer, police, or intelligence services. Even among the Five Eyes countries, the answers to these questions are currently in very different places.
[1] https://youtu.be/YJOMTAREFtY?t=1099
[2] https://twitter.com/Needadebitcard
[3] https://arstechnica.com/information-technology/2015/04/hacke...
[4] https://www.nytimes.com/2012/01/18/us/teenagers-sharing-pass...