$10 trillion vs. $300 billion: A former FBI investigator on why cybersecurity investment needs to shift toward recovery
Magnet Forensics spoke with Miguel Clarke, a former FBI Supervisory Special Agent turned cybersecurity director, about the widening gap between the cybercrime economy and the industry built to fight it. Watch the full conversation below.
Key Takeaways
- The cybercrime economy is estimated at more than $10 trillion, against a cybersecurity industry of roughly $300 billion. Miguel Clarke argues that gap means investment needs to rebalance toward recovery, not just detection.
- Most incident response programs stop at containment. The handoff between the SOC and the digital forensics team is rarely planned out, and that’s where the investigative gap opens up.
- Unifying evidence across endpoint, cloud, mobile, and memory, and using AI to clear repetitive work, can help cybersecurity teams move from raw data to a decision they can stand behind.
Miguel Clarke spent decades investigating cybercrime as an FBI Supervisory Special Agent before moving into the private sector as a cybersecurity director. Along the way, he’s watched two numbers grow further apart: the size of the cybercrime economy, and the size of the cybersecurity industry built to fight it.
The cybercrime economy is estimated at more than $10 trillion and the cybersecurity industry is in the neighborhood of $300 billion. “We have an industry that’s trying to fight an entire economy that is orders of magnitude bigger,” Clarke said.
The situation calls for rebalancing, he added: less share of the wallet on identification and detection, more on recovery.
I foresee that if we want to have an impact on the cybercrime problem, we are going to have to shift all the way over to that recovery — invest in it with our time, talent, and treasure.”
Miguel Clarke
Former FBI Supervisory Special Agent
Why post-incident analysis is needed to close the investigative gap
Agencies are drowning in more: more alerts, more logs, more artifacts scattered across endpoints, cloud environments, and mobile devices. Federal investigators today aren’t short on data, Clarke said, what’s often missing in a typical federal incident response cycle is what that data needs to become.
What we’re really looking for is wisdom that comes from knowledge, that’s derived from information, which is derived from data.”
Miguel Clarke
Former FBI Supervisory Special Agent
Most incident response programs are built around detection and containment, though these efforts prompt more questions to be answered.
This is where the investigative gap shows up most, Clarke noted. Teams usually measure incident response in terms of time to respond or recover, but rarely talk about how they are interfacing with the digital forensics team. The handoff between the SOC and the digital forensics incident response team is often not planned out.
Clarke recommends game-planning that handoff intentionally, rather than leaving it to be figured out mid-incident:
- How are we going to hand off when there’s an incident?
- Who’s going to make that decision?
- And then what’s the criteria that elevates this from a SOC problem to a digital forensics problem?
For federal digital forensics investigators, the stakes are high: mistakes or misstatements can jeopardize an entire case. “Federal investigators represent the government, so the margin for error is so much smaller,” Clarke said. “I don’t think that courts are very permissive of mistakes or misstatements that are made by the government.”
How unifying digital evidence closes the investigative gap
Clarke’s answer to the handoff problem isn’t just about tools. It’s a change in how the existing pieces relate to each other.
Bringing all the data together in one view is extremely important, he said. Agencies and organizations that can pull threat intelligence and forensic artifacts into a single platform, spanning end-to-end investigations, put themselves in the strongest position going forward.
It means correlating evidence across endpoint, cloud, mobile, and memory into a single defensible timeline — rather than piecing together fragments from several systems after the fact. Unifying access and analysis across scattered evidence sources reduces investigative delays before logs quietly roll over and evidence ages out.
Why forensic readiness matters more than prevention
Clarke’s argument circles back to where he started: an industry that measures itself almost entirely by what it prevents is going to keep losing ground to an economy that measures its returns in the trillions.
Forensic readiness is driven by a simple recognition: agencies that can prove what happened, close cases cleanly, and recover fast will out-position the ones still betting everything on keeping every attacker out.
“You have tons of data out there,” Clarke said. “Structure it correctly, create information, use that information to develop knowledge, and mix that with experience.”
Clarke sees a similar shift needed in how teams think about AI. The debate over whether AI outperforms an investigator, he said, isn’t the one worth spending energy on.
What matters is what AI frees investigators up to do: clearing the repetitive, energy-draining work out of their way so that they can spend their time where human judgment is needed.
For federal cybersecurity teams facing rising case volumes and shrinking margin for error, the edge lies beyond detection and containment. It’s faster insight, turning what’s already been collected into readiness they can stand behind.
Ready to strengthen your forensic readiness?
Download the eBook: Closing the investigative gap in incident response.