“Security engineering is about building systems to remain dependable in the face of malice, error, or mischance.”
Ross Anderson wrote or delivered these words in 2001 in “Security Engineering.” Anderson defined the field broadly to include attackers, mistakes, accidents, economics, and organizational failure. The book connected technical mechanisms to real institutions. Read in its original setting, the sentence is more precise than a motivational slogan. The date assigned to this NewsStreets series is a calendar placement, not a claim that the quotation originated on March 17. Restoring the source keeps the words connected to the problem, audience, and technical conditions that made them meaningful. It also shows which part of the argument belongs to Ross Anderson and which interpretations were added later as the technology spread into new settings.
The claim matters because it changes where responsibility is placed. Dependability must survive both deliberate attack and ordinary failure, which requires designing the whole system rather than protecting one component. Teams can apply that insight by naming the outcome they want, identifying the people affected, and choosing evidence that would reveal whether the design actually helps. A memorable quotation is useful when it sharpens a decision: architecture, interface, governance, maintenance, or the allocation of power. It is less useful when it is used to borrow authority without examining the speaker's reasoning. In practice, the principle should change a review question, a test plan, or an ownership decision rather than merely decorate a presentation.
The line becomes misleading when it is treated as a universal rule. No system remains dependable under every condition. Engineers must state threat models, prioritize harms, plan recovery, and communicate residual risk honestly. Technology operates inside organizations and communities, so performance on a narrow benchmark cannot settle every question. Responsible practice makes assumptions explicit, documents tradeoffs, invites criticism, and provides a way to correct harm. That discipline does not weaken innovation; it gives ambitious work a clearer relationship to evidence and a more honest account of who carries the risk. A careful reader should therefore ask what the quotation leaves outside its frame, which stakeholders are absent, and what contrary evidence would require a different conclusion.
The modern relevance is easy to find but should still be stated specifically. Critical infrastructure, payment systems, hospitals, and cloud platforms need this socio-technical view of security and resilience. For individuals, the quote can guide the next choice without pretending to supply a complete formula. For organizations, it can prompt clearer goals, better measurements, and more accountable ownership. Its lasting value lies in translating an influential idea into careful practice: understand the source, test the claim, keep the limitations visible, and revise the system when real users or real conditions contradict the preferred story. The standard is not admiration for a famous technologist; it is whether the idea helps people build systems that are more understandable, dependable, useful, and worthy of trust.
Ross Anderson used the line in “Security Engineering” in 2001. Anderson defined the field broadly to include attackers, mistakes, accidents, economics, and organizational failure. The book connected technical mechanisms to real institutions.
The setting separates the documented argument from later retellings and prevents the calendar date in this series from being mistaken for the date of origin.
Dependability must survive both deliberate attack and ordinary failure, which requires designing the whole system rather than protecting one component.
No system remains dependable under every condition. Engineers must state threat models, prioritize harms, plan recovery, and communicate residual risk honestly.
Critical infrastructure, payment systems, hospitals, and cloud platforms need this socio-technical view of security and resilience.
The strongest present-day use is practical: connect the principle to evidence, state the tradeoffs, and keep responsibility visible when technology changes people's choices or opportunities.
Explore more "Quotes of The Day"
Discover more notable quotes from influential voices across politics, science, business, technology, sports, and culture. Each quote offers insight into how ideas, beliefs, and decisions shape the world around us.
