Applying the System Asset Pricing Model
Decision Accounting
Applying the System Asset Pricing Model to Cybercrime: Measuring the System Welfare Cost of the Global Digital Extraction Economy
core-claim
Core claim
Every dollar cybercriminals capture destroys $6.30 in system welfare
The System Asset Pricing Model (SAPM) computes a system beta of 6.4 for the global cybercrime ecosystem: welfare cost per unit private payoff. This is not the FBI's 16.6B in reported losses nor the vendors' 10.5T projection — it follows from accounting across six welfare-cost channels.
- Private payoff Π ≈ $1.0T/yr (direct extraction, IP theft, CaaS, crypto theft)
- System welfare cost W ≈ $6.3T/yr (downtime, IP loss, critical infrastructure, psychological harm, governance failure)
- βW = W/Π ≈ 6.4 [90% CI: 4.9–8.4] from 100,000 Monte Carlo draws
measurement-gap
Measurement gap
Standard metrics capture less than 0.3% of the welfare cost
FBI IC3 reported 16.6B in 2024 losses; vendor projections hit 10.5T. The SAPM estimate of $6.3T sits between them — rigorous, channel-decomposed, and grounded in data.
- FBI IC3: $16.6B (verified complaints, vast undercount due to non-reporting)
- Cybersecurity Ventures: $10.5T (opaque methodology, 15% annual growth from 2015 baseline, no inflation adjustment)
- SAPM: $6.3T (six channels, each with identified data sources and uncertainty ranges)
sapm-framework
SAPM framework
CAPM logic applied to an activity, not an asset
The Capital Asset Pricing Model prices assets by covariance with market returns; SAPM prices activities by covariance with system welfare destruction. The algebra is unchanged; the sign is reversed.
- CAPM: ri = asset return; SAPM: Π = industry revenue to cybercrime ecosystem
- CAPM: βi = covariance with market; SAPM: βW = covariance with welfare destruction
- Key equation: βW = W/Π ≈ 6.3T/1.0T = 6.4
six-channels
Six channels
Welfare cost decomposes into six empirically grounded channels
Each channel has a welfare cost mechanism, primary data sources, and a channel-specific beta. The aggregate W = Σ δi minimizes double-counting.
- C1 Direct Financial Extraction: deadweight loss from criminal revenue (FBI IC3, Chainalysis)
- C2 Business Downtime & Remediation: lost productivity, recovery costs (IBM Cost of Data Breach, Sophos)
- C3 Intellectual Property Theft: R&D bypass, innovation disincentive (Commission on Theft of American IP)
- C4 Critical Infrastructure & National Security: tail risk, military expenditure (Lloyd's/Cambridge, SIPRI)
- C5 Consumer & Psychological Harm: identity theft remediation, trauma (NCVS-ITS, Javelin, Equifax)
- C6 Governance & Institutional Failure: regulatory capture, workforce gap (ISC², RUSI)
private-payoff
Private payoff
The cybercrime ecosystem captures $1.0 trillion annually in private value
Decomposed into four tiers: direct extraction (380B), IP theft (320B), CaaS infrastructure (180B), and crypto theft (120B). The CaaS tier industrializes crime — a teenager can buy a phishing kit for $50/month.
- Direct financial extraction: $380B (ransomware, BEC, consumer fraud, DPRK crypto theft)
- IP theft and trade secret monetization: $320B (state-sponsored APTs, corporate espionage)
- Cybercrime-as-a-Service: $180B (initial access brokers, bulletproof hosting, malware dev)
- Crypto theft and DeFi exploitation: $120B (Lazarus Group, DeFi bridge exploits)
impossibility
Impossibility theorem
No feasible institutional arrangement can push βW below 2.1
Under three axioms — Digital Dependency, Asymmetric Offense Advantage, and Attribution Impossibility — the Attack Surface Floor theorem proves an irreducible welfare wedge. The policy question is not elimination but compression toward the floor.
- Axiom 1: Digital Dependency — modern economies cannot function without networked infrastructure
- Axiom 2: Asymmetric Offense Advantage — offense scales faster than defense (SolarWinds: one compromised update hit 18,000 targets)
- Axiom 3: Attribution Impossibility — identifying attackers is a contested, political process (Rid & Buchanan 2015)
- Result: βW ≥ 2.1 for any feasible institutional arrangement
break-even
Break-even mitigation
Current defense spending requires an 84% annual welfare reduction to break even
Global cybersecurity expenditure is $215B/yr. The break-even mitigation rate μ* ≈ 84% — the annual percentage reduction in W needed to justify that spending. No existing intervention portfolio comes close.
- μ* = 1 - (ΠC / W) = 1 - (215B / 6.3T) ≈ 84%
- ΠC = counterfactual social return of diverted resources ($215B/yr defensive spending)
- Implies current defense is either radically misallocated or radically insufficient (or both)
marginal-beta
Marginal beta
The next dollar of cybercrime extraction destroys $9.40 in welfare
PSF concavity (κ ≈ 1.42) means marginal welfare cost exceeds average cost by 49%. Marginal deterrence — disrupting the next ransomware campaign — yields higher returns than inframarginal hardening.
- Average βW = 6.4; marginal βW = 9.4 at current operating intensity
- κ = 1.42 (concavity parameter from PSF calibration)
- Policy implication: prioritize marginal deterrence over blanket hardening
cross-domain
Cross-domain ranking
Cybercrime's βW of 6.4 sits between auto emissions and Bitcoin mining
In the SAPM hierarchy, cybercrime ranks mid-range, but the impossibility floor makes it structurally different: mitigation, not elimination, defines the feasible set.
- Nuclear power: βW = 20.74 (institutional design can theoretically close the wedge)
- Auto emissions: βW = 20.74 (can be reduced via regulation and technology)
- Bitcoin mining: βW = 20.74 (can be eliminated by switching off)
- Cybercrime: βW = 6.4 but floor at 2.1 — cannot be eliminated, only compressed
policy
Policy implications
The feasible policy set lies between βW = 6.4 and the floor of 2.1
Pigouvian taxes and Coasean bargaining fail categorically in cybercrime. The SAPM framework provides a measurement architecture, but closing the wedge requires structural interventions — marginal deterrence, attribution investment, and resilience over prevention.
- Pigouvian tax fails: no legal entity to tax (attacker operates from safe harbors with impunity)
- Coasean bargaining fails: property rights undefined, transaction costs infinite, parties unidentifiable
- Policy levers: marginal deterrence (disrupt next campaign), attribution investment, resilience mandates
- Goal: compress βW from 6.4 toward 2.1 — not to zero