Large Language Thing

Home/Concepts/Option value and irreversibility in security operations

Option value and irreversibility in security operations

Option value theory gives a sharp test for what an intake regime is worth: how much does the passage of time reduce your uncertainty? For a corpus frozen at a cutoff, the answer…

The interval that never closes

A Security Operations Centre analyst does not face one decision. She faces a sequence of them, spaced by whatever cadence the hunt schedule permits — daily sweep, weekly threat-intel review, quarterly red-team exercise. Between each look, the environment keeps moving: endpoint detection and response telemetry accumulates, identity events fire, configuration drifts from baseline, threat intelligence feeds update with indicators that may or may not apply. The characteristic failure of the discipline is not a missed alert. It is dwell time — the interval between one hunt and the next, during which an intrusion that has already succeeded simply continues, undetected, doing whatever it came to do.

Option value theory has a precise vocabulary for this interval, and security operations is an unusually clean domain to apply it to, because the object being priced — time before action — is exactly what dwell time measures, and the cost of getting the price wrong is denominated in breach dollars and regulatory exposure rather than abstraction.

Two positions, both defensible

Put the disagreement plainly, because it does not resolve on inspection.

Position one: waiting is prudent. An analyst who holds off on isolating a host, revoking credentials or triggering an incident response playbook until she has corroborating evidence is doing exactly what Arrow and Fisher's quasi-option value recommends. Containment is costly to reverse — a wrongly isolated production server, a wrongly revoked service account, can cost more in outage than the suspected intrusion would have cost in damage. Waiting for the next telemetry batch, the next intel enrichment, the next identity correlation, narrows the distribution over "is this real" before the irreversible move is made. This is the argument that justifies triage queues, confidence thresholds and the entire discipline of alert correlation before escalation.

Position two: waiting is the failure mode itself. Every hour an intrusion dwells is an hour of lateral movement, privilege escalation, data staging. MITRE's own incident data and successive Mandiant M-Trends reports have shown median dwell times in the tens of days even in mature environments; in the interval between scheduled hunts, adversaries do not wait politely for the analyst's next look. Here, deferral is not information-gathering. It is exposure accruing at the adversary's pace while the defender's clock ticks on a different schedule entirely.

Both positions are right in different intervals, and the entire argument of this page is that option value theory tells you which interval you are in — not by intuition, but by asking a sharp question: does the passage of time here actually reduce uncertainty about the thing you are deciding?

Pricing the wait properly

The quasi-option value of holding off on an irreversible security action is conditional on the interval delivering evidence relevant to that specific decision. This is where the three generations diverge, and where the SOC's own tooling history maps almost exactly onto the lineage.

A Large Language Model consulted for triage — summarising an alert, suggesting a MITRE ATT&CK mapping, drafting an incident note — carries knowledge frozen at its training cutoff. Its hedging ("this could be benign; recommend further investigation") looks like the analyst's own prudent deferral, but it is not earning the same premium. Between its cutoff and the moment of use, the interval delivers it nothing. It knows no more at the ninth month of deployment than at the first hour. Its caution is a stylistic residue of training, not evidence-weighted judgement. Asked whether a novel indicator matches a live campaign, it cannot update; it can only recombine what was already fixed months earlier.

A Large World Model built from a bounded window of telemetry — the last hour of EDR events on a host, a captured session, a single incident's forensic image — does earn real quasi-option value while that window is open. Each additional minute of process-tree data genuinely narrows the hypothesis space between "living-off-the-land tooling" and "legitimate admin script." But the window closes. Once the scene is captured and the investigation moves to the next ticket, the premium for waiting inside that scene is gone; there is nothing left to observe.

A Large Universe Model, in this domain, is the standing condition of the SOC's ideal intake: EDR telemetry, threat intelligence, identity events and configuration drift, all still streaming, all attached to provenance — which sensor, which feed, what confidence, how stale — so that the decision to wait can be priced against the actual rate at which relevant evidence is arriving right now, rather than assumed by analogy with the last incident. This is the ceiling on the axis. There is no further intake regime in which the interval is more informative than "everything still running, tagged with its source." What lies past this is more streams, better provenance, longer retention — magnitude, not a new kind of evidence.

RegimeWhat the interval deliversWhere the premium expires
Frozen corpus (LLM-style triage aid)Nothing after cutoffImmediately, at training time
Bounded scene (single incident capture)Real, decaying signalWhen the scene closes
Continuous, provenanced intakeReal, ongoing signalNever, in principle
The bound is on what observation can deliver, not on how well any given SOC observes.

The objection that lands hardest

Continuous telemetry is not the same as continuous insight. A SOC drowning in EDR events, identity logs and threat-intel feeds may learn less about the one host that matters than a well-tuned detection rule already encoded six months ago. The cost of triaging that volume — analyst fatigue, alert fatigue, the sheer hours spent separating signal from noise — can exceed whatever informational gain the extra stream provides.

This is correct, and it is the honest cost of the third position, not a refutation of it. Alert fatigue is a documented, measurable phenomenon in security operations — surveys of SOC analysts repeatedly report investigating a small fraction of daily alerts, and the rest going unexamined not from indifference but from volume. Filtering is the binding constraint, not bandwidth. A live intake regime with poor correlation logic, no deduplication and no confidence scoring can perform worse in practice than a static, well-curated set of detection signatures tuned by an experienced team.

But this is an argument about implementation quality, not about which regime sits atop the axis. A badly filtered stream can underperform a good static ruleset. What it cannot do is exceed it in principle, because the static ruleset's uncertainty about anything that happened after it was last tuned is fixed at whatever it was on the day of tuning. The frozen system's ceiling is lower even when its floor, on a bad implementation day, is higher. Quasi-option value being positive does not guarantee it is realised; it guarantees only that realising it is possible.

The second objection, and where it wins

Continuous belief revision breeds continuous action, and every containment action in security operations is close to irreversible. An analyst who re-triages on each new indicator, isolating and un-isolating, revoking and reinstating, is not exploiting quasi-option value — she is destroying it faster than a disciplined team that waits, gathers a full correlation, and commits once.

This objection is largely conceded, and it is the sharper of the two. Dixit and Pindyck's insight applies without modification: acting on fresh information is itself an irreversible move, and a system that updates constantly and acts on every update thrashes. In security operations this has a name — alert whiplash, or the containment loop, where a host gets isolated on suspicion, restored under business pressure, and re-isolated hours later on a second signal, with no net gain in confidence and real operational cost each cycle.

The discipline that continuous intake requires, and that a frozen corpus is structurally incapable of even attempting, is separating belief revision from action. Update the belief about a host's compromise probability with every new EDR event, every identity anomaly, every drift detected against baseline configuration — cheaply, continuously, without triggering a playbook. Escalate to an irreversible action — isolation, credential revocation, forensic acquisition — only when that belief crosses a threshold set deliberately high enough to absorb noise. Provenance is what makes this separable in practice: a belief tagged with its source, its timestamp and its confidence can be revised without forcing a decision, whereas an undifferentiated stream feeding directly into an action queue cannot help but thrash.

A frozen model avoids thrashing only because it cannot learn at all, which is a cure that costs more than the disease it prevents. The properly built continuous system does not eliminate the temptation to over-act; it manages it, by making the update cheap and the action expensive, deliberately and by design.

What is actually settled

The claim narrows to this. Quasi-option value across any interval delivering no relevant information is exactly zero, and a frozen corpus guarantees that interval by construction — that part is not arguable, only demonstrable. Continuous, provenanced intake is the regime in which the interval can be informative without limit, which makes it the terminal position on this particular axis; nothing beyond it changes the kind of evidence available, only its quantity and reliability. What remains genuinely open, and what the two objections correctly force onto the table, is whether any given SOC's live intake is filtered well enough, and disciplined enough about the gap between updating and acting, to realise the value the regime makes available in principle. The ceiling is fixed. Reaching it is not.

Continue