Is this fair to say? The defender’s dilemma or defender–attacker asymmetry in cybersecurity. The classic formulation is: The defender must protect every potential avenue of attack; the attacker only needs to find one successful avenue. Thoughts?
It’s also described as the asymmetry of cybersecurity/asymmetric advantage of attacker.
Modern security experts often criticize the literal “defender must be perfect, attacker only needs to succeed once” version, because defence in depth means one successful intrusion doesn’t necessarily equal a successful breach.
[link] [comments]