What can cybersecurity learn from biosecurity?
It takes more than chicken soup
NB: I will be traveling for a couple of weeks without access to a keyboard, so it’s unlikely I’ll post any new pieces for a bit. I think this piece needs a follow up on cybersecurity norms.
The Bulletin of the Atomic Scientists (BoAS) published an interesting piece the other day, “What can biosecurity learn from cybersecurity? A lot.” Part of why it struck me is that I’ve always thought about this from the opposite direction. Having spent a fair amount of time on a campus biosafety committee, I’ve been struck by the lessons we could learn from how biosafety is managed in a large environment as we try to figure out how to scale up our own support for research. With multiple labs, specialized equipment and HVAC requirements - not to mention, you know, Ebola - it seems like our own support and compliance models could borrow a lot from it.
I really can’t recommend strongly enough that if your organization deals with biosafety issues1, you reach out to the good people overseeing it and ask to participate. If nothing else you can point out that a successful cyberattack could result in those overpressure blowers failing, allowing disease-carrying mosquitoes to escape. You’ll find they have rigorous (and audited) protocols for everything from incident reporting and handling, to training and standards compliance, all issues you’re probably facing in your cyber domain2.
As I read through the BoAS piece, it surfaces several non-obvious lessons for cybersecurity—particularly as it matures into a domain with societal, not just technical, consequences. Viewed through the lens of institutional practice, several of the article’s arguments take on a different emphasis.
First, norms have both power and limits. It’s striking how a web of treaties, arms control, and international agreements surround the world of bioweapons. Of course, none of these were established until after these weapons were put into place. Cybersecurity, on the other hand, seems unable to establish equally durable norms around state behavior and acceptable use.
The lesson here is that norm-building matters, despite the imperfect and difficult nature of enforcement. The shared expectations that become established, such as “don’t target hospitals” do shape behavior and beliefs. Yet for us in cybersecurity there seems to be little or no equivalent to the bioweapons paradigm (or kinetic weapons for that matter). The article’s implication here is that biosecurity demonstrates that norms built for discrete visible threats can become misaligned when risk is diffuse and systemic; surely this is a line we walk regularly as cyber practitioners. Nevertheless, I find this framing valuable to reflect upon.
For me, the implication is that cyber should be investing in international norms, but design them for continuous, ambiguous activity, not just “red line” events.
Second, as the BoAS piece points out, biosecurity remains heavily anchored to the weapons paradigm (which it says is inherited from nuclear strategy). Cybersecurity has largely (though not entirely) moved past this. Instead, as the article argues, we focus on the dimensions of capabilities, access, vulnerabilities, and effects, which are many of the core dimensions of the classic TARA (Threat Agent Risk Analysis) model. If there’s a takeaway here, it’s that we need to preserve this capabilities-based approach, and resist drifting into rigid categories (e.g., “nation-state vs criminal”) which can become limiting. That is we should maintain a capabilities-and-effects lens, and resist re-simplifying threats into overly discrete categories as our field matures.
Third, I was particularly interested in the discussion of how to tier risks. Biosecurity tends to oscillate between catastrophic scenarios (i.e., bioweapons) and benign research. Consequently, the article highlights intermediate risks, such as lab accidents, misuse of common tools, and the erosion of norms. This struck me because we cybersecurity practitioners have developed a more mature understanding of this spectrum. For example, the progression from commodity ransomware to advanced persistent threat to cyber-physical attacks.
Nevertheless, I wonder if we’re still underestimating systemic, low-grade risk accumulation, such as chronic misconfiguration, supply chain fragility, and the erosion of norms (e.g., the normalization of ransomware payments). Obviously we do worry about these things, but we should ask how we might approach this class of risk cohesively. Perhaps we should create or further formalize “middle-layer risk governance”. A space that is not just high-end adversaries, nor simple hygiene, but the accumulation of small, plausible failures with large aggregate impact.
The piece also draws attention to the notion of what it calls “distributed capability” which should be recognizable to all cybersecurity practitioners. Both biosecurity and cybersecurity share a few consistent features. Not only is capability widely distributed, but barriers to entry are lower than in traditional military domains, and small groups can have disproportionate impact. While biosecurity is now aggressively dealing with these, cybersecurity has long confronted them. Yet we too often act as if central authority is sufficient and that perimeters are meaningful.
I’m struck by how the implications here for cybersecurity may actually be more mature in the research security space. Clearly we must continue shifting toward federated security models, shared responsibility architectures, and in particular ensure that security is embedded in ecosystems, not merely enforced from the center. This strikes me as particularly true in a world where we need to treat persistent compromise as a baseline condition, not an exception.
It follows from the observation on research security that infrastructure interdependence is the real risk surface. That statement seems to encapsulate so much of our struggle within our university environments where everything is interconnected at the bits, wires, and services level, yet independent and entrepreneurial at the decision-making and governance level.
The article’s most forward-looking point is the convergence of digital and biological systems. It points out that health systems depend on digital infrastructure, biological research depends on software, data, and supply chains and consequently failures cascade across domains3. Thus it is important for us to think in terms of societal infrastructure, not IT systems. Something that can be challenging to focus on amidst the chaos of ordinary operations and planning.
Thus, it seems that a mature cybersecurity strategy should step back and try to map dependencies beyond IT, extending those traces to include, for example, health infrastructure, supply chains, and research ecosystems. This sort of mapping immediately should lead us to map cross-domain cascading failures, and to factor these into broader resilience planning at the institutional or societal level.
It’s this question of how and who steps back that’s particularly challenging. One could distill almost the entire article into the observation that governance must match the system, not the threat. While biosecurity seems to be trying to move in this direction, it’s confronting a core misalignment, historically its governance was built for discrete threats, while reality is now defined by continuous, distributed risk. It feels to me like cyber may be further along this path. We’ve spent decades evolving governance to match its environment, through continuous monitoring, iterative risk management, and adaptive controls. But we also run the risk of allowing cyber governance to ossify. There is certainly a strong stream pushing us toward compliance-driven models, static frameworks, and checkbox risk management in our space. Cybersecurity governance must be designed to be adaptive (dynamic, not static), fully integrated into decision-making (not parallel to it), and capable of handling gray-zone activity, not just incidents.
Cybersecurity’s biggest takeaway from biosecurity is not technical - it’s strategic self-awareness. What the article seems to say is that biosecurity shows what happens when a field is anchored to outdated paradigms, relies on governance that lags behind technological reality (hello AI!), and that norms are strong but too narrowly scoped.
Cybersecurity, by contrast, has developed more adaptive approaches to persistent risk, intrinsic ambiguity, and distributed capabilities. But we are not immune from this same drift. Fundamentally, the challenge for us is not just managing threats - it is continually updating the frame through which threats are understood. Building on the BoAS article, one can say that if cybersecurity fails to do that, it risks becoming what biosecurity is now struggling to evolve beyond: a system optimized for a world that no longer exists.
This will include many more mundane labs that deal with corrosive or poisonous chemicals, not merely ultra-dangerous diseases.
It’s also startling to see how seriously the researchers take these protocols and processes. Something you really never see in our cybersecurity space.
I’m lightly paraphrasing here, largely reusing the article’s phrasing and logic.


