Why Cyber Investment Still Feels Like Guesswork
- Neil Hare-Brown
- Jul 22
- 3 min read

In my previous paper, I asked a deceptively simple question:
How much cybersecurity is enough?
It's a question that Boards, CEOs, CFOs and CISOs have wrestled with for decades.
Yet despite the enormous progress made in cybersecurity, many organisations still struggle to justify their cyber investment decisions with confidence. Why?
It certainly isn't because our profession lacks knowledge. Today we have more cybersecurity standards, frameworks, methodologies and guidance than ever before.
ISO/IEC 27001 provides an excellent framework for establishing and operating an Information Security Management System. The NIST Cybersecurity Framework has become one of the world's most influential approaches to managing cyber risk. FAIR introduced a disciplined methodology for quantifying cyber risk financially. SEI's OCTAVE helped organisations think systematically about operational risk.
Collectively, these and many other frameworks have advanced our profession enormously. The problem isn't that we lack frameworks. The problem is something much more practical.
How do we use them to make timely, defensible investment decisions?
The Executive Problem
Imagine sitting in a Board meeting. The discussion has moved onto cybersecurity.
The CISO requests an additional £1 million of investment.
The CFO asks a perfectly reasonable question.
"What will that £1 million buy us?"
Not technically. Financially.
How much financial risk will it remove?
How much uncertainty will remain?
How much should be insured instead?
How much can reasonably be accepted?
These are not questions about firewalls. They are questions about capital allocation. Yet many organisations still struggle to answer them objectively.
For many organisations, resilience is a requirement but not a responsibility. Business leaders want resilience of course, but they feel disconnected from a practical understanding of the risk. So, they consign the management of it to others and, while they may be influencers, are not decision-makers. Ask yourself, how many CISOs do you know who regularly sit in board meetings?
The Gap Between Analysis and Decision
One of the unintended consequences of the rapid growth of cybersecurity has been an explosion of data. Examples include:
Vulnerability counts.
Incident counts.
Threat intelligence.
Security scores.
Maturity assessments.
Patch compliance.
Attack surface metrics.
Control effectiveness.
Each has value. Each contributes something useful. Yet none of them, on its own, tells a Board whether another £1 million should be invested.
Somewhere between technical analysis and executive decision-making there is a gap. A gap that many organisations bridge using experience, instinct and professional judgement.
There is nothing inherently wrong with judgement. Every executive decision ultimately relies upon it.
The question is whether we can support that judgement with better evidence.
Utility Matters
One observation has stayed with me throughout my long career. The cybersecurity profession often assumes that more analysis automatically leads to better decisions.
In practice, that isn't always true. The most analytically rigorous methodology isn't necessarily the most useful methodology for every organisation.
Some organisations have the resources, expertise and time to perform deep quantitative analysis. Many do not. For them, the challenge is different. They need sufficient evidence to make a good decision without spending weeks or months collecting information. That isn't a compromise. It's recognising the practical reality in which most organisations operate. A reality where utility matters. Decision quality matters. Time matters. Cost matters.
Engineering Better Decisions
As an engineer by training, I've always believed that good engineering is about optimisation.
Not maximisation.
The objective isn't to collect every possible piece of information. The objective is to collect the minimum information necessary to support the best possible decision.
Collect too little information and the decision becomes subjective. Collect too much and the signal becomes buried beneath the noise. Finding that balance is one of the greatest challenges in cybersecurity governance.
Information or Noise?
Every report presented to an executive competes for one scarce resource. Attention!
Boards cannot absorb hundreds of technical metrics before making every investment decision.
Nor should they. Good governance depends upon clarity. That leads me to a principle that I have found increasingly useful over the years.
Information that does not improve a decision is noise.
That statement is deliberately provocative; perhaps even 'Muskian' (new term ;-).
It doesn't suggest the information has no value. It simply asks a different question. Does this information materially improve the decision we are trying to make? If the answer is no, then perhaps it belongs elsewhere.
A Different Conversation
Perhaps the next evolution of cybersecurity isn't another framework. Perhaps it isn't another security product. Perhaps it isn't another dashboard.
Perhaps it is simply learning how to make better investment decisions using the information we already have.
In the next paper, I'll explore why complexity and good decision-making are not the same thing. I will also discuss why adding more data can sometimes make organisations less effective rather than more.
Thought for the week
"The value of information is not measured by how much of it we collect, but by how much it improves the decisions we make."


