The most expensive cyber mistakes I see at the executive level aren’t technical. They’re decisions that were framed wrong before the first dollar was spent.
I work the seam between intelligence and strategy — adversary behavior on one side, leadership decisions on the other. Most of what I get hired to do is translate one for the other. After enough of those conversations, the patterns become legible. Below are four of the most common ways otherwise-sharp executives get cyber risk wrong, and what to do instead.
1. Treating cyber as an IT problem
The most consequential cyber decisions a CEO makes are not technical. They are decisions about which markets to enter, which counterparties to trust, which acquisitions to close, which products to ship. The IT team can’t make those calls. They shouldn’t be the ones briefing the board on them, either.
When cyber is framed as an IT problem, two things happen. The CISO becomes the only person in the room who can speak to risk, which means the conversation is constrained to what they can defend against. And the executive team stops engaging with the underlying threat picture, because they’ve outsourced it.
The fix is not to demote the CISO. It’s to put threat — meaning the actual adversaries, their actual interests, and their actual capabilities — on the executive agenda alongside the standard strategy inputs. Cyber risk is a strategy variable. Treat it like one.
2. Confusing compliance with security
A surprising number of senior leaders believe that if their organization is compliant — SOC 2, ISO 27001, FedRAMP, CMMC, whatever the relevant framework — they are secure. They are not. Compliance frameworks codify a baseline that was reasonable when the framework was written. Adversaries do not honor that baseline.
I have seen organizations with immaculate compliance posture get compromised through paths the framework didn’t contemplate. I have seen organizations with rough compliance posture survive sophisticated campaigns because their team understood their adversary better than the auditor did.
Compliance tells you how you would explain a breach to a regulator. Threat intelligence tells you how the breach is actually likely to happen. You need both, but you should not confuse them.
3. Buying tools as a substitute for judgment
The cybersecurity vendor market is enormous and very effective at marketing. Senior leaders, faced with a problem they don’t fully understand, often respond by buying a tool that promises to solve it. Sometimes the tool is excellent. The judgment problem doesn’t go away.
Tools detect and prevent. Judgment decides what to do when something gets through anyway, what to disclose, when to escalate, who to bring in, what to tell employees, what to tell customers, what to tell the board. No tool covers that. The companies I see handle incidents well are the ones whose senior leadership had practiced the judgment calls before the incident happened.
If you have not run a tabletop exercise — a real one, with the actual decision-makers, on a scenario that’s actually plausible for your business — your tools are doing more for you than your team is. Fix that.
4. Underestimating the geopolitical surface
The biggest shift I see in adversary behavior over the past several years is that more and more campaigns are downstream of state-level interests, even when the actor is nominally criminal. Ransomware crews tolerated by a host government, supply-chain campaigns aimed at a specific industrial sector, intellectual-property collection from companies whose technology is strategically interesting to a foreign capital — these are not random. They are policy.
This matters for executives in two ways. First: your exposure depends on what your business does, not just on how well you defend it. Companies in semiconductors, defense, energy, biotech, and AI infrastructure should expect a different threat picture than a regional retailer. Second: the relevant context for understanding your threat picture is geopolitical, not just technical. If your threat briefings don’t include a geopolitical frame, they are missing the part that explains why the adversary is here.
Where to take it
The throughline of all four mistakes is the same: cyber risk gets pushed down the org because it looks technical, and the executive function that actually owns the consequences of cyber decisions doesn’t engage with the underlying threat picture deeply enough to make good calls.
That’s the gap I sit in. If you’re working through any of these — a market move that turns on threat assumptions, an incident that’s testing your team’s judgment, a board conversation that needs sharper inputs — that’s the work I do. The right starting point is usually a 30-minute call.
