```html ```
top of page

The Next Big Thing - What a 1975 Punk Record Taught Us About Security Vendor Math

  • Writer: Patrick Duggan
    Patrick Duggan
  • 2 hours ago
  • 6 min read

In March 1975, a year before the Ramones put out a record, five guys from the Bronx and Queens released an album called Go Girl Crazy! The first track was called "The Next Big Thing," and it opened with a boast — the singer explaining, at length, that he was about to be enormous.


He was not. The Dictators never got big. The record sold badly. Epic dropped them.


They were also, by fairly broad agreement now, one of the first punk bands in the world. Half of what CBGB became in the next three years was on that record already. Andy Shernoff wrote the songs. Ross "The Boss" Friedman played the guitar. Handsome Dick Manitoba sang like a wrestler with a grudge. And they were doing it before almost anyone.


Both things are true. They were first, and they were ignored. The boast in the song was a joke, and it was also correct, and neither fact paid the rent.


We think about that record a lot, because our industry sings the same song completely straight.



Everybody in security is the next big thing


Walk any conference floor. Every booth has a number on it. Billions of events processed. Millions of indicators. Threats blocked, per second, at global scale, with an adjective in front of it.


The numbers are almost never lies. That is the thing worth understanding. They are usually true statements, carefully chosen from the set of true statements, and the choosing is where the work happens.


So this week we ran the audit on ourselves. Not the flattering pass. The one where you check whether your own headline survives being counted properly.


It mostly did not.





Four ways a true number becomes a lie


Rows are not indicators. We hold about 1.7 million indicator records. Deduplicated, that is 653,342 actual things. A single address can carry ninety separate rows, because each row is a point observation rather than a fact. Corpus-wide the inflation is 2.6x — and it is not spread evenly. One aggregated feed accounted for 953,833 rows describing 19,579 indicators, a factor of 48.7. Every curated feed we carry — OSV packages, urlhaus, threatfox, sslbl, openphish, malwarebazaar — came in at 1.00x. So did every source we built ourselves. Aggregation inflates. Primary research does not. That distinction matters more than the headline number, and you cannot see it unless you look per-source.


Blocks are not attacks. We have 2.9 million blocking records. 98.5 percent of them carry no request path and no user-agent, because nobody ever knocked — they are proactive listing decisions taken on reputation. Real observed attacks were the other 1.5 percent. If we had quoted the big number as "threats stopped," every word would have been defensible and the impression entirely false.


Volume is not attackers. Those 2.9 million events resolve to 12,216 distinct hosts. Roughly 238 events per attacker. Counting requests instead of machines multiplies your heroism by whatever number the noisiest scanner picked.


And our clock was wrong. Our block records carried a timestamp that turned out to be the moment a scheduled job ran, not the moment the block happened — eight consecutive events spanning thirty-five real minutes shared two timestamps. Attack peaks were being flattened by about a third and smeared into neighbouring hours. Every temporal claim we could have made was quietly measuring our own cron schedule.



The one that stung


We also run a product that scores how AI models perceive a brand. Its entire stated purpose is ending information asymmetry — giving a small business the same audit a Fortune 500 buys from consultants.


It had an information asymmetry inside its own scoring function.


Accuracy is a quarter of the score, and accuracy could only be measured for domains where we had written down ground truth — which meant our domains. Every other domain received a polite neutral 50 for a test it never sat. We had been reading a leaderboard where we were the only ones actually being examined.


Worse, when we opened our own ground truth file, it contained a claim we had publicly retired three months earlier: a consumer count we had killed because it counted curious one-off pulls rather than real users. Since accuracy is scored by whether a model repeats those facts, we had been marking models wrong for correctly refusing to repeat our own inflated number — and rewarding any model credulous enough to parrot it.


That is not an accuracy metric. That is a gullibility metric. It is fixed now: unmeasurable scores as unmeasurable rather than as average, and the grounding file says what is true today.


Cleaned up, the honest comparison against the big names, on the dimensions measured identically for everyone: Cloudflare and CrowdStrike lead, SentinelOne next, and we tie Palo Alto Networks. Not "ahead of CrowdStrike." Our own score fell from 68 to 66 over six weeks, and our sentiment reading of 46 is the lowest of the five. Models know we exist and will recommend us. They do not speak warmly about us.



What survived


One claim came through everything intact, and it is the only one we are going to repeat.


Over sixteen days, a blocklist working alone would have stopped 55 distinct attacking hosts. The behavioural shield in front of the same site stopped 1,638. Roughly thirty times more, with zero human decisions and effectively zero marginal cost.


81.3 percent of the machines that actually attacked us were on no blocklist anywhere. Not ours, not anyone's. They were caught on how they behaved, not on their reputation.


That number is worth more to us than the ones we cut, precisely because we cut the others first.



Why a low hit rate is the point


Here is the part the industry has backwards, and it took us most of a day to stop getting it wrong ourselves.


97.5 percent of the addresses on our blocklist never showed up. Read as a hit rate, that looks terrible. Read correctly, it is the entire value proposition.


A blocklist with a high hit rate is a list of things that already attacked you. That is not intelligence, it is a memoir. The whole point of holding an indicator is to hold it before it is used against you — which means most of your list should be sitting idle most of the time, like insurance you are glad not to claim on.


So there are two honest numbers, not one. How much did you hold before contact, and how much did you catch at the moment of contact. For us: 18.7 percent held in advance, 81.3 percent caught on behaviour. Almost nobody publishes the first figure, because it is small and looks like waste on a dashboard.



What The Dictators actually teach you


The lesson is not "be humble." Humility is cheap and mostly performance.


The lesson is that being early and being right and being paid are three separate things, and only one of them is under your control. That record was correct about where music was going and it did not matter commercially for twenty years. Any of us could be in the same position: correct, early, ignored.


The only thing you get to choose is whether the claim you made will still be true when somebody finally checks. The Dictators sang the boast as a joke, which is the honest way to sing it. The security industry sings it straight, with a number attached, and hopes nobody runs the arithmetic.


We are a two-person company in Minnesota. We are not the next big thing. We are pre-revenue, our AI perception score is going down, our sentiment is the worst of the five companies we compared ourselves to, and until this week our own scoring product was quietly grading everyone else on a curve.


We are also, as far as we can measure, stopping thirty times more attackers than a blocklist does, for approximately nothing, for anyone who wants it free.


Both things are true. We will keep publishing both.


If you run a security product and you have never checked whether your own headline survives being counted properly, you already know what you are going to find. Run it anyway. The number that survives is the only one worth putting on a booth.




Sources on the record: [The Dictators Go Girl Crazy! (Wikipedia)](https://en.wikipedia.org/wiki/The_Dictators_Go_Girl_Crazy!), [AllMusic review](https://www.allmusic.com/album/go-girl-crazy!-mw0000313688), [The Vinyl District](https://www.thevinyldistrict.com/storefront/graded-curve-dictators-go-girl-crazy/).




Every indicator in this post is in the feed. Free.

1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.



Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=the-next-big-thing-what-a-1975-punk-record-taught-us-about-security-vendor-math



Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page