Build Lasting Resilience

Unresolved risk is a transformation waiting for permission

Why the gap between knowing and acting is a management decision, not an operational failure.

Somewhere in your organisation, a meeting happened. The right people were in the room, the ones who understood the systems, knew the gaps, had done the assessment honestly. They presented their findings. The risks were documented. The conversation was constructive.

And then everyone went back to work.

Not because the risks weren't real. Not because the people in the room didn't care. But because the decision that would actually change something, the budget, the priority, the direction, belonged to a different room entirely. One that never quite got the same meeting.

If you recognised that, read on.

Accountability by default

Security accountability sits at the operational level by default. It lives with the people closest to the systems, the processes, the vulnerabilities. And those people, in most organisations, do remarkable work within the constraints they are given.

But the decisions that actually change things do not live there. Budget, headcount, tools, strategic priorities, none of those are operational decisions. They are management decisions. And the gap between the people who understand the risk and the people who have the authority to address it is not a personal failure. It is a structural one.

The people who understand the risk rarely have the power to address it. The people with the power rarely have the full picture.

This is where most security programmes quietly stall. Not at the technical level, but at the level where someone with real authority needs to look at the honest picture and decide what to do about it.

A signal hiding in plain sight

A useful signal is hiding in plain sight. Where does security report in your organisation?

The answer tells you more about how risk is understood at leadership level than any policy document ever could. When security lives inside IT, it tends to be treated as a technical problem, someone else's concern, surfacing only when something breaks. When it reports through a compliance function, the conversation centres on what must be evidenced rather than what must be decided. When it sits closer to leadership, with a genuine line to the executive team or the board, it tends to be treated as what it actually is: a business risk that requires business decisions.

None of these structures is inherently wrong. But each one shapes the conversation that follows. And the conversation that follows determines whether risk ever reaches the room where it can be acted on.

This is worth examining honestly in your own organisation, not as a restructuring exercise, but as a diagnostic. The organisational home of security is often the clearest indicator of whether the accountability gap is structural or incidental. And structural gaps require structural decisions to close.

Maturity is a baseline

Maturity is a useful concept, but only if you read it honestly. Where an organisation sits on the maturity spectrum is not a verdict. It is a baseline. An honest account of what was achievable within existing constraints, with the people, tools and guidance that were available.

The operational team did not fail to reach a higher maturity level. They reached the level that was possible given what they were given. That distinction matters enormously, because it changes where the next conversation needs to happen.

Moving from one maturity level to the next is not an operational task. It is a management decision. It requires someone with authority to say: we will invest here, prioritise this, provide the guidance and resources needed to change. Without that decision, the operational level will continue doing its best. And its best will remain exactly what it has always been, the best possible within unchanged constraints.

High maturity is not necessarily the same as high security. And low maturity is not necessarily the same as failure. It may simply be the honest result of decisions that were never made.

The Respect Model

This is the philosophy behind what we call the Respect Model, not because it sounds good, but because respect is precisely what is missing in most security conversations.

Respect for what the operational level achieved within its constraints. Respect for the honest gaps that exist not from negligence, but from the absence of the resources, skills and direction needed to close them. And respect for the fact that closing those gaps is not the operational team's decision to make.

The model places decisions where they belong. High risk, the kind that threatens business continuity, reputation or regulatory standing, belongs at the strategy and leadership level. Structured risk sits in planned initiatives and governance cycles. Operational risk lives in daily management and routine controls. Not a hierarchy of blame. A structure of accountability.

When risk finds its natural decision level, something shifts. The operational team stops carrying the weight of decisions that were never theirs to make. Leadership starts engaging with risk as a strategic input rather than a compliance report. And the organisation begins moving, not because it was told to, but because the right people finally made the right decisions.

The risk register

The risk register is not a list of failures. It is a list of decisions that have not been made yet.

Every entry represents something the organisation already knows: a gap, a vulnerability, an exposure. Someone documented it. Someone assessed it. And then it waited. Not because it wasn't important, but because the permission to act on it never arrived from the level that could grant it.

When management engages with the risk register honestly, not to file it, not to satisfy an audit, but to decide, it becomes something else entirely. It becomes a transformation roadmap. Each risk treated is an initiative prioritised, a resource committed, a direction set.

But not all unresolved risks demand the same response. Some need immediate tactical action: a misconfiguration corrected, a missing control implemented, a gap in documentation closed. Others need structured planning, process improvements, updated components, clarified ownership, tracked across quarters with real resource allocation. Some reveal deeper challenges that require investigation before anything can be fixed. And occasionally, a pattern of risk reveals something more fundamental than a problem to fix. It reveals a structure that needs to transform.

The lens that makes this distinction possible is straightforward: weigh consequence against fixability. A high consequence risk that is easy to fix demands immediate action regardless of anything else. A complex risk with moderate consequence belongs in structured planning. A high consequence risk that is difficult to fix requires investigation and a strategic decision. This is not a matrix to fill in. It is a conversation to have. Honestly, at the right level, with the people who can actually decide.

The starting point

The starting point looks different for every organisation.

Sometimes it begins with a maturity assessment, not to produce a score, but to establish a shared and honest baseline between operational reality and management perception. Sometimes it is a gap analysis that surfaces the distance between where the organisation is and where its risk appetite says it should be. And increasingly, assume breach thinking is shifting how organisations prepare, moving from the question of whether something will happen to what the organisation does when it does.

The right approach depends on where you are. But the starting point is always the same. It begins with an honest account of where the organisation actually stands, brought to the level where decisions can be made. Not to be filed. To be decided.

This is the second article in a series on security, risk and organisational transformation. The first is The illusion of resilience.

← All articles

If you need help, we're here.

Tell us where you are, and we'll help you find the right first step.

Talk to us