September 30, 2026
What Working in Cybersecurity Has Taught Me About How Businesses Manage Risk
By Matthew Stiles
Risk Is Not Something You Can Eliminate
Working in cybersecurity has changed the way I think about risk. Earlier in my career, I tended to think about business risk in more traditional terms. There was financial risk, competitive risk, hiring risk, and the risk that a major business decision simply would not work out the way you expected. Those things still matter, but spending years around cybersecurity has made me look at risk differently.
The biggest lesson has probably been that every business accepts some level of risk, whether the leadership team talks about it openly or not. The question is not whether a company can eliminate risk. It cannot. The real question is whether the company understands the risks it is taking and whether those risks are reasonable for the business.
That sounds simple, but it becomes much harder when technology is involved. Businesses need technology to operate, and the more technology they use, the more they have to think about what could happen if something goes wrong.
The Right Technology Does Not Solve Everything
One thing I have noticed throughout my career is that businesses can sometimes put too much faith in buying another piece of technology. I understand why. When you are dealing with cybersecurity threats, having better tools feels like an obvious answer.
The problem is that technology is only part of the equation.
A company can have strong security products in place and still have weaknesses because of the way those products are configured, how employees use systems, how access is managed, or how quickly a team can respond when something unusual happens. That does not mean the technology was a bad investment. It means the technology has to fit into a larger strategy.
I find myself asking questions like, "What problem are we actually trying to solve?" and "What happens after we put this in place?" Those questions are just as important as asking what a product can do.
In cybersecurity, there is also a tradeoff between security and convenience. Businesses need employees to be productive. Customers expect systems to be easy to use. Security controls that make everything unnecessarily difficult can create their own problems because people may start looking for ways around them.
Finding that balance is not always straightforward.
Businesses Have to Understand What Matters Most
Another lesson I have learned is that not every risk deserves the same response. This is especially important for businesses that have limited time, people, and budgets.
There can be a tendency to look at cybersecurity as one giant problem that needs to be solved all at once. In reality, businesses have to make choices. They need to understand which systems and information are most important, where they are most exposed, and what the consequences could be if something goes wrong.
That requires more than looking at a list of technical vulnerabilities.
A business leader may not need to know every technical detail about a security system, but they should understand what is at stake. If a particular system supports an important part of the business, then protecting it may deserve more attention than something with a much smaller impact.
I think that is where good cybersecurity conversations become business conversations. Instead of simply asking whether something is secure, you start asking what level of risk the company is comfortable accepting.
Experience Changes How You Look at Risk
Working with different technology companies has also made me realize how much perspective matters. The same security concern can look very different depending on the size of the business, its industry, its customers, and the technology it relies on.
There is no single security strategy that makes sense for everyone.
That is something I have become more aware of over time. Earlier in a career, it is easy to look at a problem and think there should be one obvious answer. Experience tends to make you more cautious about that assumption.
Sometimes the best solution is not the most complicated one. Sometimes a company needs to make a significant investment. Sometimes it needs to improve a process that already exists instead of buying something new.
I have also learned that asking better questions is often more valuable than immediately trying to provide an answer.
Risk Management Is an Ongoing Process
Cybersecurity has also taught me that risk management is not something a company can check off a list and move past. Technology changes. Businesses change. Employees change. The threats change.
Something that made sense six months ago may need to be reconsidered today.
That can be frustrating for business leaders because there is always another issue to think about. At the same time, I think that is just the reality of operating a modern business. The goal is not to reach some point where there is no longer anything to worry about. The goal is to build a process for recognizing problems and responding to them before they become bigger problems.
That mindset has influenced how I approach my own work. I try not to assume that the newest technology automatically represents the right answer. I want to understand the problem, the business environment, and the tradeoffs involved.
The Human Side of Risk
For all the technology involved in cybersecurity, I have found that the human side remains one of the most important parts.
People make decisions. People create processes. People decide who gets access to information. People respond when something goes wrong. Technology can help businesses manage those responsibilities, but it cannot completely replace good judgment.
That is probably one of the biggest things cybersecurity has taught me. Managing risk is ultimately about making informed decisions with incomplete information.
You rarely know exactly what is going to happen. You have to look at what you know, recognize what you do not know, and decide where to put your attention and resources.
After spending years working around technology and cybersecurity, I have become more comfortable with that uncertainty. I do not think good risk management means having every answer. I think it means asking the right questions, understanding the tradeoffs, and being willing to adjust when circumstances change.