top of page

Complexity Isn't Intelligence

Writer: Neil Hare-Brown
Neil Hare-Brown
Aug 27
3 min read

"If I had an hour to solve a problem, I'd spend fifty-five minutes thinking about the problem and five minutes thinking about solutions."


Whether or not Albert Einstein actually said those words is almost irrelevant. The sentiment captures an important truth.


Good decisions rarely come from collecting more information. They come from understanding which information actually matters. Cybersecurity, unfortunately, has developed a habit of measuring almost everything. Perhaps it is because vendors know that many cybersecurity buyers depend on statistics to obtain budget that they spend so much time on actual or made-up measurement data. Examples include:

  • Asset inventories.

  • Vulnerability counts.

  • Threat intelligence.

  • Security alerts.

  • Patch compliance.

  • Maturity assessments.

  • Attack surface metrics.

  • Configuration reviews.

  • Third-party questionnaires.

  • Risk registers.


The list goes on. Each of these can be useful. Collectively they can become overwhelming.


When More Becomes Less

One of the unintended consequences of cybersecurity's rapid maturity is information overload. Many organisations have invested heavily in collecting more data, yet boards continue to struggle with the same questions. Should we increase our cybersecurity budget? Should we buy cyber insurance?

Which investment should we make first? Where is our greatest financial exposure?


The paradox is obvious. We have more information than ever before, yet many investment decisions remain largely subjective.


Information Is Not the Same as Understanding

There is a common assumption that better decisions require more information. In reality, better decisions require better information.


Those are two very different things. Imagine asking a Board to review a twenty-page cybersecurity report immediately before approving next year's investment programme. Even the most diligent directors have limited time.


However, the challenge is not intelligence. It is attention. Attention is one of the scarcest resources available to any executive team. Every unnecessary graph, metric and table consumes attention that could have been devoted to making a better decision.


The Cost of Noise

During my career I've increasingly come to believe that cybersecurity suffers from a problem that receives very little attention. Noise.


Not network noise. Decision noise. Information that distracts from the decision rather than improving it.

This has led me to adopt a simple design principle.

Information that does not improve the decision being supported is noise.

Notice what this principle does not say. It doesn't suggest the information has no value. Of course, a packet capture is invaluable to a forensic investigator; a detailed vulnerability scan is invaluable to a penetration tester and a firewall rule review is invaluable to a network engineer.


But none of those belongs in a Board paper discussing next year's cybersecurity investment.

Context matters. The value of information depends upon the decision it is intended to support.


Every Field Should Earn Its Place

This raises an uncomfortable question. Why do so many cybersecurity assessments ask hundreds of questions?


I appreciate that sometimes the answer is perfectly valid. Compliance; audit; a technical investigation; operational management. But when the objective is executive decision-making, a different standard should apply. Every question should justify its existence. Every field should earn its place.


This is not because collecting information is difficult but because unnecessary information has a cost.

It consumes time, it creates inconsistency and increases subjectivity. Most importantly, it makes good decisions harder rather than easier.


Engineering Better Decisions

As an engineer, I've always believed that good design isn't about adding functionality but about removing everything that doesn't contribute to the objective.


The same principle applies to cyber governance. The objective isn't to collect the maximum amount of information. It is to collect the minimum amount of information necessary to support a high-quality decision. The distinction is subtle but, I believe it is also profound.


Less Can Be More

Perhaps the future of cybersecurity governance isn't another dashboard or another framework or source of threat intelligence.


Perhaps it is simply learning to distinguish between signal and noise. Between information and understanding. Between measurement and decision-making.


Because ultimately, Boards aren't trying to manage information. They're trying to make decisions.


In the next paper I'll argue that the starting point for those decisions isn't the network, the technology estate or the vulnerability scanner. It's identifying what actually matters most.


Thought for the week (reiterated)

"Information that does not improve the decision being supported is noise."

 
 

Speak with a cybersecurity specialist

Contact the team at STORM Guidance:

UK/Europe: +44-203-693-7480

Africa: +230-434-1277

India: 0008001004277

USA: +1-703-232-9015

Your contact details will only be used in connection with this enquiry.

Please read our Privacy Policy.

I'm enquiring as
bottom of page