Digital Pollution: The Hidden Cost of Insecurity

A hand-drawn image depicting a row of factories, labeled Equifax, Marriott, Facebook, T-Mobile, and M&S. Each has a smokestack belching black smoke into the sky.

The internet is polluted...and not with just spam.

Every breach, every leak, every ransomware attack is a digital smoke signal from the same fire: a system that rewards speed over safety, growth over responsibility, and shortcuts over care. We’re not facing a mystery. We’re facing pollution.

Digital pollution.

Because what’s happening in cybersecurity isn’t new. It’s just playing out in code instead of carbon. And just like with environmental degradation, the people making the mess aren’t the ones who suffer the most from it. The rest of us are.


Information Security Is a Broken Market

Our problem isn’t that companies don’t understand the risks. It’s that they do. They now have enough empirical data to price in the costs of breaches. They’ve learned that, as the market is configured today, preventing harm is more expensive than offloading responsibility for it.

This isn’t incompetence. It’s not apathy. It’s rational behavior in a distorted market.

Security is treated as a cost center. Breaches are written off as acceptable losses. Prevention is chronically underfunded. The math is simple: why spend more to protect data, when the breach fallout lands mostly elsewhere?

That’s not a lapse in judgement. It's a feature of the system. One that looks remarkably like the economics of pollution.


The Externality Model: Pollution, Meet Infosec

In both pollution and insecure software, producers enjoy the upside while pushing costs downstream:

ConceptPollutionDigital Security
Producer benefitCheap production, higher marginsFast development cycles, rapid scaling, low-cost features
Externalized harmDirty air/water, public healthIdentity theft, data loss, financial damage
Cost to preventFilters, regulation complianceSecurity engineers, secure development practices
Incentive to preventLow (without regulation or PR disaster)Low (without regulation or PR disaster)
Affected partiesPublic, ecosystemsCustomers, users, citizens
AccountabilityWeak or delayedWeak or capped at fines
Just like pollution, security risk is a negative externality: a cost imposed on others that never appears on your own balance sheet.

Companies have three basic approaches to risk:

  1. Cleanup: expensive, after-the-fact remediation
  2. Prevention: moderate cost, requiring upfront investment
  3. Offloading: cheapest, shifting consequences to customers, partners, or the public

Cleanup is rarely mandated, and prevention doesn’t directly boost profits. Offloading wins by default, and the damage lands on the most vulnerable:

  • People without the resources for identity protection
  • Small businesses running insecure software
  • Abuse survivors tracked via poorly secured devices
  • Communities surveilled through negligent cloud systems

We are choking on digital exhaust. And nobody’s installing filters.


Passing the Buck: The Economics of Offloading

Offloading isn’t a loophole. It’s an incentive.

Corporate risk has three levers: eliminate, prevent, or offload. Security teams focus on the first two. But the business is focused on the third, because it’s cheapest.

Systems don’t have to be malicious to do harm. They just have to be optimized for the wrong outcome.

Offloading in this case means outsourcing blame and liability: contractually capping liability, buying cyber insurance, and funneling risk downstream to customers and subcontractors.

Recovery costs are then mostly external, while prevention costs are mostly internal. Offloading is the perfect outcome from the company’s point of view: heads I collect the profits, tails you cover most of the losses.

This setup is, in economic terms, a moral hazard: where someone takes risks they don’t personally pay for.

This isn’t about finger-pointing. Many CISOs and execs genuinely want to invest in stronger security. But when the system rewards offloading over prevention, and penalizes those who do more, the invisible hand doesn’t guide us toward safety. It drags us away from it.

Even companies that want to do the right thing often can’t afford to.

Security done right is expensive. It slows things down. It doesn’t convert users or drive revenue. And in a race against competitors who skip those investments, the secure company becomes the uncompetitive one.

Security professionals often argue, correctly, that proper security saves money in the long run. But that’s true only when you look at the global picture, well beyond the company itself. For companies that can successfully externalize the costs of security failures — offloading harm onto customers, partners, or the public — proper security is more expensive to the company, even in the long run. Like polluters dumping toxic waste to avoid disposal costs, these companies financially benefit by shifting the burden elsewhere.

This is the tragedy of the security commons. A tragedy worthy of Shakespeare’s pen: where the sins of the father are laid upon the children, and the good actors are driven from the stage. Clean companies die. All that’s left are the polluters.


Meet the New Boss, Same as the Old Boss

The empirical data are everywhere:

It’s not just that the wrong behavior is rewarded. It’s that the right behavior is actively punished.

Boards see cost, not quality. Investors prize growth over resilience. CISOs are given little authority, but are expected to take the blame. Regulators are slow, reactive, or absent.

And subcontracting? It’s structurally wired for liability avoidance. Contracts cap damages. Clickwrap agreements funnel users into arbitration. Insurance demands risk offloading as much as it does risk mitigation. Everyone protects their own flank...and the customer eats what’s left.

Pollution disperses. So does breach fallout.
And in both cases, the ones who make the mess rarely clean it up.

No wonder resilience gets lip service while breach response gets budget. No wonder breach fatigue is the default public reaction.

We get on our knees and pray...and wonder why nothing changes.


Burnout Isn’t a Bug. It’s a Feature.

Security teams aren’t failing for lack of care or tools. They’re failing because they’re fighting their own organizations.

Burnout isn’t merely emotional. It’s also economic.

Budgets are denied until after a breach. Secure designs are rejected because they’re “too slow”, or “too intrusive”. Warnings are ignored...until someone needs a scapegoat.

The cycle is familiar:

  1. Breach happens
  2. Headlines fly
  3. Vendors repackage old tools
  4. Leadership shifts blame
  5. Security budget gets a temporary bump
  6. Rinse and repeat
In pollution terms: we’re treating asthma with PR campaigns while the smog rolls in.

This Isn’t About Awareness

We’ve spent years trying to fix security with better communication: more dashboards, better metaphors, clearer metrics. But this isn’t a messaging issue.

Executives now understand the risk. They just have different incentives.

You don’t fix pollution by raising awareness.
You fix it by raising the cost of polluting.

That means legal liability. Mandatory disclosures. Regulatory enforcement with teeth. And economic signals that reward prevention over cleanup.

Security professionals can’t do that alone. But policymakers can. So can insurers, shareholders, and yes...customers.

Breaches damage trust on paper. But rarely on the balance sheet.

Until breach costs land where they’re created, the cheapest option will remain: Let it burn. Call the PR team. Repeat.


Changing the Rules Changes the Game

To reduce pollution, we didn’t just raise awareness; we imposed real costs on polluters. We changed the rules.

We made it illegal to dump toxins in rivers. We gave regulators teeth. We measured emissions. We imposed costs. And we demanded cleaner alternatives.

That’s what we need now in cybersecurity:

  • Mandatory, public breach reporting
  • Real legal liability for negligence
  • Audited and enforced security standards
  • Transparent software bills of materials
  • Actual consequences for insecure products and services

Because until the cost of insecurity lands with the people who enable it, nothing will change.


Both Sides, Now

Security is fundamentally a moral issue, but in practice, it’s also an externality problem. And until those two realities align, we’ll keep playing breach Whac-a-Mole while users absorb the damage. Until organizations are forced to own the costs of the harm they create, the breaches will keep coming...and the public will keep paying.

We’ve done this before. The Cuyahoga River in Ohio caught fire, and the EPA was born. We banned leaded gasoline. We banned CFCs. We improved air quality even as cities grew...not because polluters suddenly found religion, but because the system made it more expensive to pollute. This isn’t just about awareness. It’s about power, pressure, and accountability.


We Haven’t Had Our Security Cuyahoga Yet

The Cuyahoga actually caught fire multiple times, but it was the 1969 blaze that shocked the nation and sparked sweeping environmental reform. It was the moment when pollution stopped being an abstract problem and became an undeniable crisis.

In cybersecurity, we haven’t had that moment yet. No single breach or digital disaster has galvanized the public or regulators to enforce real accountability and systemic change. Instead, we suffer from a slow, pervasive poisoning...a digital smog that seeps into our lives quietly, invisibly, yet relentlessly.

Without that tipping point, the incentives to offload risk remain strong, and the toxic cycle of breaches, blame, and burnout continues unabated. But we shouldn’t wait for a disaster to force change. The stakes are too high, and the harm too widespread.

It’s time to treat digital pollution like the public health crisis it is. Until we demand accountability, as voters, customers, shareholders...we’re all living downwind.

Choking on the fallout.