Ten Years of CyberGreen: From Measurement to Cyber Public Health
Ten years ago, we started CyberGreen with a simple conviction:
At the time, cybersecurity was largely discussed through incidents, vulnerabilities, threats, and individual organizations. We wanted to look at the problem differently — at the internet as a shared environment, and at systemic conditions beyond individual organizations.
So we started measuring.
Over the past decade, CyberGreen has built datasets, scorecards, and methods for observing internet infrastructure health across countries and networks and produced numerous reports. We developed the Internet Infrastructure Health Metrics Framework (IIHMF) and worked to make measurement transparent and enable comparisons across time.
But measurement raised more fundamental questions.
First, who are we looking at? A country, a sector, a community, a set of organizations, or the infrastructure they depend on?
And second, what do we aspire to for that population: fewer exposed weaknesses, greater resilience, faster recovery, stronger capacity to act?
Once we identify a problem, what might actually change the outcome?
Those questions gradually pushed our thinking beyond measurement and gave us a clearer way to articulate our goals: Cyber Public Health.
From global measurement to population health
Public health offered a different way to think about cybersecurity. Rather than focusing only on individual cases, it asks about populations: Where is harm concentrated? What conditions contribute to it? Which interventions work?
We began asking similar questions about cybersecurity.
That thinking has shaped our work, including Cyber Vital Statistics, the Cyber Belief Model, and the continued development of the Internet Infrastructure Health Metrics Framework.
Our goal is not simply to produce more cybersecurity data. It is to turn measurement into evidence that can support action.
A critical part of that challenge is connecting populations as they exist in the physical world — hospitals, schools, water utilities, businesses, or communities — to their observable presence in cyberspace. That bridge creates the foundation for understanding where weaknesses are concentrated, who is in a position to act, and what interventions might improve conditions across a population.
One principle has therefore become particularly important to us:
Beginning to close the loop
Over the past year, our work with U.S. rural healthcare gave us an opportunity to put this approach into practice.
We started with a population defined in the physical world — rural healthcare facilities — and worked to map those facilities to their presence on the internet. From there, we measured DNS delegation health, identified actionable findings, and worked with trusted intermediaries to notify affected organizations.
Our aim was to explore a simple cycle:
This began moving us beyond observing conditions toward testing what happens when measurement is connected to intervention and learning.
That experience also sharpened the questions ahead. Who can actually remediate a condition? How do we reach them? What drives action? And can interventions at shared points of infrastructure improve conditions for many organizations at once?
Ultimately:
Ten years is also a story of people
Over the past decade, CyberGreen has grown through collaboration with researchers, engineers, policymakers, funders, companies, governments, and civil society organizations around the world.
I am especially grateful to Arastoo Taslim, Adam Shostack, and David Conrad, who have helped build and shape this work over many years, and to Dan Geer, Koji Hachiyama, Paul Twomey, and Jun Murai for their wisdom, challenge, and continued support.
A very special thanks also goes to Bill Reid, who has thought alongside us for many years about what Cyber Public Health could become. Through our collaboration with Google, his questions, encouragement, and willingness to explore new ideas with us have helped move these ideas from measurement and theory toward real-world application.
And as we look back on these ten years, we cannot do so without remembering Richard Soley.
Richard supported CyberGreen through many years of service on our Board. He believed in the organization and shared his experience, judgment, and encouragement generously. Losing Richard was a profound loss, but what he gave us remains part of CyberGreen. I remember him on this anniversary with particular gratitude.
To everyone who has worked with us, challenged us, supported us, and believed in work that did not always fit neatly into conventional cybersecurity categories — thank you.
And thank you to those who kept asking:
So what?
Who can act on what you measured?
How do you know what works?
Those questions made the work better.
The next ten years
CyberGreen’s first decade built the foundations for measuring and understanding internet infrastructure health.
We want to strengthen the science and institutional capacity needed to understand and improve Cyber Public Health: defining populations, connecting them to their presence in cyberspace, measuring conditions that matter, designing interventions, and evaluating whether they work.
We want to understand not only where poor cyber health is concentrated, but what actually improves it.
And we want to preserve something that has always mattered deeply to CyberGreen: independent, transparent, public-interest measurement as a common foundation for collaboration.
But this next chapter cannot be built by CyberGreen alone.
Cyber Public Health is inherently a collective endeavor. It will require researchers, governments, technology companies, sector organizations, civil society, and funders bringing together their knowledge, technology, networks, and resources to build, test, and learn together.
So as we mark ten years, our message is also an invitation.
Bring us new populations and problems to study. Challenge our assumptions. Help us test what works — and build the independent, public-interest infrastructure needed to turn measurement into measurable improvement.
We hope you will be part of the next ten.
Yurie Ito
Executive Director, CyberGreen