Cyber Risk Is Not a Technical Problem – It’s a Storytelling Failure

Cyber Risk Is Not a Technical Problem – It’s a Storytelling Failure

There are dozens of threads stating authoritatively that you’ve got to be technical to be in cyber. And there are lots of technical people who are really, really, good.

But I’ve sat in too many meetings where cyber risks described by a very technically competent professional were then ‘accepted’ without anyone really understanding what that acceptance actually meant. That’s just one good reason why I don’t believe cyber risk is primarily a technical problem.

When a cyber incident makes the headlines, the explanation is almost always technical.

“A vulnerability wasn’t patched.”

“A system was misconfigured.”

“A control failed.”

The post-mortem is written in acronyms and diagrams and the implicit conclusion is comforting: “this was a technical failure, therefore a technical fix will prevent it happening again”. That conclusion is usually wrong.

Because behind almost every serious cyber incident sits a quieter, more uncomfortable truth: the right people were never told the real story of the risk they were accepting.

The failure rarely happens where we say it does. In high-stakes, regulated environments, government, critical infrastructure, financial services, cyber incidents almost never come as a total surprise to the people closest to the systems.

Engineers usually know where the weaknesses are.

Security teams often know which controls are fragile, compensating or quietly out of date.

What fails is not detection or expertise. What fails is translation.

Somewhere between the technical reality and the executive decision, risk is softened, abstracted or reframed into something that feels manageable. By the time it reaches a board paper or dashboard, the story has changed.

Uncertainty becomes a percentage. Impact becomes a colour. Failure becomes “accepted risk”.

And crucially, no one ever quite explains what that acceptance actually means.

Red, Amber, Green. And dangerously incomplete. Most organisations rely on the same visual language to communicate cyber risk: red-amber-green charts, heatmaps, maturity scores, residual risk statements. They look reassuringly precise. They suggest control.

But they hide more than they reveal.

A “low likelihood, high impact” risk looks neat on a grid. It does not tell a non-technical decision maker what will actually happen when that risk materialises. Which services stop. Who notices first. How long recovery takes. What customers, regulators, or the press will see. Likewise, control-focused reporting tells leaders what exists, not what breaks.

We report that logging is in place, not what happens when logs are incomplete.

We report that backups exist, not whether they restore under pressure.

We report that access is restricted, not what happens when credentials are stolen anyway.

In effect, we describe defences without ever narrating failure.

Comfort is not clarity. Most cyber professionals are not deliberately misleading leaders. In fact, the opposite is usually true. There is a genuine desire to be measured, objective and non-alarmist.

But in trying to be professional, we often become narrators of comfort rather than translators of consequence. Technical language acts as a buffer. It allows difficult truths to be expressed without emotional weight.

“Risk appetite exceeded” sounds calmer than “this will stop the service for days.”

“Residual risk accepted” sounds cleaner than “we cannot prevent this and have no tested recovery.”

Over time, this creates a dangerous illusion: that risks are understood, owned and consciously accepted.

Budgets are approved. Plans are signed off. Assurances are given.

Yet if you stop a board member in the corridor and ask, “What will actually happen if this fails?” the answer is often vague, or wrong.

One of the most revealing phrases in cyber governance is “acceptable risk”.

Acceptable to whom, exactly?

Acceptable to the business?

To the board?

To regulators?

To customers?

To the individual who will have to explain the outage on the evening news?

In practice, “acceptable” often means unexamined. It means no one has explicitly described the consequences in human, operational, or reputational terms. No one has named who owns the outcome. No one has asked whether they would still accept the risk if the story were told plainly.

This is not a tooling problem. It is not a framework gap. And it will not be solved by another dashboard.

It is a failure of responsibility and courage.

Storytelling as a professional duty. Good cyber risk communication is not about simplifying the technical truth until it fits on a slide. It is about telling a truer story, one that connects systems to services, failures to outcomes and decisions to consequences.

That means:

  • Explaining how controls fail, not just that they exist
  • Describing impact in operational and human terms, not abstract scores
  • Making uncertainty explicit instead of hiding it in averages
  • Naming ownership rather than hiding behind process
  • Being clear about what is not understood as well as what is

This is harder than producing a heatmap. It is also far more valuable.

In regulated environments, we already accept this logic elsewhere. We do not brief safety risks, financial exposure, or legal liability purely in technical language. We tell scenarios. We explain consequences. We ask leaders to actively acknowledge what they are choosing.

Cyber risk deserves the same treatment.

A different question for leaders. Reframing cyber security as a storytelling challenge does not diminish its technical complexity. It elevates it. It recognises that the real work happens at the boundary between expertise and decision-making.

The most important question for leaders is not, “Are we secure?”

That question is unanswerable and usually meaningless.

The better question is: “Do we truly understand the risk we are choosing to live with?”

If the answer is no, or not sure, then the failure has already happened. Not in the firewall. Not in the code.

But in the story that was never properly told. And if cyber security keeps failing, it may not be because the technology is too complex but because the stories we tell about it are still too easy.

Have you seen cyber risk well told, or badly translated? Have you sat in rooms where everyone nodded, yet no shared understanding actually existed? And what would change if we treated telling the unvarnished truth about cyber risk as a professional obligation, not an optional skill?

If this resonates or if it makes you uncomfortable, I’d genuinely like to hear your experience.


Lawrie Abercrombie is Arcanum’s Chief Consultant. He is a Chartered Cyber Security professional and a Fellow and Board Member of the Chartered Institute of Information Security. All of his articles and more are on our website.