Ross Anderson
- Author of Security Engineering, the standard textbook, across three editions
- Helped found the field of security economics
- Fellow of the Royal Society and the Royal Academy of Engineering
Bio
Ross Anderson (1956 to 2024) was professor of security engineering at Cambridge and wrote Security Engineering, the textbook most practitioners in this field learned from, published in 1993, 2008, and 2020 editions and made freely available. He helped found security economics and campaigned publicly on surveillance, banking liability, and encryption policy.
Profile built from public academic, publication, and press records. Included because his teaching shaped a generation of practitioners.
Where their work shows up
His central argument was that systems fail where incentives are misaligned, not where the cryptography is weak: banks pushed fraud liability onto customers, so fraud persisted; vendors bore no cost for insecure defaults, so defaults stayed insecure. That lens explains more identity failures than any protocol analysis does, including why MFA adoption lagged for a decade after the technology worked. See the breach teardowns for what misaligned incentives look like in practice.
Related on Start with Identity
- ExpertCo-author of the Needham-Schroeder protocol
Michael D. Schroeder co-authored two of the foundational papers in this field within three years of each other: the 1975 design-principles paper with Jerome Sal
- ExpertCo-author of the NIST RBAC model
David Ferraiolo co-authored "Role-Based Access Controls" with Rick Kuhn, presented at the 15th National Computer Security Conference in October 1992. The NIST m
- ExpertCo-author of the NIST RBAC model
Rick Kuhn co-authored the 1992 NIST paper on role-based access control with David Ferraiolo and has worked on the model, its formalization, and its assurance ev