Understand Your Exposure

The illusion of resilience

Why most organisations feel more secure than they are, and what it takes to close that gap.

When did you last genuinely question whether your organisation's security posture matches your actual risk reality?

Most executives carry more risk than they realise. And when it materialises, they discover they can absorb far less than they believed.

That's not a criticism. It's a pattern. And understanding it may be the most important business conversation you're not yet having.

Security maturity isn't binary. You're not secure or insecure.

You exist somewhere on a spectrum, and the distance between where you think you are, and where you are is the gap that keeps certain people in your organisation awake at night.

The illusion of resilience rarely comes from negligence. It comes from a dangerous and understandable combination: a healthy appetite for risk, paired with an incomplete understanding of what that risk means, and limited organisational capacity to absorb it if it materialises.

The confidence is real. The capability to back it up may not be.

And the illusion persists, partly because it is rewarded. Audits get passed. Reports get filed. Certifications get framed.

The incentive structures of most organisations quietly favour the appearance of security over the reality of it.

This isn't cynicism, it's rational behaviour inside a system that measures the wrong things. But rational behaviour inside a broken system still produces broken outcomes.

Somewhere in your organisation someone already knows.

The question is whether that knowledge has reached the people with the power to act on it.

That person is often not who you'd expect. They tend to be fixers and reflectors, people with deep situational awareness and limited appetite for the political cost of being heard.

They may lack mandate, budget, or the organisational gravity to move the conversation upward. The knowledge exists. The gap is structural. And it is in that gap, between what is known and what is decided, where incidents become inevitable.

Most breaches don't require a sophisticated adversary. They require an unlocked door and a moment of inattention. The organisations that suffer the most aren't always the least technical, they're often the ones who were most certain they had it handled.

Security is not rocket science.

Unless you are NASA. Then it is.

The point is proportionality. The right security posture isn't the most sophisticated one. It's the one that honestly reflects what you're protecting, what you stand to lose, and critically what you can do when something goes wrong.

Good risk thinking begins with an open mind about what could realistically happen, not probability scores, but genuine intellectual honesty about the threat landscape.

Five years ago, most European organisations would have dismissed pandemic disruption as remote, or cyber conflict as someone else's problem. The world changes faster than risk registers do, and closing doors on threats prematurely is its own form of exposure.

Once you have agreed on what is realistically possible, a different set of questions becomes far more useful. How exposed are you and does that vary across your assets?

Can you detect, respond, and recover? And can you act? Or would the response outstrip your mandate and your means?

Fixability weighed against consequence is a more honest prioritisation tool than any likelihood matrix. It moves the conversation from whether something could happen to what you would do about it.

Here is something that rarely gets said out loud about the frameworks that govern our businesses (ISO, NIS2, DORA, and their counterparts).

Read with a compliance mindset, they become a checklist. Something to satisfy, to evidence, to present. Read with an improvement mindset, they become something else: a mirror.

Any serious framework, read with the right intent, is essentially the same document. It asks: what matters to you, what threatens it, how would you know, and what would you do?

Compliance asks those questions to produce evidence.

Transformation asks them to produce honesty.

The compliance reader finishes with a certificate. The improvement reader finishes with a transformation roadmap built on self-awareness, one that protects what matters, uses resources responsibly, and is built on a transparent and honest account of where the organisation stands.

Transparency is not a vulnerability. It is the foundation on which real resilience is built. You cannot protect what you won't acknowledge. You cannot improve what you are only staging.

The frameworks didn't get it wrong. The reading of them did.

The shift that matters isn't technical. It's transformational. It begins not with a new tool or a new policy, but with an honest conversation about the gap between perception and reality, one that includes the people who already know, gives them the mandate to speak, and reaches the level of leadership where decisions can be made.

That conversation has a natural starting point. Gather your leadership and ask not, "are we secure?" but "if something went seriously wrong tomorrow, would we know, would we be ready, and could we act?"

Let the honest discomfort of that question do its work. What surfaces is not a weakness. It is the beginning of a transformation built on something solid: reality.

You questioned it once reading this. Now bring that question into the room where decisions are made.

Not "are we secure?"

But if we weren't, would we know, and could we do something about it?

This is the first article in a series on security, risk and organisational transformation. The second is Unresolved risk is a transformation waiting for permission.

← All articles

If you need help, we're here.

Tell us where you are, and we'll help you find the right first step.

Talk to us