Skip to main content
  1. Home
  2. Computing
  3. Features

Pay-n-pray cybersecurity isn’t working. What if we just paid when it works?

Add as a preferred source on Google
Cybersecurity Pay-and-Pray
Image used with permission by copyright holder

(in)Secure is a weekly column that dives into the rapidly escalating topic of cybersecurity.

Like home security, people would often rather not think about cybersecurity once they’ve paid for it. They’d rather pay and pray.

Recommended Videos

But how do you know when a security company’s software is working? With all the billions of dollars poured into protecting ourselves and our businesses online, why do hacks seem to be increasing in regularity and damages?

We spoke with Oren J. Falkowitz, a former senior-level employee at the NSA and United States Cyber Command, who has a radical idea for how cybersecurity companies should be making their money.

The problem

Our modern cybersecurity fiasco has many causes. Maybe it’s a lack of government funding and regulation. Maybe it’s large tech corporations not caring enough about privacy. Maybe it’s just a matter of educating the public and explaining in simple terms what’s at stake.

“Companies spend about $93 billion on cybersecurity, with no end in sight …”

Falkowitz has a different take. He believes the real problem is that cybersecurity profits aren’t tied to performance. “For us, it means performance-based cybersecurity and paying for results, not a failure,” he told Digital Trends. “Companies should pay for cybersecurity only when and if it performs as designed.”

That’s not how it works today. Cybersecurity experts, companies, and antivirus software are presented and purchased like an insurance plan. You pay monthly and hope that nothing bad happens. If it does, they’ll help you pick up the pieces — and maybe try to upsell you on more security.

Area 1 Security, Falkowitz’ own cybersecurity company, takes the opposite approach. Area 1 calls out the fact that people “commit to security contracts running three to five years, spending six or seven figures. But they still don’t get what they pay for.” Falkowitz believes clients should pay only for attempted crimes that are stopped. It’s an idea similar to bug bounty programs, which encourage hackers to find – and then disclose – vulnerabilities.

It's Always Phishing

“Companies spend about $93 billion on cybersecurity, with no end in sight, and what’s worse, no end to the severity or frequency of cyber attacks,” Falkowitz said. “Performance-based and accountable cybersecurity will ensure that results are what drive the future innovations and successful outcomes in business models.”

You might wonder how a company could stay in business if it constantly had to prove to customers that attacks are being stopped. Area 1 Security makes it work by focusing its efforts on a particular aspect of cybersecurity — phishing.

It all leads back to phishing

“Phishing is the attack that starts the attack, it’s the root cause for an astounding 95 percent of all damages,” said Falkowitz. “The key to performance-based cybersecurity is stopping phishing.”

“Phishing is a socially-engineered attack that relies on authenticity to evade detection.”

Phishing has become the bane of the internet’s existence. From malware to stolen data, phishing is often the entry point for the worst cyberattacks we’ve seen. It usually takes the form of a fraudulent email, sent to an unsuspecting victim under the guise of an official company or organization.

The email will then prompt the reader to click a link — and once they do, the attacker’s trap is triggered. Though simple, hackers have used phishing for everything from the Clinton campaign email debacle to the devastating 2017 WannaCry ransomware attack.

“Phishing is a socially-engineered attack that relies on authenticity to evade detection,” Falkowitz explained. “It’s designed not to be caught by anyone! That’s why it works so well. Besides being effective, it’s also incredibly cheap. That’s part of why it’s so good economically to be a bad guy on the internet. If you’re an attacker and you have something that works, that most companies can’t defend against, why not keep using it?”

Area 1 Security’s system claims to stop 99.99 percent of all phishing attacks, allowing them to keep a log of the attacks they’re preventing. Its philosophy isn’t to hunt down the criminals across the internet, but instead to stop the ones who are already knocking at our doors.

“Until we take phishing as a weapon out of the hands of attackers, we’ll continue on this increasingly dangerous and expensive trajectory.”

Maybe it’s time we started asking more from the companies that claim to protect us. After all, disarming the bad guys sounds like a much better plan than waiting for them to attack.

Luke Larsen
Former Senior Editor, Computing
Luke Larsen is the Senior Editor of Computing, managing all content covering laptops, monitors, PC hardware, Macs, and more.
Siri is about to hear everything you say, but Apple’s privacy approach has me cautiously on board
Apple's new Audio Intelligence features want to hear almost everything you say. A privacy document released alongside them explains why I am mostly okay with that.
Apple Watch Audio Intelligence features

Apple used its September 2026 launch event to enter a feature category it has mostly avoided until now: ambient listening. Siri Recap, Live Rewind, Music Recognition with Shazam, and Sound Recognition all landed on the Apple Watch Series 12 and Apple Watch Ultra 4. All four depend on the watch microphone picking up sound around you far more often than any previous Apple product has.

Siri Recap listens for conversations throughout your day and turns them into short AI summaries you can check later. Live Rewind is smaller in scope but arguably more useful day-to-day. It transcribes the last 15 seconds of whatever was just said with a double-press of the crown. This is perfect for catching a name, a book title, or directions you missed the first time. Music Recognition uses Shazam to identify songs playing nearby without you lifting a finger, much like Now Playing on Google's Pixel devices. Sound Recognition is a useful accessibility feature that listens for sirens, doorbells, and alarms to alert users who have a hearing impairment.

Read more
Can You Turn a Mini PC Into a Local AI Agent?
Furniture, Table, Computer

This post is brought to you in paid partnership with MSI

Not every AI task needs the scale of the cloud. An employee searching company documents, a retail kiosk answering product questions, or a digital sign reacting to customer behavior all need fast responses, but they don't necessarily need to send every prompt to a remote data center. Running those workloads locally reduces latency, keeps sensitive information closer to where it's generated, and can lower the ongoing cost of AI deployments. As a result, many organizations are moving toward hybrid AI architectures that handle routine requests on-device while reserving cloud models for tasks that genuinely need more processing power.

Read more
Everything Apple announced at its September event: iPhone Duo, iPhone 18 Pro, new Apple Watches, and AirPods 5
Apple packed its biggest September event in years with a foldable iPhone, new watches, and smarter AirPods.
Computer, Electronics, Tablet Computer

The "Surprise and Shine" September launch event was one of Apple's crispest, most elaborate, and most loaded launch events in a while. Instead of leaving the minute details in the spec sheet or fine print, Apple actually included them in its keynote presentation, not just for its big reveal but for all the devices it unveiled on September 9, 2026. 

While the 'Surprise' bit was covered by the new iPhone Duo, 'Shine' probably refers to the new colors in the iPhone 18 Pro lineup. Beyond these, Apple also announced two new Apple Watches and a refresh for the regular AirPods (not the Pro ones). Given that there's a lot of ground to cover, here's everything Apple announced at its September 2026 event. 

Read more