MIT SCRAM: a new analysis platform for prioritizing enterprise security investments

The platform shows that data analysis can provide actionable insight for enterprise security.
Written by Charlie Osborne, Contributing Writer

MIT has debuted a new platform designed to help the enterprise decide how to invest in cybersecurity. 

On Thursday, MIT's Computer Science and Artificial Intelligence Lab (CSAIL) launched the Secure Cyber Risk Aggregation and Measurement (SCRAM) cryptographic platform (.PDF), which aggregates data to show the weakest spots in security -- and those leading to the worst financial losses. 

According to the researchers, at a time when many organizations are restructuring and cutting costs due to the disruption caused by COVID-19, a technological solution that is able to quantify an organization's security posture and recommend what areas to prioritize is valuable. 

See also: Lazarus group strikes cryptocurrency firm through LinkedIn job adverts

SCRAM, developed by Taylor Reynolds, technology policy director at MIT's Internet Policy Research Initiative (IPRI), economist Professor Andrew Lo and cryptographer Vinod Vaikuntanathan, does not require users to reveal sensitive corporate data, but instead, builds its recommendations based on existing security incidents without accessing the finer points of each event. 

The team says that the platform has three goals: to quantify how secure an organization is, how their security compares to rival companies, and to evaluate whether or not cybersecurity is being given the right budget -- and if not, what priorities should be changed.  

CNET: Best Android VPNs for 2020

During tests, internal data was received by seven enterprise companies averaging 50,000 employees with annual revenue of $24 billion. SCRAM then aggregated data from 50 security incidents at the participating companies using Center for Internet Security Sub-Controls, allowing researchers to analyze the attack vectors and what steps could have potentially prevented each one. 

By using multi-party computation (MPC), the team was able to perform calculations in tandem with the CIS controls, without reading or unlocking the confidential information they were sent. Once analyzed, the participating companies received individual cryptographic keys to unlock each report privately. 

TechRepublic: North Korean hackers are actively robbing banks around the world, US government warns

"The power of this platform is that it allows firms to contribute locked data that would otherwise be too sensitive or risky to share with a third party," Reynolds says.

The MIT CSAIL team found that the most expensive financial losses, exceeding $1 million, were caused by failures to prevent malware infections; unauthorized communication over ports, and failure to log and manage security incident records.


In the future, the researchers hope that more companies will participate; in particular, from the electricity, financial, and biotech industries. If 70 to 80 companies representing these areas join up, MIT believes it will be able to "put an actual dollar figure on the risk of particular defenses failing."

The biggest hacks, data breaches of 2020 (so far)

Previous and related coverage

Have a tip? Get in touch securely via WhatsApp | Signal at +447713 025 499, or over at Keybase: charlie0

Editorial standards