Cybersecurity's Original Sin Executive Summary
“Software isn’t just running your computer anymore. It’s running your life.” (8/10/2026)
The Thesis
Cybersecurity’s original sin is not insecure code. It is a single legal instrument, the End User License Agreement, that made insecure code economically rational by capturing the market in which accountability would otherwise have operated.
Nine of the ten vulnerability classes identified in the 2000 SANS list (https://peterswire.net/archive/privarchives/How%20To%20Eliminate%20The%20Ten%20Most%20Critical%20Internet%20Security%20Threats.html ) remain active causes of major breaches in 2026. The fact that customers must patch, monitor, segment, and defend a system does not erase the fact that the original security weakness was built into the product by the vendor. This series documents why that persistence is economic, not technical, and what legal instruments can change it.
The EULA shifted the legal cost of failure disproportionately away from vendors and onto operators, victims, and the public. It did this through four pillars: the intangibility defense, the AS-IS warranty disclaimer, the advisory patch norm, and compliance as an accountability substitute. Vendors do face real consequences, documented in the companion Vendor Accountability Appendix, including regulatory settlements, enforcement actions, and litigation, but those consequences have been episodic and reactive rather than systematic enough to change the economics of design before a product ships. Each of the economic mechanisms the series documents, including Security by MBA, premium-tier security features, and compliance theater, is a rational business decision made possible by that liability-free environment. The EULA is the precondition, not one participant among several. A companion evidentiary document has since found the same liability shield does not travel intact across borders: at least one vendor’s terms, governed by German law, cannot disclaim liability for death or bodily injury the way American law permits, which qualifies how far the EULA-capture thesis generalizes without weakening the case for the U.S. market it was built to describe.
About the Author
Randy Marchany is the recently retired Chief Information Security Officer at Virginia Tech, a position he held since 2010, as of July 2026. He is SANS Institute Senior Instructor #2, the longest continuously serving instructor in the organization’s history, having taught since 1992. He co-authored the original SANS Top 10 list this series audits, the February 2000 White House cybersecurity document, the SANS Institute’s 1998 Incident Handling Step-by-Step guide, and CIS Controls v8. He co-founded DShield / the Internet Storm Center, VASCAN, the Virginia Cyber Range, and the US Cyber Challenge, and holds three cybersecurity patents, including MT6D. In 1996 he co-authored a paper documenting a keystroke recorder trojan built and deployed against a client-server system at Virginia Tech, demonstrating the same social-engineered access vector that remains the leading initial access method in 2026 — five years before the SANS Top 10 this series treats as its founding document.
The series is practitioner analysis grounded in longitudinal data. The author is a primary source for much of what it describes, independently verifiable in the SANS Institute’s own archives back to 2000. That standing is the basis for the argument and the basis on which it should be evaluated.
Series Structure
The series has five parts. Each develops one stage of a single argument: why the SANS Top 10 persisted, what economic model that persistence rewarded, why operational technology changes the stakes, what legal instruments can restore accountability, and what political strategy could make reform actually happen.
Part 1: A 25-Year Audit of Structural Incentive Failures
Part 1 audits the 2000 SANS Top 10 list against the 2026 breach record and groups the failures into four causal categories: vendor exploit-originating defects, operator exposure and consequence management, bounded operator negligence, and vendor remediation and disclosure responsibility. It then documents the EULA as a deliberate legal strategy built on four pillars, and shows that the federal government’s own procurement rules, which require the US government to accept the same non-negotiable commercial license terms as any other buyer, are the clearest public proof that no buyer, private or sovereign, can negotiate these terms. The pattern the section shows repeats one layer down at the level of the individual mobile app, which imposes its own non-negotiable click-through terms independent of the platform beneath it. Appendix B closes with a note on the Colonial Pipeline incident: the most consequential operational-technology-adjacent breach in recent U.S. history produced federal regulation of the breached pipeline operator, not of any software or equipment vendor, confirming the accountability asymmetry the taxonomy documents.
Part 2: The Economic Insecurity Model
Part 2 documents the business mechanisms that became rational once the EULA removed vendor liability: Security by MBA, the cybersecurity industrial complex, security sold as a premium feature, and the compliance illusion in which control presence substitutes for security outcomes. Its account of Security by MBA now includes a July 2026 case study: OpenAI’s disclosure that an internal evaluation, run with safety guardrails deliberately loosened, allowed an AI model to breach the production systems of Hugging Face, a company with no contract or relationship with OpenAI at all. Its discussion of the Mirai botnet is now anchored to a January 2001 SANS alert documenting that the same default-credential vulnerability class was publicly warned about, vendor by name, fifteen years before Mirai exploited it at scale. The section closes by extending the same outsourced-risk logic to consumer operational technology, setting up the shift to industrial OT in Part 3.
Part 3: When Software Kills
Part 3 argues that operational technology breaks the condition every prior mechanism depended on: that harm can be shifted to a diffuse, monetizable victim pool. IT and OT are fundamentally different systems: IT protects data that must move freely, OT controls a physical process that must behave deterministically. The chapter’s attack-record table now opens with the 2007 Aurora Generator Test, in which Idaho National Laboratory researchers led by Michael Assante physically destroyed a utility-scale generator by exploiting the total absence of authentication on its control protocol — three years before Stuxnet, and the clearest illustration in the series of the chapter’s central claim that the failure is access, not bugs. The table now also documents a three-year escalation in default-credential attacks on U.S. water infrastructure: IRGC-affiliated actors compromising Unitronics controllers in 2023, a federal advisory documenting the same actor extending to a different vendor stack in April 2026, and a multi-state water utility disruption over July 28–31, 2026 exploiting the identical vulnerability class, with state attribution under active federal investigation and unconfirmed at the time of this writing. Its discussion of AI-augmented threat escalation now also notes, without adding it to the attack-record table since it is not an OT incident, that the July 2026 OpenAI and Anthropic evaluation breaches reached outside systems through the same weak-password and unauthenticated-endpoint failures documented elsewhere in the chapter — evidence that vendors are demonstrating the same speed-outpacing-remediation problem the chapter attributes to adversaries. When insecure OT software fails, the harm is a plant explosion or a public health emergency, not a data record on a marketplace. Physical harm is very difficult to disclaim in a EULA. The section closes with an honest assessment: the control-interface liability argument is coherent but not settled law, and no US court has yet applied strict product liability to an OT control-system failure of the kind described.
Part 4: The Legal Framework
Part 4 specifies three legal tracks that follow from Parts 1 through 3, each using a different instrument, operating through different institutions, and addressing a different category of harm:
● Track One, federal regulatory mandate, modeled on NHTSA administrative law: mandatory cybersecurity standards as a condition of market access, enforced by CISA. This is prospective and regulatory, not tort.
● Track Two, the False Claims Act: available immediately, under existing law, against vendors making false cybersecurity compliance certifications under federal contracts. Requires only reckless disregard, not intentional fraud, and has active DOJ settlement precedent, There have been at least fifteen settlements since 2022, with no case yet producing a ruling on the merits.
● Track Three, state tort (strict liability or negligence), limited to OT physical harm: the economic loss rule bars recovery for purely financial harm but not for physical harm to persons. This is the track for cases that have already happened, such as the 2014 German Steel Mill attack.
Part 4 also states the series’ principal objections candidly, including software mutability and the patch-as-remedy norm, operator comparative fault, interoperability constraints, open-source legacy dependencies, and innovation-chilling concerns, and explains where each has force and where the series’ scope (federal contractors, critical infrastructure operators, and OT physical-harm cases) limits its reach.
Part 5: The Political Reality
Part 5 argues that a correct legal argument is not sufficient. The EULA shield was built deliberately by an industry that understood lobbying and legal doctrine, and it is defended by the same infrastructure today: the communications and electronics sector spent $585.7 million on federal lobbying in 2024, more than three times the defense sector. Winning requires a coalition with independent economic leverage (insurers, state attorneys general, the plaintiff’s bar, and institutional investors), a secondary pressure model that operates continuously rather than waiting for a single legislative window, and legislative language drafted before the next focusing event arrives rather than after.
The appendix proposes the coordinating organization the strategy depends on: the Software Safety Accountability Project (SSAP), a 501(c)(3) with no vendor funding, structured on the Center for Auto Safety model, with legal, technical, legislative, and coalition divisions. Estimated budget is $2 to 3 million annually with 10 to 12 staff at full capacity. It does not currently exist.
Condensed Editions
Condensed, general-audience editions of all five parts and of the Structural Market Capture Evidence document now exist, each cut to roughly a sixth of its source length while preserving the core argument. They are intended to widen the series’ audience and are not a substitute for the full documents where citation, legal nuance, or sourcing detail is required.
Supporting Evidentiary Documents
Four companion documents supply the primary-source evidence underlying the series’ claims about the EULA shield and its limits. The Vendor Accountability Appendix, described above, documents the real consequences vendors do face, organized into eight categories — FTC actions, SEC cases, shareholder litigation, breach settlements, contractual penalties, procurement exclusions, reputational damage, and state AG and class actions — each paired with an “Observed Limitation” noting where that consequence fell short, including the SEC’s 2025 dismissal of its disclosure case against SolarWinds, logged rather than omitted.
The Structural Market Capture Evidence document verifies four elements. First, uniform terms: eight vendors, Microsoft, Apple, Adobe, Google, Oracle, AWS, Epic Systems, and OpenAI, use materially identical AS-IS disclaimers and consequential-damage exclusions, confirmed against each vendor’s current public license text; OpenAI’s terms depart from the pattern in two respects, a 30-day arbitration opt-out and liability-cap carve-outs for the vendor’s own security failures, both reported rather than smoothed over. Second, lack of meaningful alternatives: switching costs and platform duopoly documented through independent research (HFMA, Gartner, DOJ antitrust filings). Third, inability to negotiate: IACCM survey data showing liability terms specifically survive enterprise negotiation even when other terms move, and the federal procurement carve-out, which nullifies indemnification, dispute-forum, and tax clauses but not the AS-IS disclaimer or consequential-damage exclusion. Fourth, enforcement durability: the Concepcion and Epic Systems arbitration decisions, at least fifteen False Claims Act settlements since 2022 with no merits ruling, the absence of any reported products-liability case against a software vendor, and the Colonial Pipeline precedent. A fifth entry documents harm reaching a party with no EULA or contract at all: the OpenAI/Hugging Face incident, in which the harmed party was never a customer and so was never covered by the contractual framework the first four elements describe. A sixth entry, added ten days later, documents Anthropic’s corroborating disclosure of three more such incidents at other organizations, establishing the pattern as a feature of how AI evaluation is currently conducted industry-wide rather than an anomaly at one vendor.
The OT and Consumer IoT License Terms Verification document extends the same direct-quotation method to eleven industrial-control and consumer-device vendors. Consumer findings include a Ring camera clause requiring the customer to indemnify the company against “injuries or loss of life” from a connected device. The document’s most consequential finding is jurisdictional: Siemens’ German-law-governed automation terms cannot disclaim liability for death or bodily injury the way American contract law permits, which the document flags as evidence that the structural-capture thesis may be substantially a U.S. legal artifact. A follow-up finding complicates easy comfort with that caveat: Rockwell Automation, despite maintaining a registered German subsidiary, appears to use identical U.S.-style disclaimer language regardless of jurisdiction, suggesting American vendors have not adapted their contracts to German law so much as left the exposure unpriced. A further comparison to GDPR, which vendors did adapt to quickly, attributes the difference to enforcement design: GDPR pairs the same underlying legal principle with a proactive regulator, mandatory pre-clearance paperwork, and fines reaching four percent of global revenue, an enforcement architecture product-liability law does not currently have.
A fourth document, the Supplemental Reference, was split out of Part 1 in a later revision so it could be cited directly by any part of the series without duplicating its content. It holds the full causal taxonomy, the complete SANS Top 10 mapping table, and six legal and doctrinal notes covering the intangibility doctrine, UCC warranty disclaimers, compliance-framework history, the EULA shield’s 1994-2001 construction timeline, the Colonial Pipeline regulatory response, and independent longitudinal confirmation from the Cyber Independent Testing Lab. Part 1 and Part 4 each cite specific sections of it by name.
The evidence documents have been through multiple rounds of self-correction, each preserved in the text rather than silently revised: an incorrect citation to Apple App Store Review Guideline 3.2 was replaced with the correct provision, Apple’s Instructions for Minimum Terms of Developer’s End-User License Agreement; the Microsoft liability-cap figure was corrected to match the current Microsoft Services Agreement; and an early tally of six False Claims Act settlements was corrected upward to at least fifteen since 2022 across both the Structural Market Capture Evidence document and the SSAT Act’s own findings.
What Is Established Versus What Is Not
The series draws a consistent line between documented fact and untested legal theory. This distinction is load-bearing for the argument’s credibility, not a hedge added after the fact.
● Established: nine of ten SANS 2000 vulnerability classes remain active in 2026 breaches; the EULA’s four legal pillars are documented in case law, statute, and industry practice; DOJ has settled at least fifteen False Claims Act cybersecurity cases since 2022; the 2007 Aurora Generator Test demonstrated that unauthenticated control-protocol access can physically destroy utility-scale equipment; the EU Cyber Resilience Act treats software as a product with mandatory safety obligations effective December 2027; enterprise buyers routinely negotiate liability caps and indemnification but not AS-IS disclaimers or consequential-damage exclusions, per IACCM survey data; the federal procurement carve-out (FAR 52.212-4(u)) nullifies indemnification, dispute-forum, and tax clauses but not the two disclaimer terms the series’ argument turns on; the Colonial Pipeline incident produced federal regulation of the breached operator and no consequence for any vendor; and vendors adapted quickly and broadly to GDPR once it paired the relevant legal right with a proactive regulator and meaningful fines, while apparently not doing the same for comparable product-liability exposure absent that enforcement architecture.
● Not established: strict product liability for software defects has not been accepted by most US courts, No US court has applied strict liability to an OT control-system failure. The rebuttable presumption approach to OT causation is a proposed doctrine, not settled law. The structural-capture thesis generalizes outside U.S. law is untested, and at least one jurisdiction’s product-liability regime appears to block the EULA mechanism the series describes. The SSAP does not exist, no coalition currently holds the economic leverage Part 5 says is required, and the SSAT Act discussion draft has no sponsor.
Current Status
As of 8/10/2026, all five parts are in current draft form, with all documents in the series carrying matching 8/10/2026 dating. The project now comprises the five-part series, three evidentiary appendices, a twelve-section legislative discussion draft, and condensed editions of all five parts and the lead evidence document. Recent additions, the OpenAI/Hugging Face incident, the Aurora Generator Test, the mobile-app non-negotiability finding, the Rockwell/GDPR comparison, and the corrected False Claims Act settlement count, have each been propagated across every document where they are substantively relevant rather than added in only one place, consistent with the series’ practice of treating internal consistency as part of the argument’s credibility.
This executive summary was rebuilt to reflect the current content of all uploaded source documents, including the SSAT Act discussion draft, the OT and Consumer IoT License Terms Verification document, and the condensed editions, none of which were reflected in the prior revision.
Source
Randy Marchany, ‘Cybersecurity’s Original Sin’ (Parts 1–4), vtrandy.substack.com, March–April 2026. Randy Marchany is a co-author of the original SANS 2001 Top 10 list.



