Skip to content Skip to sidebar Skip to footer
Home Resources Blog Breaking out of optimised failure: Is there a case for a post-risk cyber world?

Breaking out of optimised failure: Is there a case for a post-risk cyber world?

7 minutes reading time

Breaking out of optimised failure: Is there a case for a post-risk cyber world?

Cybersecurity has relied on risk management for decades, but is the model still fit for purpose? During the Cyber Security Coalition’s Application Security Experience Sharing Day, Petra Vukmirovic challenged conventional thinking on cyber risk, exploring why risk registers, quantification models and compliance-driven approaches often fail to improve decision-making. From AI-driven threats and supply chain attacks to the limitations of cyber risk scoring, the session examined whether the industry is optimising failure rather than building resilience, and what a post-risk cybersecurity strategy could look like.

Cybersecurity has built much of its professional language around risk. Risk appetite, residual risk, likelihood, impact, registers and matrices have become familiar tools for governance, investment and prioritisation. During the recent Application Security Experience Sharing Day, Petra Vukmirovic, Head of Information Security and IT at Numan, considered whether the industry has become too dependent on this model and whether it is still helping organisations make better decisions.

She did not argue for abandoning risk outright. Instead, the session was framed as a thought exercise: a way to question the assumptions behind cyber risk, compare its promised benefits with real-world outcomes, and explore whether alternative approaches could help the industry move beyond what she called “optimised failure”.

An uncomfortable decade

The talk opened against a backdrop of escalating cyber disruption. Petra Vukmirovic referred to major incidents affecting retailers and automotive, attacks on airports, recent supply chain compromises and the rise of malicious packages. AI was also presented as a growing source of uncertainty, particularly through what she called the oversight illusion: the idea that humans may still appear to be in control, while in practice they increasingly approve automated outputs without meaningful scrutiny.

The UK National Cyber Security Centre’s reported doubling of significant incidents year on year reinforced the point. If the scale and impact of cyber incidents keep growing, is the effort to understand and manage cyber risk fundamentally futile, or has the industry simply failed to do it well enough?

How risk became the default

Petra Vukmirovic then stepped back to show how cybersecurity became so risk centric. Enterprise risk management developed after the Second World War, as organisations looked for ways to manage uncertainty and protect themselves against future losses. In computing, early networked systems, worms and later events such as the Morris worm helped establish cyber security as a discipline focused on preventing harm.

Over time, cyber risk became increasingly formalised. Frameworks and standards such as BS 7799, ISO/IEC 17799, ISO/IEC 27001, ISO/IEC 27005, FISMA and NIST SP 800-30 embedded risk-based thinking into information security practice. Cybersecurity gained a place in enterprise risk registers, board reporting and governance structures.

Yet Petra Vukmirovic argued that, despite dramatic changes in technology and attacker behaviour, the industry has not moved far enough beyond the tools and habits that became normalised decades ago.

ERM language without ERM mathematics

A key criticism was that cybersecurity adopted the language of enterprise risk management without adopting its mathematical discipline. The industry uses concepts such as risk appetite, residual risk and scoring, but often lacks the reliable data needed to quantify cyber risk properly.

Cyber risk is also fundamentally different from financial risk. A financial loss can often be expressed directly in monetary terms. A cyber event is adversarial, fast-changing and highly context-dependent. The same ransomware scenario might be detected early and cost almost nothing, or escalate into an existential incident that disrupts operations, supply chains and communities.

That makes quantification difficult. Cyber incidents usually emerge from chains of events rather than single causes. Understanding those chains requires data, organisational context and technical expertise. Petra Vukmirovic’s interaction with the audience illustrated the problem: many professionals have attempted cyber risk quantification, but far fewer have access to enough high-quality data to do it well without expensive external sources.

The result is what can be described as casino math: structured judgement presented as quantitative analysis. Risk numbers may look rigorous but often rest on subjective assumptions rather than calibrated measurement.

Why current practices break down

The practical consequences are visible in many organisations. Risk registers become overloaded with non-actionable items. Compliance findings are logged as risks until every issue appears urgent. When everything is labelled high risk, nothing is meaningfully high risk.

Business buy-in is another challenge. Cyber risk often sounds abstract, probabilistic and technical. Compared with commercial risks, which connect directly to revenue, or clinical and safety risks, which carry clear moral and regulatory weight, cyber can struggle to compete for attention and resources.

Even advanced quantification can be difficult to apply. It is resource-intensive, computationally expensive and hard to tailor to the specific context of an organisation. Tooling may help, but industry averages rarely capture the difference between a contained alert and a business-critical incident.

Petra Vukmirovic also highlighted the human side of the problem. People do not tend to calculate risk; they feel it. Vivid stories are remembered more easily than outcomes, emotion can override probability, and metrics can be gamed once they become targets. In that environment, risk management can become performative: producing scores, dashboards and reports without necessarily improving decisions.

A growing scepticism

The presentation situated this critique within a wider industry debate. Ross Young was cited as sceptical of how cyber risk quantification is practised today, favouring scenario evidence and security outcomes per pound spent. Adam Shostack was presented as taking a more radical view, challenging the assumption that risk management deserves its default status. Bruce Schneier’s critique focused on the lack of data, while Shannon Lantzy’s work questions risk matrices when they distort decisions rather than clarify them.

The shared message was not that risk assessment has no value. It was that current practices often fail to provide the evidence, precision or decision support they promise.

What could come next?

Petra Vukmirovic then explored what a post-risk cyber world might learn from other disciplines. Medicine was one example. Clinical scoring systems such as HEART, CURB-65 and ABCD² help doctors make decisions about cardiac events, pneumonia severity and stroke risk. These tools work because they are built on years of research, large datasets and measurable factors linked to concrete actions.

Cybersecurity could learn from this evidence-based model, but only if it confronts its own data problem. Without shared, high-quality data on incidents, controls and outcomes, cyber scoring risks becoming pseudoscience.

Safety engineering offered another useful comparison. Cyber incidents, like aviation accidents, often result from chains of small failures. Fault tree analysis starts with a top event and works backwards to identify the conditions that would need to occur for that event to materialise. This resembles attack trees and threat modelling, but with more emphasis on causal chains, probabilities and control effectiveness.

Other approaches could also strengthen decision-making. Chaos engineering deliberately breaks systems in controlled ways to test resilience. Threat-centric methods focus on what is being built, what can go wrong and which controls matter most. Early warning scores could inspire cybersecurity key risk indicators that are leading, objective, actionable and trend based. FAIR remains a useful framework for financial quantification, but only when supported by better data and more disciplined application.

Stop optimising failure

Petra Vukmirovic’s final challenge was for cybersecurity professionals to reassess their risk-centric assumptions. If current methods are not delivering, the industry needs the courage to improve them, supplement them or, where necessary, move beyond them.

That means working together, defining acceptable methods for quantification, sharing more data, exploring safety engineering and threat-centric alternatives, and being honest about which practices genuinely support better decisions. The message was not that risk should disappear from cybersecurity. It was that risk management should no longer be treated as an unquestioned default.

In a decade shaped by AI-enabled attackers, fragile supply chains and rising systemic exposure, cybersecurity cannot afford to keep optimising a failing system. It needs stronger evidence, more practical decision tools and a willingness to challenge its own assumptions.

 

Application Security 04-06-26
About the author
Jo De Brabandere

Jo De Brabandere

Experienced Marketing & Communications Expert and Strategist
Jo De Brabandere is an experienced marketing & communications expert and strategist.
Join our podcast
Please choose your preferred listening platform and language

Spotify

EN

FR

NL

Apple

EN

FR

NL

Join our newsletter

Cyber Pulse keeps you up-to-date on the latest cybersecurity news, community actions and member stories.