The risk of cyber catastrophes has become a growing concern. Following the July 2026 hack of Hugging Face by a swarm of AI agents and a series of allegedly Iran-backed attacks on water utilities, a growing coalition of tech companies, cybersecurity experts, and officials has been calling on the federal government to take steps to ensure that the country’s critical infrastructure and citizens are adequately protected from cyber threats. Suggested policy solutions include increased funds for cybersecurity investments, more regulation, or the creation of government-backed cyber reinsurance. However, these policies overlook that resilience is not fostered from the top down. Bureaucrats are often poorly positioned to foresee and develop optimal responses to novel threats. The best defense against an uncertain cyber threat is not necessarily a centrally mandated defense, but an institutional environment capable of continually discovering new ones.

Imposing more rules risks adding to already duplicative cyber regulations and centralized approaches undermine the bottom-up processes that contribute to active cyber-risk management and the ability to recover from catastrophic cyberattacks. Open markets give entrepreneurs and firms incentives to develop novel technologies and practices in response to emerging threats, while allowing them to rapidly substitute, reorganize, and redirect resources when attacks succeed. Economic freedom, in other words, is a key and often overlooked piece of “critical infrastructure” that enhances America’s resilience to system shocks like cyberattacks. Policies that unnecessarily restrict market processes consequently reduce the ability of firms and communities to adapt to changing threat environments and recover from attacks.

Institutions and Black Swans

Economists and risk analysts have attempted to estimate the economic costs of a “catastrophic” cyberattack, which vary, with some estimates ranging between $0.54-62 billion or the equivalent of 0.3 percent of U.S. gross domestic product (GDP). Looking across a range of countries, another estimate places the losses from cyberattacks at approximately or 0.32 percent of their GDPs. While these estimates are large, they are but a fraction of the losses resulting from other disasters. The 2011 Japanese tsunami, for instance, caused around $220 billion in losses, whereas Hurricane Katrina in 2005 created $125 billion in damage. Nevertheless, despite their scale, society was able to recover from these disasters. Thus, it is not the scale of the losses per se that matters, but what determines a society’s resilience. The study of resilience to catastrophes is not new. John Stuart Mill once wrote in his Principles of Political Economy that,

“…what has so often excited wonder, the great rapidity with which countries recover from a state of devastation; the disappearance, in a short time, of all traces of the mischiefs done by earthquakes, floods, hurricanes, and the ravages of war. An enemy lays waste a country by fire and sword, and destroys or carries away nearly all the moveable wealth existing in it: all the inhabitants are ruined, and yet in a few years after, everything is much as it was before.”

Nevertheless, the ability to bounce back from disasters, either man-made or natural, is not universal. Economists and political scientists have argued that a society’s institutional framework—the formal and informal rules that govern it—plays a significant role in determining how resilient a society is. Yet, differences in institutional quality determine how they shape economic and political outcomes. Economically free institutions, those that protect private property, uphold the rule of law, minimize regulation, and constrain the powers of government, tend to promote resilience and recovery. In contrast, as Mill observed, those that allow governments to subject individuals to “arbitrary exactions” hamper recovery and resilience alike.

A growing body of research provides support for Mill’s insight. For example, several studies examining the effects of crises have found that economically freer countries tend to suffer fewer losses from natural disasters, while another study found that negative effects of natural disasters on housing price appreciation are smaller and recover faster in U.S. counties with higher economic freedom. A similar pattern emerges with pandemics, where higher levels of economic freedom helped to mitigate the economic damages resulting from the influenza pandemics of the early 20th century. These findings are particularly significant since the 1918 influenza pandemic was one of the largest shocks of the 20th century, indicating that economic freedom’s “shock-absorbing” effects are not limited by the size of the catastrophe. Turning from natural to “man-made disasters,” a recent study found that U.S. metropolitan areas that went into the 2008 financial crisis with fewer regulatory impediments recovered faster, in terms of employment and incomes, than areas with higher regulation. Thus, across a range of crisis types, there is strong evidence that a polity’s resilience to these is bound up with the degree of liberty it grants to economic actors.

This means that governments can promote resilience by not imposing high regulatory barriers to entry and interfering with the price system. Freer jurisdictions let entrepreneurs discover which new combinations of scarce resources create the most value to consumers, given the changes brought on by the initial shock. In a crisis when prices rise or services are unavailable, an incentive is created for businesses to find substitutes, restore those services, or to develop means to reduce the risk associated with their loss. Indeed, the expectation of crises incentivizes the development of products and services specially attuned to mitigating their effectsbeforehand. Catastrophe bonds and parametric insurance are examples of such instruments developed by market processes to compensate individuals and businesses for the value of damaged or lost assets. In giving entrepreneurs and workers the latitude and information necessary to adjust to crises, open markets lessen their severity and speed recovery. Moreover, economic freedom itself serves as a kind of societal insurance, generating more resources with which crises can be absorbed and by which bad circumstances can be escaped. The free market accomplishes this by driving improvements in economic growth, investment, incomes, and social mobility. The lesson for cyber policy is that security is dependent on the ability of the United States to cope with an evolving threat environment.

Cyber-Resilience from the Bottom-Up

An often-cited statistic from officials is that approximately 85 percent of the country’s critical infrastructure is privately owned, often in service of arguments for greater government regulation of cybersecurity. However, the actual share of privately owned critical infrastructure varies state-by-state and sector-by-sector. When it comes to critical infrastructure owned by the government or operated as a tightly regulated monopoly, security failures cannot be straightforwardly attributed to market failure. Where critical infrastructure is privately owned, there is a strong incentive, in the event of a cyberattack, to quickly restore services or suffer financial and reputational penalties, and potentially be exposed to legal liability. This same loss avoidance creates an incentive for firms to make investments in their own security prior to an incident. Indeed, 88 percent of respondents to a recent Deloitte survey stated that they expect to increase their cybersecurity expenditures over the next year.

Nevertheless, investments in security can suffer from issues of free riding, as some firms attempt to benefit from the efforts of others, as well as the possibility that all the benefits of these investments may not be fully enjoyed by the investing company. Thus, ensuring adequate cybersecurity becomes a problem of aligning incentives on the part of owners of critical infrastructure and providing the means to absorb the losses resulting from an attack. Insurance and capital markets provide one mechanism by which these investment incentives can be corrected. The demand for cyber insurance stems from the same loss avoidance incentives that guide firm security investments. Insurers, for their part, assess the security posture of insured companies, adjust premiums, coverage limits, and enforce security standards. This last function is particularly important as it is through firm monitoring and standard enforcement that insurers are able to not only ensure that insured parties are adhering to certain minimum security protocols, but also signal to other firms that those insured do not pose a cyber risk to them. Indeed, part of the enforcement power of insurers comes from other market participants, particularly commercial partners, demanding that firms possess cyber coverage or certification as part of doing business.

The governance provided by insurers is reinforced by reinsurers and capital markets, all of which have increased their role in pricing and monitoring cyber risk. Reinsurers, by offering the primary market a means to offload some of their own exposure, also provide an additional layer of market discipline on insurers by collecting information on—and monitoring the underwriting processes of—primary insurers. Firms that demonstrate superior risk management are more likely to be rewarded with favorable terms, higher coverage limits, and lower rates. Capital markets, through investments in catastrophe (cat) bonds and other insurance-linked securities, perform a similar role. While cyber-related catastrophe bonds have existed since 2016, the first dedicated cyber cat bond was issued only in 2023 by AXIS Capital. Investors in these instruments agree to surrender interest payments on their funds and a portion of the principal in the event of a pre-specified catastrophe, in exchange for a higher rate of return. Access to these instruments allows reinsurers to diversify their own risk exposure and access deeper wells of funds. Conversely, investors in these instruments have an incentive to monitor the underwriting practices of both insurers and reinsurers, charging higher rates or limiting the funds offered to firms that engage in riskier underwriting or insufficiently monitor clients.

Yet, the growing role of both reinsurers and cat bond investors illustrates how financial markets are increasingly incorporating cyber risk into their assessments and, in doing so, providing market discipline for cybersecurity practices. Indeed, following the attacks on water and healthcare organizations, credit rating agencies highlighted the importance of firms’ cybersecurity posture in mitigating “negative ratings momentum.” Moreover, the depth offered by these secondary market players contributes to the resilience of society to cyberattacks. Injecting a public backstop would only hinder the evolution of this private market function by weakening discipline and price discovery.

In addition to their role in pricing and absorbing the losses from cyberattacks, markets have spawned a growing ecosystem of firms focused on asset recovery and negotiating with attackers. In serving as middlemen between legitimate and illegitimate actors, such firms serve a loss mitigation function by striking bargains that reduce the losses that might otherwise be incurred from ransomware attacks. In the absence of such services, targeted firms would face few alternatives to either attempting to negotiate with attackers themselves or relying on public law enforcement agencies, which face relatively weaker incentives to pursue investigations and remediation in a timely, cost-effective manner. Private negotiators, by contrast, only stay in business if they successfully return assets, or a portion of their value, to their rightful owners. In this regard, private asset remediation performs much the same role as maritime salvage, ransom negotiations, or other instances of private conflict resolution where state authority is weak or non-existent. Interestingly, economists who have examined these practices have discovered that, by negotiating, potential victims can alter the incentives of bad actors in a cooperative direction, leading them to “prey” less and reducing the costs of conflict. Additionally, many of these negotiation firms provide security consulting services, utilizing their expertise in dealing with criminals to help firms harden their systems.

Robust Cyber Policy

Market processes have devised several mechanisms by which the costs and risks of cyber breaches can be priced, adjusted for, or mitigated after the fact. Preserving this open, dynamic process, then, is essential to maintaining the resilience of the United States. The risk of listening to the voices calling for more cyber regulations is that these will only serve to reduce the adaptive capacity of digital markets to novel threats. A recent Government Accountability Office report found that federal cyber incident reporting and compliance requirements overlap by 70 percent. Beyond increasing the compliance costs faced by firms, regulatory morass introduces an element of uncertainty to managerial decision-making. When faced with such a policy environment, firms adopt a “wait-and-see” approach to investing in their own cybersecurity capabilities. Thus, perversely, cyber regulatory churn can increase the vulnerability of digital markets to threats, rather than reducing it.

Policymakers looking to enhance cyber-resilience should first eliminate redundant cyber incident report requirements or regulations requiring firms to establish cybersecurity plans and focus on fostering a flexible, competitive environment wherein insurance products, certifications, security products, and other services can evolve and be adopted. Congressional attention should be paid to examining where existing common law liability rules leave gaps or could be refined to improve firms’ incentives to internalize more of the external costs associated with cybersecurity investments. This would enhance the incentives faced by firms to invest in their own security, as well as actively monitor those of their business partners. Moreover, attention should be paid to the competitiveness of insurance markets. State-level regulatory barriers, in particular, reduce the competitiveness of insurance markets, likely hindering the development and adoption of novel cyber insurance products.

An implicit assumption in many cybersecurity discussions is that the presence of any incidents is sufficient evidence of market failure and requires government intervention to correct it. Yet government officials are as poorly positioned to determine what the “right” level of cybersecurity is for every firm. Just as a positive frequency of car accidents is consistent with an efficient transportation system, the optimal level of cyberattacks is unlikely to be zero. Indeed, bureaucratic incentives are likely to push regulators to overshoot the right level of cybersecurity investment. Sustaining the resilience of the United States to novel cyber threats requires preserving, not hindering, the innovative, learning processes embodied by economic freedom and open markets.