Where Math Meets the Boardroom - Turning Systemic Cyber Risk into Strategic Business Advantage
Dr. Ranjan Pal is a Research Scientist at the MIT Sloan School of Management and a cybersecurity expert who leads graduate and undergraduate researchers on cyber risk and resilience management through the Cybersecurity at MIT Sloan (CAMS) consortium. In 2026, he was inducted as a full member of the prestigious Sigma Xi Honor Society for his cybersecurity research contributions.
Ranjan specializes in the operations research of cybersecurity applications, drawing on theoretical computer science, decision science, and applied probability and statistics. As an invited member of the World Economic Forum's (WEF) systems cyber resilience working group, he contributes expert insights on major societal cyber resilience challenges—some reaching the White House. He pioneered the field of mathematical models assessing the market sustainability of cyber insurance solutions, has advised corporations on strategic cyber risk management, and has served as an invited expert on government science and technology review panels.
A prolific author across academic, policy, and thought leadership venues, his work appears in premier journals and conferences, as well as WEF reports, Forbes, The Financial Times, The Economic Times, The Financial Express, Re-InAsia, and The Times of India. Ranjan has spoken at nearly 50 venues worldwide and held visiting scholar and faculty positions at Cambridge University, Princeton University, Tsinghua University, King’s College London, IIM Ahmedabad, AIIMS, and ISB.
My PhD in computer science exposed me to the technical roots of security, but I quickly realized that breaches aren't just engineering failures—they're also economic decisions. This is well known in the cybersecurity community. Firms underinvest, misprice risk, and free ride on others' defenses.
Operations research and decision science (that encompasses multiple theoretical computer science aspects) let me model these factors and incentives rigorously. A purely engineering/computing technical lens sees only vulnerabilities and patches; a purely economic one often sees vulnerability markets but misses network structure via which digital enterprises with varied levels of cybersecurity posture connect with one another and do business.
My combined research approach reveals how risk propagates through interdependent systems, why cyber-insurance markets fail and how to “un-fail” them, and how enterprises and their supply chain ecosystems can be resilient cost-effectively. Cybersecurity is fundamentally a socio-technical, systemic problem - you can't solve it from just one side.
The biggest gap is that policymakers tend to think about cyber risk in terms of compliance and regulation, i.e., checklists, standards, and harmonizing rules across sectors. That matters, but inside enterprises, cyber risk plays out as a messy economic and behavioral problem. Managers face budget constraints, competing priorities, and misaligned incentives.
They often free ride on others' defenses or underinvest because the returns on security are invisible until a breach actually hits. What looks like negligence from a regulator's seat is frequently a rational economic decision under uncertainty.
Second, policymakers frequently treat organizations as isolated units, but real risk is systemic. In interdependent supply chains, one vendor's weakness cascades across the entire ecosystem - a reality that static regulations rarely capture.
Our (researchers at MIT CAMS along with global enterprise and academic leaders) work representing the World Economic Forum builds on harmonizing cybersecurity regulations in the electricity sector and building supply chain resilience tried to bridge exactly this disconnect, and some of those insights reached the White House's request on harmonizing cybersecurity rules.
Finally, policy moves slowly while threats like AI-driven attacks or the coming quantum reckoning—move fast. Regulations designed today may be obsolete before they're enforced. The gap is fundamentally about translating static, top-down rules into the dynamic, incentive-driven decisions enterprises actually make on the ground and giving managers quantitative tools to price and manage risk, not just comply with it.
The most common mistake is treating supply chain risk as a sum of individual vendor assessments rather than a network problem. Organizations send out security questionnaires, score each supplier in isolation, and assume that if every partner looks 'compliant,' the whole chain is safe. But risk doesn't add up linearly. It propagates and correlates.
A single shared dependency, like a widely used AI and/or software component, can trigger simultaneous failures across seemingly unrelated vendors. That's aggregation risk, and it's exactly what makes systemic breaches catastrophic.
In addition, enterprise C-suites do not often get the context right about estimating this impact of supply chain risk from division heads. As the popular management science saying goes “if you cannot estimate, you cannot manage”. The second mistake is ignoring the business service topology. Firms rarely map how deeply interconnected they are—who their vendors' vendors are.
Network science driven cyber risk management research I lead at MIT CAMS shows you can quantify and bound this systemic supply chain risk for businesses, but only if you model the actual structure of dependencies, including dependencies attributed to AI/software bills of materials.
Without that, you're managing the risk you can see while remaining blind to the correlated, hidden exposures actually taking enterprises down and adversely affecting cyber resilience.
At the company level, resilience is ultimately an optimization against a balance sheet, i.e., you weigh security investments, cyber insurance, and expected losses to protect shareholder value. The objective is relatively clear and quantifiable. At the national scale, that calculus fundamentally changes because the objective function shifts from profit to public welfare, continuity, and even lives.
A firm can accept a calculated risk and self-insure a residual loss; a nation can't 'accept' the failure of its power grid or water systems as the stakes extend from economics to political and public sentiment performance indicators. The interdependencies are also far denser, i.e., critical infrastructure networks are deeply coupled, so a localized failure cascades into systemic, society-wide fallout.
My work at MIT CAMS on optimizing cyber-resilience of application flows in critical infrastructure tries to capture exactly this towards satisfying the strictest possible resilience constraints demanded of critical infrastructure. Finally, the actors differ.
A company answers to its board; a nation must coordinate across competing private operators with misaligned incentives. Resilience becomes a collective-action problem, not just an engineering one which is why operations research and decision science matter as much as the technology that boosts cybersecurity and resilience.
First, I'd push back gently on framing this as replacing judgment with models. The goal isn't pure quantification. It's disciplined judgment informed by rigorous modeling. Checklists fail not because they're qualitative, but because they're static and disconnected from how risk actually propagates. Good cyber operations research and decision science doesn't eliminate context; it structures it.
For the enterprise cyber risk management field to adopt this as standard practice, three things need to happen. First, we need data. Much of my own research at MIT CAMS confronts the 'small and noisy data' problem, i.e., cyber incidents are rare and underreported, so cyber risk management models must be robust under data scarcity and uncertainty, not falsely precise.
Building shared threat-intelligence pools is essential that boosts the mentioned quantitative risk management models. Second, we need to bridge the language gap. Managers and boards think in narratives and dollars, not in terms of mathematical risk equations – both being necessary for effective decision making. The quantitative rigor has to translate into C-suite decisions in how much to invest, whether to insure, which vendor to trust.
Enterprises should focus on hiring or training experts able to bridge this gap. My Forbes writing exists precisely to make that bridge. Third, we need to respect judgment's role. Numbers bound and inform risk; they don't dictate action. As I've argued, in the boardroom judgment matters more than numbers alone. The winning combination is quantitative models that discipline intuition giving managers defensible, contextual estimates rather than a false binary between gut feeling and spurious precision.
What struck me most is that cyber risk is universal, but how institutions frame it is deeply cultural. In the US and UK, i.e., at Cambridge, USC, MIT—the conversation is heavily market-driven: cyber-insurance, risk transfer, and how private incentives shape security investment. There's a relatively mature ecosystem of insurers, regulators, and capital markets to build on. In India—at IIT Delhi, IIM Ahmedabad, and ISB—the emphasis shifts.
The infrastructure is scaling rapidly, often leapfrogging legacy systems, so the risk landscape is more dynamic and less insured. There, I found real appetite for foundational questions: how do you build resilience when insurance markets are still nascent, or when ransomware hits hospitals like AIIMS? It pushed my mind to thinking toward policy and regulatory design, not just corporate strategy.
At Tsinghua in China and King's College London, the framing again differed—more state-centric, more focused on critical infrastructure and national coordination. The deeper lesson is that no single lens travels intact. A market solution that works in Boston may be meaningless where markets don't yet exist or are very sparse. Seeing the problem across these geo-diverse settings taught me to separate the invariant mathematics of risk from the context-specific institutions that govern it and to design solutions that adapt to local incentives rather than assuming one model fits all.
Both, and that tension is exactly what my research explores. In theory, cyber-insurance is elegant: it prices risk, rewards good security with lower premiums, and pushes firms to invest. When designed well with differentiated premiums tied to security posture, it can genuinely close the gap. But left unchecked, it creates blind spots.
The first is moral hazard: once insured, firms may underinvest, treating the policy as a substitute for security.
The second is aggregation risk where insurers cover correlated exposures like shared software or cloud providers, so one systemic event could trigger simultaneous claims and threaten solvency. This leads to a deeper blind spot: some risks are becoming effectively uninsurable.
AI is widening the attack surface—LLMs, agentic AI, and AI-driven supply chains introduce poorly understood vulnerabilities like model poisoning, hallucinated dependencies, and prompt injection.
When exposures are this correlated, novel, and hard to quantify, insurers respond by excluding them, capping payouts, or walking away, exactly as we saw with systemic and war-adjacent cyber events (e.g., Merck’s NotPetya claim, Mondelez vs Zurich, Lloyd state-backed cyber-attack exclusions).
That leaves enterprises exposed precisely where they feel safest. The fix isn't abandoning insurance—it's re-engineering it: CAT bonds and capital-market instruments to absorb tail risk that traditional insurers can't hold, and pricing that reflects these emerging, interconnected AI exposures. Done right, insurance disciplines security; done naively, it just relocates the risk.
The most under-studied problem is systemic risk from agentic AI that are autonomous systems that don't just advise but act, transact, and make decisions across interconnected enterprises. Academia studies AI safety and model robustness in isolation, but almost no one is rigorously modeling what happens when millions of AI agents, built on a handful of shared foundation models, interact across supply chains.
The correlated failure modes are enormous and largely unquantified. Closely related is the quantum reckoning. Adversaries are already harvesting encrypted data today to decrypt once quantum computers mature—'harvest now, decrypt later.' Enterprises treat this as distant, but the migration to post-quantum cryptography will take years, so the clock has already started.
Both share a common thread my work emphasizes: they're systemic, correlated, and hard to insure. Academia tends to study threats in silos, but the urgent frontier is the aggregation of these risks and their management, i.e., how they cascade and whether cyber insurance markets can absorb them at all.
For academic peer reviewers in operations research, computing, and the decision sciences, the contribution is often the rigor itself, i.e., the mathematical theorems associated with a solution methodology driven by a problem solving idea. The 'so what' is methodological. For business leaders, I invert that entirely: I lead with the decision.
What should you invest in, insure, or worry about tomorrow morning? The mathematics becomes invisible scaffolding; the narrative and the dollar implications carry the message. My Forbes pieces usually translate academic risk management research insights into boardroom judgment action items.
What business media still gets wrong is treating cyber risk as episodic and technical—a parade of breach headlines and patch advisories. It frames security as an IT cost center reacting to the last attack. What's missing is the systemic, economic framing: that risk is correlated across firms and not a siloed thing, that incentives drive investments in security controls, and that resilience is a strategic, proactive, and quantifiable business decision.
Media covers the fire; it rarely explains the flammable structure of interdependence that makes the fire spread. As an example, media framed the 2024 CrowdStrike outage as a botched update, missing the real story: dangerous global concentration risk from shared single-point dependencies. It framed the 2022 AIIMS ransomware attack as an isolated hospital IT failure, missing the systemic vulnerability of India's entire healthcare infrastructure and weak security governance.
One idea: treat cyber risk as a systemic, quantifiable business strategy and not an IT cost center. Concretely, boards should demand that cyber risk be expressed in the same language as every other enterprise risk: bounded, dollar-denominated estimates of correlated exposure across their supply chain, not a dashboard of patch counts and compliance checkmarks.
Why hasn't it happened? Three reasons. First, a language gap: security teams speak in vulnerabilities, boards think in returns, and no one translates. Second, the returns on security are invisible; you don't see the breach you prevented, so it's chronically underprioritized until disaster strikes.
Third, quantifying systemic risk is genuinely hard as the data is sparse and the interdependencies are complex, so boards default to checklists that feel rigorous but aren't. My work shows this risk can be estimated and bounded. The barrier isn't feasibility; it's that boards are yet to demand judgment informed by numbers over false comfort of compliances.
Dr. Ranjan Pal's message is clear: cybersecurity is no longer a technical afterthought; it is a systemic, economic, and strategic imperative that belongs in the boardroom. From the failures of compliance checklists to the looming threats of agentic AI and the quantum reckoning, he challenges enterprises to move beyond reacting to headlines and start quantifying the correlated, hidden risks that truly threaten resilience.
His work at MIT CAMS bridges rigorous mathematics with real-world decision-making, insisting that judgment and numbers must work together. As cyber threats grow more interconnected and unpredictable, Pal's call to action is timely: measure what matters and manage what you measure.
Systemic cyber risk is the risk that a cyber incident in one organization, vendor, or shared technology can spread across interconnected businesses and systems.
Organizations should look beyond individual vendor assessments and map their wider network of dependencies. This helps identify hidden and correlated risks across the supply chain.
Cyber insurance can help organizations manage financial losses and encourage stronger security practices. However, issues such as moral hazard and systemic risks can limit its effectiveness.
Agentic AI can act and make decisions across interconnected systems, creating new possibilities for correlated failures. These risks become harder to manage when many AI systems depend on shared technologies.
Cybersecurity affects business operations, financial exposure, and overall resilience. Treating it as a strategic business risk helps boards make informed decisions about investment, insurance, and risk management.